Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Phpgurukul

First CVE: Jan 6, 2020Active for: 7 yearsTotal CVEs: 1,062
46.6
VTI Score
High

Phpgurukul maintains a portfolio of open-source management and e-commerce applications, including hospital, zoo, and gallery management systems, that serve as templates and learning platforms for web development. The vendor's vulnerability profile skews strongly toward critical-severity outcomes, with disclosures concentrating on foundational web application flaws including SQL injection, cross-site scripting, code injection, and improper file-upload handling that are characteristic of applications built without defense-in-depth input validation. These weakness classes recur across the vendor's product line, reflecting a structural pattern of insufficient sanitization of user-controlled data at multiple integration points. The broad accessibility and educational positioning of these applications means vulnerabilities affect both production deployments and development environments; defenders should treat this vendor's advisories as high-priority for any exposed instances. Current severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
1,062
Total CVEs
More Total CVEs than 100% of tracked vendors
1.7
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 79% of tracked vendors
8.1
Avg CVSS Score
Higher Avg CVSS Score than 78% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Phpgurukul over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jan 6, 2020
6 years ago
Most Recent CVE
Mar 23, 2026
124 days ago

Products(87 total)

Top CVEs

Signals from CVEs in this vendor scope (1062 CVEs).

1,062 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2023-0562CRITICAL
A vulnerability was found in PHPGurukul Bank Locker Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file index.php
Jan 28, 20239.866NOYES
CVE-2022-29009CRITICAL
Multiple SQL injection vulnerabilities via the username and password parameters in the Admin panel of Cyber Cafe Management System Project v1.0 allows attackers to bypass authentic
May 11, 20229.853NOYES
CVE-2022-29006CRITICAL
Multiple SQL injection vulnerabilities via the username and password parameters in the Admin panel of Directory Management System v1.0 allows attackers to bypass authentication.
May 11, 20229.852NOYES
CVE-2023-0563MEDIUM
A vulnerability classified as problematic has been found in PHPGurukul Bank Locker Management System 1.0. This affects an unknown part of the file add-locker-form.php of the compon
Jan 28, 20234.848NOYES
CVE-2020-5192HIGH
PHPGurukul Hospital Management System in PHP v4.0 suffers from multiple SQL injection vulnerabilities: multiple pages and parameters are not validating user input, and allow for th
Jan 6, 20208.848NOYES
CVE-2022-24263CRITICAL
Hospital Management System v4.0 was discovered to contain a SQL injection vulnerability in /Hospital-Management-System-master/func.php via the email parameter.
Jan 31, 20229.847NOYES
CVE-2020-5307CRITICAL
PHPGurukul Dairy Farm Shop Management System 1.0 is vulnerable to SQL injection, as demonstrated by the username parameter in index.php, the category and CategoryCode parameters in
Jan 7, 20209.847NOYES
CVE-2023-23162CRITICAL
Art Gallery Management System Project v1.0 was discovered to contain a SQL injection vulnerability via the cid parameter at product.php.
Feb 10, 20239.844NOYES
CVE-2022-29007CRITICAL
Multiple SQL injection vulnerabilities via the username and password parameters in the Admin panel of Dairy Farm Shop Management System v1.0 allows attackers to bypass authenticati
May 11, 20229.844NOYES
CVE-2023-23163CRITICAL
Art Gallery Management System Project v1.0 was discovered to contain a SQL injection vulnerability via the editid parameter.
Feb 10, 20239.842NOYES
View all 1,062 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products1,062 CVEs
31%
26%
42%
Severity distribution among all CVEs352,427 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local12 (1.1%)
Network1,050 (98.9%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low1,056 (99.4%)
High6 (0.6%)
Unknown0 (0.0%)
User Interaction
None774 (72.9%)
Unknown0 (0.0%)
Required288 (27.1%)
Privileges Required
Low290 (27.3%)
High106 (10.0%)
None666 (62.7%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (1062 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
16 CVEs
1.5% of CVEs· 95th percentile
ExploitDB
14 CVEs
1.3% of CVEs· 74th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Phpgurukul.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Phpgurukul — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Phpgurukul's Products

View all 4 CNAs →

Top CWEs