Phpgurukul Hospital Management System vulnerabilities
69 known vulnerabilities affecting phpgurukul/hospital_management_system.
Total CVEs
69
CISA KEV
0
Public exploits
5
Exploited in wild
1
Severity breakdown
CRITICAL15HIGH26MEDIUM27LOW1
Vulnerabilities
Page 3 of 4
CVE-2026-2179P3HIGHCVSS 7.2v4.02026-02-08
CVE-2026-2179 [HIGH] CWE-74 CVE-2026-2179: A vulnerability was determined in PHPGurukul Hospital Management System 4.0. This impacts an unknown
A vulnerability was determined in PHPGurukul Hospital Management System 4.0. This impacts an unknown function of the file /admin/manage-users.php. This manipulation of the argument ID causes sql injection. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized.
nvd
CVE-2022-46497P3HIGHCVSS 8.1v1.02024-03-07
CVE-2022-46497 [HIGH] CWE-89 CVE-2022-46497: Hospital Management System 1.0 was discovered to contain a SQL injection vulnerability via the pat_n
Hospital Management System 1.0 was discovered to contain a SQL injection vulnerability via the pat_number parameter at his_doc_view_single_patien.php.
nvd
CVE-2020-22176P3HIGHCVSS 7.5v4.02021-06-22
CVE-2020-22176 [HIGH] CWE-287 CVE-2020-22176: PHPGurukul Hospital Management System in PHP v4.0 has a sensitive information disclosure vulnerabili
PHPGurukul Hospital Management System in PHP v4.0 has a sensitive information disclosure vulnerability in multiple areas. Remote unauthenticated users can exploit the vulnerability to obtain user sensitive information.
nvd
CVE-2025-70063P3MEDIUMCVSS 6.5v4.02026-02-18
CVE-2025-70063 [MEDIUM] CWE-639 CVE-2025-70063: The 'Medical History' module in PHPGurukul Hospital Management System v4.0 contains an Insecure Dire
The 'Medical History' module in PHPGurukul Hospital Management System v4.0 contains an Insecure Direct Object Reference (IDOR) vulnerability. The application fails to verify that the requested 'viewid' parameter belongs to the currently authenticated patient. This allows a user to access the confidential medical records of other patients by iteratin
nvd
CVE-2025-56215P3MEDIUMCVSS 6.5v4.02025-08-25
CVE-2025-56215 [MEDIUM] CWE-89 CVE-2025-56215: phpgurukul Hospital Management System 4.0 is vulnerable to SQL Injection in contact.php via the page
phpgurukul Hospital Management System 4.0 is vulnerable to SQL Injection in contact.php via the pagetitle parameter.
nvd
CVE-2025-70062P4MEDIUMCVSS 6.5v4.02026-02-18
CVE-2025-70062 [MEDIUM] CWE-352 CVE-2025-70062: PHPGurukul Hospital Management System v4.0 contains a Cross-Site Request Forgery (CSRF) vulnerabilit
PHPGurukul Hospital Management System v4.0 contains a Cross-Site Request Forgery (CSRF) vulnerability in the 'Add Doctor' module. The application fails to enforce CSRF token validation on the add-doctor.php endpoint. This allows remote attackers to create arbitrary Doctor accounts (privileged users) by tricking an authenticated administrator into vi
nvd
CVE-2023-7173P4MEDIUMCVSS 5.4v1.02023-12-30
CVE-2023-7173 [MEDIUM] CWE-79 CVE-2023-7173: A vulnerability, which was classified as problematic, was found in PHPGurukul Hospital Management Sy
A vulnerability, which was classified as problematic, was found in PHPGurukul Hospital Management System 1.0. This affects an unknown part of the file registration.php. The manipulation of the argument First Name leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
nvd
CVE-2025-5584P4MEDIUMCVSS 5.4v4.02025-06-04
CVE-2025-5584 [MEDIUM] CWE-79 CVE-2025-5584: A vulnerability was found in PHPGurukul Hospital Management System 4.0. It has been classified as pr
A vulnerability was found in PHPGurukul Hospital Management System 4.0. It has been classified as problematic. Affected is an unknown function of the file /doctor/edit-patient.php?editid=2 of the component POST Parameter Handler. The manipulation of the argument patname leads to cross site scripting. It is possible to launch the attack remotely. The ex
nvd
CVE-2020-26627P4MEDIUMCVSS 4.9v4.02024-01-10
CVE-2020-26627 [MEDIUM] CWE-89 CVE-2020-26627: A Time-Based SQL Injection vulnerability was discovered in Hospital Management System V4.0 which can
A Time-Based SQL Injection vulnerability was discovered in Hospital Management System V4.0 which can allow an attacker to dump database information via a crafted payload entered into the 'Admin Remark' parameter under the 'Contact Us Queries -> Unread Query' tab.
