Phpgurukul
Phpgurukul Hospital Management System: vulnerabilidades y CVE
Phpgurukul Hospital Management System tiene 62 vulnerabilidades publicadas, 6 de ellas en los últimos 12 meses. 11 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE62
Últimos 12 meses6
Críticas11
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2025-70064 | Alta (8.8) | 0.48% | — | 18 feb 2026 | PHPGurukul Hospital Management System v4.0 contains a Privilege Escalation vulnerability. A low-privileged user (Patient) can directly access the Administrator Dashboard and all sub-modules (e.g., User Logs, Doctor… |
| CVE-2025-70063 | Media (6.5) | 0.34% | — | 18 feb 2026 | The 'Medical History' module in PHPGurukul Hospital Management System v4.0 contains an Insecure Direct Object Reference (IDOR) vulnerability. The application fails to verify that the requested 'viewid' parameter belongs… |
| CVE-2025-70062 | Media (6.5) | 0.18% | — | 18 feb 2026 | PHPGurukul Hospital Management System v4.0 contains a Cross-Site Request Forgery (CSRF) vulnerability in the 'Add Doctor' module. The application fails to enforce CSRF token validation on the add-doctor.php endpoint.… |
| CVE-2026-2179 | Baja (2) | 0.36% | — | 8 feb 2026 | A vulnerability was determined in PHPGurukul Hospital Management System 4.0. This impacts an unknown function of the file /admin/manage-users.php. This manipulation of the argument ID causes sql injection. The attack… |
| CVE-2026-2134 | Baja (2) | 0.36% | — | 8 feb 2026 | A security vulnerability has been detected in PHPGurukul Hospital Management System 4.0. The affected element is an unknown function of the file /hms/admin/manage-doctors.php. Such manipulation of the argument ID leads… |
| CVE-2026-1550 | Baja (2.1) | 0.40% | — | 28 ene 2026 | A security flaw has been discovered in PHPGurukul Hospital Management System 1.0. Affected by this issue is some unknown functionality of the file /hms/hospital/docappsystem/adminviews.py of the component Admin… |
| CVE-2025-56216 | Alta (8.5) | 0.29% | — | 25 ago 2025 | phpgurukul Hospital Management System 4.0 is vulnerable to SQL Injection in about-us.php via the pagetitle parameter. |
| CVE-2025-56215 | Media (6.5) | 0.27% | — | 25 ago 2025 | phpgurukul Hospital Management System 4.0 is vulnerable to SQL Injection in contact.php via the pagetitle parameter. |
| CVE-2025-56214 | Crítica (9.8) | 0.35% | — | 25 ago 2025 | phpgurukul Hospital Management System 4.0 is vulnerable to SQL Injection in index.php via the username parameter. |
| CVE-2025-56212 | Crítica (9.8) | 0.43% | — | 25 ago 2025 | phpgurukul Hospital Management System 4.0 is vulnerable to SQL Injection in add-doctor.php via the docname parameter. |
| CVE-2025-7604 | Media (5.5) | 0.44% | — | 14 jul 2025 | A vulnerability was found in PHPGurukul Hospital Management System 4.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /user-login.php. The manipulation of the… |
| CVE-2025-7176 | Media (5.5) | 0.64% | — | 8 jul 2025 | A vulnerability was found in PHPGurukul Hospital Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file view-medhistory.php. The manipulation of… |
| CVE-2024-51360 | Crítica (9.8) | 0.92% | — | 23 may 2025 | An issue in Hospital Management System In PHP V4.0 allows a remote attacker to execute arbitrary code via the hms/doctor/edit-profile.php file |
| CVE-2024-56990 | Media (4.5) | 0.40% | — | 21 ene 2025 | PHPGurukul Hospital Management System 4.0 is vulnerable to Cross Site Scripting (XSS) in /view-medhistory.php and /admin/view-patient.php. |
| CVE-2024-56998 | Media (4.2) | 0.20% | — | 21 ene 2025 | PHPGurukul Hospital Management System 4.0 is vulnerable to Cross Site Scripting (XSS) in /edit-profile.php via the parameter $address. |
| CVE-2024-56997 | Media (4.2) | 0.20% | — | 21 ene 2025 | PHPGurukul Hospital Management System 4.0 is vulnerable to Cross Site Scripting (XSS) in /doctor/index.php via the 'Email' parameter. |
