Vulnerabilidades em PHPGurukul

706 resultados
Análise Vexday

Com 706 CVEs catalogadas e 19 novas entradas nos últimos 90 dias, o portfólio de vulnerabilidades em produtos PHPGurukul demonstra volume expressivo e ritmo contínuo de descoberta. A falha mais prevalente é CWE-89 (SQL Injection), o que é coerente com o perfil de aplicações PHP orientadas a banco de dados; o CVE mais perigoso atualmente ativo é CVE-2023-0562, com score EPSS de 0,4117 — valor relevante que indica probabilidade não negligenciável de exploração. Embora a taxa de exploração confirmada (0 entradas no CISA KEV) esteja abaixo da média geral do catálogo, a existência de 20 vulnerabilidades com PoC pública e 13 de severidade crítica representa superfície de ataque considerável para equipes que dependem dessas aplicações. A presença de código de prova de conceito disponível publicamente eleva o risco prático mesmo sem confirmação formal de exploração em larga escala, exigindo atenção prioritária na aplicação de patches e validação de entradas.

CVE-2023-0562HIGHPHPGurukul Bank Locker Management System Login index.php sql injectionEPSS 44.3%CVE-2023-0563LOWPHPGurukul Bank Locker Management System Assign Locker add-locker-form.php cross site scriptingEPSS 37.6%CVE-2023-0527LOWPHPGurukul Online Security Guards Hiring System search-request.php cross site scriptingEPSS 6.1%CVE-2023-3187MEDIUMPHPGurukul Teachers Record Management System Profile Picture changeimage.php unrestricted uploadEPSS 2.6%CVE-2025-2473MEDIUMPHPGurukul Company Visitor Management System Sign In index.php sql injectionEPSS 2.4%CVE-2025-7160MEDIUMPHPGurukul Zoo Management System index.php sql injectionEPSS 1.7%CVE-2023-7173MEDIUMPHPGurukul Hospital Management System registration.php cross site scriptingEPSS 1.5%CVE-2023-7172HIGHPHPGurukul Hospital Management System Admin Dashboard sql injectionEPSS 1.5%CVE-2024-9326MEDIUMPHPGurukul Online Shopping Portal Admin Panel index.php sql injectionEPSS 1.4%CVE-2024-3690MEDIUMPHPGurukul Small CRM Change Password sql injectionEPSS 1.3%CVE-2023-1964HIGHPHPGurukul Bank Locker Management System Password Reset recovery.php sql injectionEPSS 1.0%CVE-2023-0641LOWPHPGurukul Employee Leaves Management System changepassword.php weak passwordEPSS 1.0%CVE-2023-6648MEDIUMPHPGurukul Nipah Virus Testing Management System password-recovery.php sql injectionEPSS 1.0%CVE-2023-6076MEDIUMPHPGurukul Restaurant Table Booking System Reservation Status booking-details.php information disclosureEPSS 1.0%CVE-2024-3769HIGHPHPGurukul Student Record System login.php sql injectionEPSS 0.9%CVE-2024-3691HIGHPHPGurukul Small CRM Registration Page sql injectionEPSS 0.9%CVE-2024-0286MEDIUMPHPGurukul Hospital Management System Contact Form index.php#contact_us cross site scriptingEPSS 0.9%CVE-2024-4294MEDIUMPHPGurukul Doctor Appointment Management System view-appointment-detail.php resource injectionEPSS 0.9%CVE-2024-3770MEDIUMPHPGurukul Student Record System sql injectionEPSS 0.8%CVE-2025-1588MEDIUMPHPGurukul Online Nurse Hiring System manage-nurse.php path traversalEPSS 0.8%