Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

PHPGurukul — Vulnerabilities & Security Advisories 705

Browse all 705 CVE security advisories affecting PHPGurukul. AI-powered Chinese analysis, POCs, and references for each vulnerability.

PHPGurukul operates as an educational platform providing free coding tutorials and project resources, primarily targeting students and beginners in web development. Despite its benign educational intent, the platform has been associated with a significant number of security issues, currently holding 705 recorded CVEs. These vulnerabilities predominantly stem from poorly secured downloadable source code and outdated scripts shared within its repository. Common flaw classes include Remote Code Execution (RCE), Cross-Site Scripting (XSS), and SQL Injection, often resulting from insufficient input validation and hardcoded credentials in legacy projects. While PHPGurukul itself is not typically the direct target of sophisticated attacks, the widespread distribution of its unpatched materials creates a substantial attack surface for downstream users. The high volume of CVEs reflects systemic neglect in code review processes rather than a single major breach, highlighting the risks inherent in distributing unvetted software assets to novice developers.

CVE IDTitleCVSSSeverityPublished
CVE-2026-0733 PHPGurukul Online Course Registration System manage-students.php sql injection — Online Course Registration SystemCWE-89 6.3 Medium2026-01-08
CVE-2026-0730 PHPGurukul Staff Leave Management System SVG File adminviews.py UPDATE_STAFF cross site scripting — Staff Leave Management SystemCWE-79 2.4 Low2026-01-08
CVE-2026-0547 PHPGurukul Online Course Registration Student Registration edit-student-profile.php unrestricted upload — Online Course RegistrationCWE-434 6.3 Medium2026-01-02
CVE-2025-15406 PHPGurukul Online Course Registration authorization — Online Course RegistrationCWE-862 6.3 Medium2026-01-01
CVE-2025-15390 PHPGurukul Small CRM edit-user.php authorization — Small CRMCWE-862 6.3 Medium2025-12-31
CVE-2025-13577 PHPGurukul Hostel Management System register-complaint.php cross site scripting — Hostel Management SystemCWE-79 3.5 Low2025-11-24
CVE-2025-13247 PHPGurukul Tourism Management System user-bookings.php sql injection — Tourism Management SystemCWE-89 7.3 High2025-11-16
CVE-2025-12616 PHPGurukul News Portal settings.py insertion of sensitive information into debugging code — News PortalCWE-215 3.7 Low2025-11-03
CVE-2025-12615 PHPGurukul News Portal settings.py hard-coded key — News PortalCWE-321 5.0 Medium2025-11-03
CVE-2025-12312 PHPGurukul Curfew e-Pass Management System view-pass-detail.php cross site scripting — Curfew e-Pass Management SystemCWE-79 2.4 Low2025-10-27
CVE-2025-12311 PHPGurukul Curfew e-Pass Management System edit-category-detail.php cross site scripting — Curfew e-Pass Management SystemCWE-79 2.4 Low2025-10-27
CVE-2025-12303 PHPGurukul Curfew e-Pass Management System admin-profile.php cross site scripting — Curfew e-Pass Management SystemCWE-79 2.4 Low2025-10-27
CVE-2025-11507 PHPGurukul Beauty Parlour Management System search-invoices.php sql injection — Beauty Parlour Management SystemCWE-89 7.3 High2025-10-08
CVE-2025-11506 PHPGurukul Beauty Parlour Management System search-appointment.php sql injection — Beauty Parlour Management SystemCWE-89 7.3 High2025-10-08
CVE-2025-11505 PHPGurukul Beauty Parlour Management System new-appointment.php sql injection — Beauty Parlour Management SystemCWE-89 7.3 High2025-10-08
CVE-2025-11503 PHPGurukul Beauty Parlour Management System manage-services.php sql injection — Beauty Parlour Management SystemCWE-89 7.3 High2025-10-08
CVE-2025-11416 PHPGurukul Beauty Parlour Management System invoices.php sql injection — Beauty Parlour Management SystemCWE-89 7.3 High2025-10-07
CVE-2025-11415 PHPGurukul Beauty Parlour Management System customer-list.php sql injection — Beauty Parlour Management SystemCWE-89 7.3 High2025-10-07
CVE-2025-11390 PHPGurukul Cyber Cafe Management System POST Parameter search.php cross site scripting — Cyber Cafe Management SystemCWE-79 4.3 Medium2025-10-07
CVE-2025-11330 PHPGurukul Beauty Parlour Management System sales-reports-detail.php sql injection — Beauty Parlour Management SystemCWE-89 6.3 Medium2025-10-06
CVE-2025-11112 PHPGurukul Employee Record Management System myprofile.php cross site scripting — Employee Record Management SystemCWE-79 4.3 Medium2025-09-28
CVE-2025-11053 PHPGurukul Small CRM forgot-password.php sql injection — Small CRMCWE-89 7.3 High2025-09-27
CVE-2025-10794 PHPGurukul Car Rental Project search.php cross site scripting — Car Rental ProjectCWE-79 4.3 Medium2025-09-22
CVE-2025-10664 PHPGurukul Small CRM create-ticket.php sql injection — Small CRMCWE-89 7.3 High2025-09-18
CVE-2025-10663 PHPGurukul Online Course Registration my-profile.php sql injection — Online Course RegistrationCWE-89 7.3 High2025-09-18
CVE-2025-10624 PHPGurukul User Management System login.php sql injection — User Management SystemCWE-89 7.3 High2025-09-17
CVE-2025-10604 PHPGurukul Online Discussion Forum edit_member.php sql injection — Online Discussion ForumCWE-89 7.3 High2025-09-17
CVE-2025-10603 PHPGurukul Online Discussion Forum search_result.php sql injection — Online Discussion ForumCWE-89 7.3 High2025-09-17
CVE-2025-10459 PHPGurukul Beauty Parlour Management System all-appointment.php sql injection — Beauty Parlour Management SystemCWE-89 7.3 High2025-09-15
CVE-2025-10403 PHPGurukul Beauty Parlour Management System view-enquiry.php sql injection — Beauty Parlour Management SystemCWE-89 7.3 High2025-09-14

This page lists every published CVE security advisory associated with PHPGurukul. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.