nvd
CVE-2024-0286P4MEDIUMCVSS 6.1v1.02024-01-07
CVE-2024-0286 [MEDIUM] CWE-79 CVE-2024-0286: A vulnerability, which was classified as problematic, was found in PHPGurukul Hospital Management Sy
A vulnerability, which was classified as problematic, was found in PHPGurukul Hospital Management System 1.0. This affects an unknown part of the file index.php#contact_us of the component Contact Form. The manipulation of the argument Name/Email/Message leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been
nvd
CVE-2025-6613P4MEDIUMCVSS 5.4v4.02025-06-25
CVE-2025-6613 [MEDIUM] CWE-79 CVE-2025-6613: A vulnerability classified as problematic was found in PHPGurukul Hospital Management System 4.0. Af
A vulnerability classified as problematic was found in PHPGurukul Hospital Management System 4.0. Affected by this vulnerability is an unknown functionality of the file /doctor/manage-patient.php. The manipulation of the argument Name leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and ma
nvd
CVE-2020-26630P4MEDIUMCVSS 4.9v4.02024-01-10
CVE-2020-26630 [MEDIUM] CWE-89 CVE-2020-26630: A Time-Based SQL Injection vulnerability was discovered in Hospital Management System V4.0 which can
A Time-Based SQL Injection vulnerability was discovered in Hospital Management System V4.0 which can allow an attacker to dump database information via a special payload in the 'Doctor Specialization' field under the 'Go to Doctors' tab after logging in as an admin.
nvd
CVE-2024-11675P4MEDIUMCVSS 5.4v1.02024-11-26
CVE-2024-11675 [MEDIUM] CWE-79 CVE-2024-11675: A vulnerability has been found in CodeAstro Hospital Management System 1.0 and classified as problem
A vulnerability has been found in CodeAstro Hospital Management System 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /backend/admin/his_admin_register_patient.php of the component Add Patient Details Page. The manipulation of the argument pat_fname/pat_ailment/pat_lname/pat_age/pat_dob/pat_n
nvd
CVE-2020-25271P4MEDIUMCVSS 5.4v4.02020-10-08
CVE-2020-25271 [MEDIUM] CWE-79 CVE-2020-25271: PHPGurukul hospital-management-system-in-php 4.0 allows XSS via admin/patient-search.php, doctor/sea
PHPGurukul hospital-management-system-in-php 4.0 allows XSS via admin/patient-search.php, doctor/search.php, book-appointment.php, doctor/appointment-history.php, or admin/appointment-history.php.
nvd
CVE-2020-26628P4MEDIUMCVSS 6.1v4.02024-01-10
CVE-2020-26628 [MEDIUM] CWE-79 CVE-2020-26628: A Cross-Site Scripting (XSS) vulnerability was discovered in Hospital Management System V4.0 which a
A Cross-Site Scripting (XSS) vulnerability was discovered in Hospital Management System V4.0 which allows an attacker to execute arbitrary web scripts or HTML code via a malicious payload appended to a username on the 'Edit Profile" page and triggered by another user visiting the profile.
nvd
CVE-2020-22167P4MEDIUMCVSS 5.4v4.02021-06-22
CVE-2020-22167 [MEDIUM] CWE-79 CVE-2020-22167: PHPGurukul Hospital Management System in PHP v4.0 has a Persistent Cross-Site Scripting vulnerabilit
PHPGurukul Hospital Management System in PHP v4.0 has a Persistent Cross-Site Scripting vulnerability in \hms\admin\appointment-history.php. Remote registered users can exploit the vulnerability to obtain user cookie data.
nvd
CVE-2022-42206P4MEDIUMCVSS 5.4v4.02022-10-21
CVE-2022-42206 [MEDIUM] CWE-79 CVE-2022-42206: PHPGurukul Hospital Management System In PHP V 4.0 is vulnerable to Cross Site Scripting (XSS) via d
PHPGurukul Hospital Management System In PHP V 4.0 is vulnerable to Cross Site Scripting (XSS) via doctor/view-patient.php, admin/view-patient.php, and view-medhistory.php.
nvd
CVE-2024-10807P4MEDIUMCVSS 4.8v4.02024-11-05
CVE-2024-10807 [MEDIUM] CWE-74 CVE-2024-10807: A vulnerability was found in PHPGurukul Hospital Management System 4.0. It has been rated as problem
A vulnerability was found in PHPGurukul Hospital Management System 4.0. It has been rated as problematic. This issue affects some unknown processing of the file hms/doctor/search.php. The manipulation of the argument searchdata leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be
nvd
CVE-2020-5193P4MEDIUMCVSS 6.1v4.02020-01-14
CVE-2020-5193 [MEDIUM] CWE-79 CVE-2020-5193: PHPGurukul Hospital Management System in PHP v4.0 suffers from multiple reflected XSS vulnerabilitie
PHPGurukul Hospital Management System in PHP v4.0 suffers from multiple reflected XSS vulnerabilities via the searchdata or Doctorspecialization parameter.
nvd
CVE-2024-46237P4MEDIUMCVSS 5.4v4.02024-10-09
CVE-2024-46237 [MEDIUM] CWE-79 CVE-2024-46237: PHPGurukul Hospital Management System 4.0 is vulnerable to Cross Site Scripting (XSS) via the patnam
PHPGurukul Hospital Management System 4.0 is vulnerable to Cross Site Scripting (XSS) via the patname, pataddress, and medhis parameters in doctor/add-patient.php and doctor/edit-patient.php.
nvd