| CVE-2024-11675 | Media (5.3) | 0.48% | — | 26 nov 2024 | A vulnerability has been found in CodeAstro Hospital Management System 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file… |
| CVE-2024-46239 | Media (5.9) | 0.30% | — | 21 oct 2024 | Multiple cross-site scripting vulnerabilities exist in PHPGurukul Hospital Management System 4.0 via the docname parameter in /doctor/edit-profile.php and adminremark parameter in /admin/query-details.php. |
| CVE-2024-46238 | Media (5.9) | 0.30% | — | 21 oct 2024 | Multiple Cross Site Scripting (XSS) vulnerabilities exist in PHPGurukul Hospital Management System 4.0 via the docname parameter in /admin/add-doctor.php and /admin/edit-doctor.php |
| CVE-2024-46237 | Media (5.4) | 0.32% | — | 9 oct 2024 | PHPGurukul Hospital Management System 4.0 is vulnerable to Cross Site Scripting (XSS) via the patname, pataddress, and medhis parameters in doctor/add-patient.php and doctor/edit-patient.php. |
| CVE-2022-46499 | Alta (8.8) | 0.55% | — | 7 mar 2024 | Hospital Management System 1.0 was discovered to contain a SQL injection vulnerability via the pat_number parameter at his_admin_view_single_patient.php. |
| CVE-2022-46498 | Baja (2.7) | 0.44% | — | 7 mar 2024 | Hospital Management System 1.0 was discovered to contain a SQL injection vulnerability via the doc_number parameter at his_admin_view_single_employee.php. |
| CVE-2022-46497 | Alta (8.1) | 0.50% | — | 7 mar 2024 | Hospital Management System 1.0 was discovered to contain a SQL injection vulnerability via the pat_number parameter at his_doc_view_single_patien.php. |
| CVE-2020-26630 | Media (4.9) | 0.71% | — | 10 ene 2024 | A Time-Based SQL Injection vulnerability was discovered in Hospital Management System V4.0 which can allow an attacker to dump database information via a special payload in the 'Doctor Specialization' field under the… |
| CVE-2020-26629 | Crítica (9.8) | 1.2% | — | 10 ene 2024 | A JQuery Unrestricted Arbitrary File Upload vulnerability was discovered in Hospital Management System V4.0 which allows an unauthenticated attacker to upload any file to the server. |
| CVE-2020-26628 | Media (6.1) | 0.50% | — | 10 ene 2024 | A Cross-Site Scripting (XSS) vulnerability was discovered in Hospital Management System V4.0 which allows an attacker to execute arbitrary web scripts or HTML code via a malicious payload appended to a username on the… |
| CVE-2020-26627 | Media (4.9) | 0.71% | — | 10 ene 2024 | A Time-Based SQL Injection vulnerability was discovered in Hospital Management System V4.0 which can allow an attacker to dump database information via a crafted payload entered into the 'Admin Remark' parameter under… |
| CVE-2024-0364 | Crítica (9.8) | 0.53% | — | 10 ene 2024 | A vulnerability, which was classified as critical, was found in PHPGurukul Hospital Management System 1.0. This affects an unknown part of the file admin/query-details.php. The manipulation of the argument adminremark… |
| CVE-2024-0363 | Crítica (9.8) | 0.65% | — | 10 ene 2024 | A vulnerability, which was classified as critical, has been found in PHPGurukul Hospital Management System 1.0. Affected by this issue is some unknown functionality of the file admin/patient-search.php. The manipulation… |
| CVE-2024-0362 | Crítica (9.8) | 0.65% | — | 10 ene 2024 | A vulnerability classified as critical was found in PHPGurukul Hospital Management System 1.0. Affected by this vulnerability is an unknown functionality of the file admin/change-password.php. The manipulation of the… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.
Otros productos de Phpgurukul
Online Shopping Portal · 43ZOO Management System · 37ART Gallery Management System · 36Online Fire Reporting System · 32Complaint Management System · 32Student Record System · 29Beauty Parlour Management System · 28User Registration & Login AND User Management System · 25Land Record System · 25Pre-school Enrollment System · 25Vehicle Parking Management System · 24Dairy Farm Shop Management System · 24