Phpgurukul Vulnerabilities
Comprehensive security vulnerability database for Phpgurukul products
4
0
4
0
Severity Distribution
| Description | Vendor / Product | Exploit Status | |||
|---|---|---|---|---|---|
| CVE-2026-3403 | 4.8 | This vulnerability allows an attacker to inject malicious scripts into the student record system, potentially compromising users' data or sessions when they visit the affected page. The attack can be executed remotely by manipulating a specific argument in the URL, making it easy for attackers to exploit. | phpgurukulstudent record system | Exploit Available | about 1 month agoMar 2, 2026 |
| CVE-2026-3402 | 4.8 | An attacker can inject malicious scripts into the PHPGurukul Student Record Management System through the Course Short Name field, potentially allowing them to steal sensitive information from users who visit the compromised page. This vulnerability can be exploited remotely, meaning the attacker doesn't need physical access to the system to carry out the attack. | phpgurukulstudent record system | Exploit Available | about 1 month agoMar 2, 2026 |
| CVE-2024-55270 | 8.8 | This vulnerability allows an attacker to manipulate the database of the student management system by injecting harmful SQL code through the searchdata parameter, potentially exposing sensitive information or altering data. To exploit this, the attacker needs access to the search feature on the admin page. | phpgurukulstudent management system | Exploit Available | about 2 months agoFeb 17, 2026 |
| CVE-2024-55271 | 3.5 | An attacker can trick a logged-in user of the gym management system into unknowingly updating their profile information by sending them a malicious link. This vulnerability requires the user to be logged in and click on the link while visiting the attacker's site, potentially allowing the attacker to change the user's details without their consent. | phpgurukulgym management system | Exploit Available | about 2 months agoFeb 17, 2026 |
About Phpgurukul Security
This page tracks all publicly disclosed security vulnerabilities (CVEs) affecting Phpgurukul products. Our database is updated in real-time from the National Vulnerability Database (NVD) and enriched with exploit information from GitHub and other security research sources.
Each CVE listing includes CVSS severity scores, exploit availability status, AI-powered vulnerability summaries, and links to official patches and security advisories.