Phpgurukul
Phpgurukul Hostel Management System: vulnerabilidades y CVE
Phpgurukul Hostel Management System tiene 17 vulnerabilidades publicadas, 5 de ellas en los últimos 12 meses. 2 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE17
Últimos 12 meses5
Críticas2
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-90851 | Baja (2.1) | 0.37% | — | 15 sept 2026 | A flaw has been found in PHPGurukul Hostel Management System 3.0. This affects an unknown part of the file /admin/includes/checklogin.php. This manipulation of the argument ID causes improper access controls. Remote… |
| CVE-2026-90850 | Baja (1.9) | 0.37% | — | 15 sept 2026 | A vulnerability was detected in PHPGurukul Hostel Management System 3.0. Affected by this issue is some unknown functionality of the file /admin/manage-students.php. The manipulation results in cross site scripting. The… |
| CVE-2025-63611 | Alta (8.7) | 0.30% | — | 8 ene 2026 | Cross-Site Scripting in phpgurukul Hostel Management System v2.1 user-provided complaint fields (Explain the Complaint) submitted via /register-complaint.php are stored and rendered unescaped in the admin viewer… |
| CVE-2025-13577 | Baja (2) | 0.22% | — | 24 nov 2025 | A flaw has been found in PHPGurukul Hostel Management System 2.1. The impacted element is an unknown function of the file /register-complaint.php. Executing a manipulation of the argument cdetails can lead to cross site… |
| CVE-2025-28129 | Media (5.4) | 0.22% | — | 6 oct 2025 | Phpgurukul Hostel Management System 2.1 is vulnerable to clickjacking. |
| CVE-2025-6155 | Media (5.5) | 0.51% | — | 17 jun 2025 | A vulnerability was found in PHPGurukul Hostel Management System 1.0. It has been classified as critical. Affected is an unknown function of the file /includes/login-hm.inc.php. The manipulation of the argument Username… |
| CVE-2025-6154 | Media (5.5) | 0.51% | — | 17 jun 2025 | A vulnerability was found in PHPGurukul Hostel Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /includes/login.inc.php. The manipulation of the argument… |
| CVE-2025-6153 | Media (5.5) | 0.51% | — | 17 jun 2025 | A vulnerability has been found in PHPGurukul Hostel Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file /admin/students.php. The manipulation of the argument search_box… |
| CVE-2025-45953 | Crítica (9.1) | 0.44% | — | 28 abr 2025 | A vulnerability was found in PHPGurukul Hostel Management System 2.1 in the /hostel/change-password.php file of the user panel - Change Password component. Improper handling of session data allows a Session Hijacking… |
| CVE-2023-36939 | Media (6.1) | 0.56% | — | 10 jul 2023 | Cross-Site Scripting (XSS) vulnerability in Hostel Management System v2.1 allows an attacker to execute arbitrary code via a crafted payload to the search booking field. |
| CVE-2023-36375 | Media (5.4) | 0.87% | — | 10 jul 2023 | Cross Site Scripting vulnerability in Hostel Management System v2.1 allows an attacker to execute arbitrary code via a crafted payload to the Guardian name, Guardian relation, complimentary address, city, permanent… |
| CVE-2023-36376 | Media (4.8) | 0.59% | — | 10 jul 2023 | Cross-Site Scripting (XSS) vulnerability in Hostel Management System v.2.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the add course section. |
| CVE-2023-34647 | Media (6.1) | 0.36% | — | 28 jun 2023 | PHPgurukl Hostel Management System v.1.0 is vulnerable to Cross Site Scripting (XSS). |
| CVE-2023-34652 | Media (6.1) | 0.49% | — | 28 jun 2023 | PHPgurukl Hostel Management System v.1.0 is vulnerable to Cross Site Scripting (XSS) via Add New Course. |
| CVE-2021-43137 | Alta (8.8) | 0.53% | — | 1 dic 2021 | Cross-Site Scripting (XSS) and Cross-Site Request Forgery (CSRF) vulnerability exits in hostel management system 2.1 via the name field in my-profile.php. Chaining to this both vulnerabilities leads to account takeover. |
| CVE-2020-25270 | Media (5.4) | 3.2% | — | 8 oct 2020 | PHPGurukul hostel-management-system 2.1 allows XSS via Guardian Name, Guardian Relation, Guardian Contact no, Address, or City. |
| CVE-2020-5510 | Crítica (9.8) | 2.1% | — | 8 ene 2020 | PHPGurukul Hostel Management System v2.0 allows SQL injection via the id parameter in the full-profile.php file. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.
Otros productos de Phpgurukul
Hospital Management System · 62Online Shopping Portal · 43ZOO Management System · 37ART Gallery Management System · 36Online Fire Reporting System · 32Complaint Management System · 32Student Record System · 29Beauty Parlour Management System · 28User Registration & Login AND User Management System · 25Land Record System · 25Pre-school Enrollment System · 25Dairy Farm Shop Management System · 24