Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

PHPGurukul — Vulnerabilities & Security Advisories 720

Browse all 720 CVE security advisories affecting PHPGurukul. AI-powered Chinese analysis, POCs, and references for each vulnerability.

PHPGurukul operates as an educational platform providing free coding tutorials and project resources, primarily targeting students and beginners in web development. Despite its benign educational intent, the platform has been associated with a significant number of security issues, currently holding 705 recorded CVEs. These vulnerabilities predominantly stem from poorly secured downloadable source code and outdated scripts shared within its repository. Common flaw classes include Remote Code Execution (RCE), Cross-Site Scripting (XSS), and SQL Injection, often resulting from insufficient input validation and hardcoded credentials in legacy projects. While PHPGurukul itself is not typically the direct target of sophisticated attacks, the widespread distribution of its unpatched materials creates a substantial attack surface for downstream users. The high volume of CVEs reflects systemic neglect in code review processes rather than a single major breach, highlighting the risks inherent in distributing unvetted software assets to novice developers.

CVE ID Title CVSS Severity Published
CVE-2026-90851 PHPGurukul Hostel Management System checklogin.php access control — Hostel Management System CWE-284 6.3 Medium 2026-09-15
CVE-2026-90850 PHPGurukul Hostel Management System manage-students.php cross site scripting — Hostel Management System CWE-79 2.4 Low 2026-09-15
CVE-2026-90846 PHPGurukul Daily Expense Tracker System forgot-password.php sql injection — Daily Expense Tracker System CWE-89 7.3 High 2026-09-15
CVE-2026-90845 PHPGurukul Daily Expense Tracker System sidebar.php cross site scripting — Daily Expense Tracker System CWE-79 3.5 Low 2026-09-15
CVE-2026-90844 PHPGurukul Daily Expense Tracker System Login index.php sql injection — Daily Expense Tracker System CWE-89 7.3 High 2026-09-15
CVE-2026-90842 PHPGurukul Blood Donor Management System Login_Model.php cleartext storage in file — Blood Donor Management System CWE-313 3.7 Low 2026-09-14
CVE-2026-90841 PHPGurukul Blood Donor Management System Report Endpoint Report.php sql injection — Blood Donor Management System CWE-89 7.3 High 2026-09-14
CVE-2026-90840 PHPGurukul Blood Donor Management System Admin Controllers Dashboard.php __construct improper authentication — Blood Donor Management System CWE-287 7.3 High 2026-09-14
CVE-2026-90575 PHPGurukul Small CRM Login Success login.php unserialize deserialization — Small CRM CWE-502 3.7 Low 2026-09-13
CVE-2026-90519 PHPGurukul Bank Locker Management System add-locker-form.php unrestricted upload — Bank Locker Management System CWE-434 6.3 Medium 2026-09-13
CVE-2026-90518 PHPGurukul Bank Locker Management System sidebar.php access control — Bank Locker Management System CWE-284 6.3 Medium 2026-09-13
CVE-2026-90517 PHPGurukul Bank Locker Management System view-assign-locker.php authorization — Bank Locker Management System CWE-639 5.3 Medium 2026-09-13
CVE-2026-82424 PHPGurukul Student Information System student_edit1.php sql injection — Student Information System CWE-89 6.3 Medium 2026-08-29
CVE-2026-75089 PHPGurukul Complaint Management System check_availability.php sql injection — Complaint Management System CWE-89 7.3 High 2026-08-18
CVE-2026-19207 PHPGurukul Company Visitor Management System manage-newvisitors.php cross site scripting — Company Visitor Management System CWE-79 2.4 Low 2026-08-07
CVE-2026-6193 PHPGurukul Daily Expense Tracking System register.php sql injection — Daily Expense Tracking System CWE-89 7.3 High 2026-04-13
CVE-2026-6162 PHPGurukul Company Visitor Management System bwdates-reports-details.php cross site scripting — Company Visitor Management System CWE-79 3.5 Low 2026-04-13
CVE-2026-5840 PHPGurukul News Portal Project check_availability.php sql injection — News Portal Project CWE-89 4.7 Medium 2026-04-09
CVE-2026-5839 PHPGurukul News Portal Project add-subcategory.php sql injection — News Portal Project CWE-89 4.7 Medium 2026-04-09
CVE-2026-5838 PHPGurukul News Portal Project add-subadmins.php sql injection — News Portal Project CWE-89 4.7 Medium 2026-04-09
CVE-2026-5837 PHPGurukul News Portal Project news-details.php sql injection — News Portal Project CWE-89 7.3 High 2026-04-09
CVE-2026-5814 PHPGurukul Online Course Registration check_availability.php sql injection — Online Course Registration CWE-89 7.3 High 2026-04-08
CVE-2026-5813 PHPGurukul Online Course Registration check_availability.php sql injection — Online Course Registration CWE-89 7.3 High 2026-04-08
CVE-2026-5641 PHPGurukul Online Shopping Portal Project Parameter update-image1.php sql injection — Online Shopping Portal Project CWE-89 6.3 Medium 2026-04-06
CVE-2026-5640 PHPGurukul Online Shopping Portal Project Parameter update-image2.php sql injection — Online Shopping Portal Project CWE-89 6.3 Medium 2026-04-06
CVE-2026-5639 PHPGurukul Online Shopping Portal Project Parameter update-image3.php sql injection — Online Shopping Portal Project CWE-89 6.3 Medium 2026-04-06
CVE-2026-5636 PHPGurukul Online Shopping Portal Project Parameter cancelorder.php sql injection — Online Shopping Portal Project CWE-89 6.3 Medium 2026-04-06
CVE-2026-5635 PHPGurukul Online Shopping Portal Project Parameter categorywise-products.php sql injection — Online Shopping Portal Project CWE-89 6.3 Medium 2026-04-06
CVE-2026-5606 PHPGurukul Online Shopping Portal Project Parameter order-details.php sql injection — Online Shopping Portal Project CWE-89 6.3 Medium 2026-04-06
CVE-2026-5583 PHPGurukul Online Shopping Portal Project Parameter my-profile.php sql injection — Online Shopping Portal Project CWE-89 6.3 Medium 2026-04-05

This page lists every published CVE security advisory associated with PHPGurukul. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.