Phpgurukul Student Record System vulnerabilities
29 known vulnerabilities affecting phpgurukul/student_record_system.
Total CVEs
29
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL8HIGH11MEDIUM10
Vulnerabilities
Page 2 of 2
CVE-2024-44632P3MEDIUMCVSS 6.5v3.202025-11-14
CVE-2024-44632 [MEDIUM] CWE-89 CVE-2024-44632: PHPGurukul Student Record System 3.20 is vulnerable to SQL Injection via the id and emailid paramete
PHPGurukul Student Record System 3.20 is vulnerable to SQL Injection via the id and emailid parameters in password-recovery.php.
nvd
CVE-2024-44633P3MEDIUMCVSS 6.5v3.202025-11-14
CVE-2024-44633 [MEDIUM] CWE-89 CVE-2024-44633: PHPGurukul Student Record System 3.20 is vulnerable to SQL Injection via the currentpassword paramet
PHPGurukul Student Record System 3.20 is vulnerable to SQL Injection via the currentpassword parameter in change-password.php.
nvd
CVE-2024-44636P3MEDIUMCVSS 6.5v3.202025-11-14
CVE-2024-44636 [MEDIUM] CWE-89 CVE-2024-44636: PHPGurukul Student Record System 3.20 is vulnerable to SQL Injection via the adminname and aemailid
PHPGurukul Student Record System 3.20 is vulnerable to SQL Injection via the adminname and aemailid parameters in /admin-profile.php.
nvd
CVE-2025-63955P3HIGHCVSS 7.5v3.22025-11-18
CVE-2025-63955 [HIGH] CWE-352 CVE-2025-63955: A Cross-Site Request Forgery (CSRF) vulnerability in the manage-students.php component of PHPGurukul
A Cross-Site Request Forgery (CSRF) vulnerability in the manage-students.php component of PHPGurukul Student Record System v3.2 allows an attacker to trick an authenticated administrator into submitting a forged request. This leads to the unauthorized deletion of user accounts, causing a Denial of Service (DoS).
nvd
CVE-2024-55016P3MEDIUMCVSS 6.5v3.202025-11-14
CVE-2024-55016 [MEDIUM] CWE-89 CVE-2024-55016: PHPGurukul Student Record Management System 3.20 is vulnerable to SQL Injection via the id and passw
PHPGurukul Student Record Management System 3.20 is vulnerable to SQL Injection via the id and password parameters in login.php.
nvd
CVE-2024-27685P3HIGHCVSS 7.1v3.202025-06-25
CVE-2024-27685 [HIGH] CWE-89 CVE-2024-27685: SQL Injection vulnerability in Student Record system Using PHP and MySQL v.3.20 allows a remote atta
SQL Injection vulnerability in Student Record system Using PHP and MySQL v.3.20 allows a remote attacker to obtain sensitive information via a crafted payload to the $cshortname, $cfullname, and $cdate variables.
nvd
CVE-2024-44635P4MEDIUMCVSS 6.1v3.202025-11-14
CVE-2024-44635 [MEDIUM] CWE-79 CVE-2024-44635: PHPGurukul Student Record System 3.20 is vulnerable to Cross Site Scripting (XSS) via adminname and
PHPGurukul Student Record System 3.20 is vulnerable to Cross Site Scripting (XSS) via adminname and aemailid parameters in /admin-profile.php.
nvd
CVE-2026-3402P4MEDIUMCVSS 4.8v1.02026-03-02
CVE-2026-3402 [MEDIUM] CWE-79 CVE-2026-3402: A security vulnerability has been detected in PHPGurukul Student Record Management System up to 1.0.
A security vulnerability has been detected in PHPGurukul Student Record Management System up to 1.0. This vulnerability affects unknown code of the file /edit-course.php. Such manipulation of the argument Course Short Name leads to cross site scripting. The attack can be executed remotely. The exploit has been disclosed publicly and may be used.
nvd
CVE-2026-3403P4MEDIUMCVSS 4.8v1.02026-03-02
CVE-2026-3403 [MEDIUM] CWE-79 CVE-2026-3403: A vulnerability was detected in PHPGurukul Student Record Management System 1.0. This issue affects
A vulnerability was detected in PHPGurukul Student Record Management System 1.0. This issue affects some unknown processing of the file /edit-subject.php. Performing a manipulation of the argument Subject 1 results in cross site scripting. The attack is possible to be carried out remotely. The exploit is now public and may be used.
nvd
← Previous2 / 2