Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

PHPGurukul — Vulnerabilities & Security Advisories 720

Browse all 720 CVE security advisories affecting PHPGurukul. AI-powered Chinese analysis, POCs, and references for each vulnerability.

PHPGurukul operates as an educational platform providing free coding tutorials and project resources, primarily targeting students and beginners in web development. Despite its benign educational intent, the platform has been associated with a significant number of security issues, currently holding 705 recorded CVEs. These vulnerabilities predominantly stem from poorly secured downloadable source code and outdated scripts shared within its repository. Common flaw classes include Remote Code Execution (RCE), Cross-Site Scripting (XSS), and SQL Injection, often resulting from insufficient input validation and hardcoded credentials in legacy projects. While PHPGurukul itself is not typically the direct target of sophisticated attacks, the widespread distribution of its unpatched materials creates a substantial attack surface for downstream users. The high volume of CVEs reflects systemic neglect in code review processes rather than a single major breach, highlighting the risks inherent in distributing unvetted software assets to novice developers.

CVE ID Title CVSS Severity Published
CVE-2026-5560 PHPGurukul Online Shopping Portal Project Parameter payment-method.php sql injection — Online Shopping Portal Project CWE-89 6.3 Medium 2026-04-05
CVE-2026-5558 PHPGurukul PHPGurukul Online Shopping Portal Project Parameter pending-orders.php sql injection — PHPGurukul Online Shopping Portal Project CWE-89 6.3 Medium 2026-04-05
CVE-2026-5552 PHPGurukul Online Shopping Portal Project Parameter sub-category.php sql injection — Online Shopping Portal Project CWE-89 6.3 Medium 2026-04-05
CVE-2026-5543 PHPGurukul User Registration & Login and User Management System yesterday-reg-users.php sql injection — User Registration & Login and User Management System CWE-89 6.3 Medium 2026-04-05
CVE-2026-3403 PHPGurukul Student Record Management System edit-subject.php cross site scripting — Student Record Management System CWE-79 2.4 Low 2026-03-02
CVE-2026-3402 PHPGurukul Student Record Management System edit-course.php cross site scripting — Student Record Management System CWE-79 2.4 Low 2026-03-02
CVE-2026-2179 PHPGurukul Hospital Management System manage-users.php sql injection — Hospital Management System CWE-89 4.7 Medium 2026-02-08
CVE-2026-2134 PHPGurukul Hospital Management System manage-doctors.php sql injection — Hospital Management System CWE-89 4.7 Medium 2026-02-08
CVE-2026-2088 PHPGurukul Beauty Parlour Management System accepted-appointment.php sql injection — Beauty Parlour Management System CWE-89 7.3 High 2026-02-07
CVE-2026-1550 PHPGurukul Hospital Management System Admin Dashboard adminviews.py improper authorization — Hospital Management System CWE-285 6.3 Medium 2026-01-28
CVE-2026-1424 PHPGurukul News Portal Profile Pic unrestricted upload — News Portal CWE-434 4.7 Medium 2026-01-26
CVE-2026-1160 PHPGurukul Directory Management System Search index.php sql injection — Directory Management System CWE-89 7.3 High 2026-01-19
CVE-2026-1142 PHPGurukul News Portal cross-site request forgery — News Portal CWE-352 4.3 Medium 2026-01-19
CVE-2026-1141 PHPGurukul News Portal Add Sub-Admin add-subadmins.php improper authorization — News Portal CWE-285 6.3 Medium 2026-01-19
CVE-2026-0803 PHPGurukul Online Course Registration System enroll.php sql injection — Online Course Registration System CWE-89 6.3 Medium 2026-01-09
CVE-2026-0733 PHPGurukul Online Course Registration System manage-students.php sql injection — Online Course Registration System CWE-89 6.3 Medium 2026-01-08
CVE-2026-0730 PHPGurukul Staff Leave Management System SVG File adminviews.py UPDATE_STAFF cross site scripting — Staff Leave Management System CWE-79 2.4 Low 2026-01-08
CVE-2026-0547 PHPGurukul Online Course Registration Student Registration edit-student-profile.php unrestricted upload — Online Course Registration CWE-434 6.3 Medium 2026-01-02
CVE-2025-15406 PHPGurukul Online Course Registration authorization — Online Course Registration CWE-862 6.3 Medium 2026-01-01
CVE-2025-15390 PHPGurukul Small CRM edit-user.php authorization — Small CRM CWE-862 6.3 Medium 2025-12-31
CVE-2025-13577 PHPGurukul Hostel Management System register-complaint.php cross site scripting — Hostel Management System CWE-79 3.5 Low 2025-11-24
CVE-2025-13247 PHPGurukul Tourism Management System user-bookings.php sql injection — Tourism Management System CWE-89 7.3 High 2025-11-16
CVE-2025-12616 PHPGurukul News Portal settings.py insertion of sensitive information into debugging code — News Portal CWE-215 3.7 Low 2025-11-03
CVE-2025-12615 PHPGurukul News Portal settings.py hard-coded key — News Portal CWE-321 5.0 Medium 2025-11-03
CVE-2025-12312 PHPGurukul Curfew e-Pass Management System view-pass-detail.php cross site scripting — Curfew e-Pass Management System CWE-79 2.4 Low 2025-10-27
CVE-2025-12311 PHPGurukul Curfew e-Pass Management System edit-category-detail.php cross site scripting — Curfew e-Pass Management System CWE-79 2.4 Low 2025-10-27
CVE-2025-12303 PHPGurukul Curfew e-Pass Management System admin-profile.php cross site scripting — Curfew e-Pass Management System CWE-79 2.4 Low 2025-10-27
CVE-2025-11507 PHPGurukul Beauty Parlour Management System search-invoices.php sql injection — Beauty Parlour Management System CWE-89 7.3 High 2025-10-08
CVE-2025-11506 PHPGurukul Beauty Parlour Management System search-appointment.php sql injection — Beauty Parlour Management System CWE-89 7.3 High 2025-10-08
CVE-2025-11505 PHPGurukul Beauty Parlour Management System new-appointment.php sql injection — Beauty Parlour Management System CWE-89 7.3 High 2025-10-08

This page lists every published CVE security advisory associated with PHPGurukul. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.