CVEs we hold for Php
Records whose assigning authority named Php as the affected vendor. Newest identifiers first, capped at 200.
CVE-2026-90851PHPGurukul Hostel Management System checklogin.php access controlPHPGurukul Hostel Management System
CVE-2026-90850PHPGurukul Hostel Management System manage-students.php cross site scriptingPHPGurukul Hostel Management System
CVE-2026-90846PHPGurukul Daily Expense Tracker System forgot-password.php sql injectionPHPGurukul Daily Expense Tracker System
CVE-2026-90845PHPGurukul Daily Expense Tracker System sidebar.php cross site scriptingPHPGurukul Daily Expense Tracker System
CVE-2026-90844PHPGurukul Daily Expense Tracker System Login index.php sql injectionPHPGurukul Daily Expense Tracker System
CVE-2026-90842PHPGurukul Blood Donor Management System Login_Model.php cleartext storage in filePHPGurukul Blood Donor Management System
CVE-2026-90841PHPGurukul Blood Donor Management System Report Endpoint Report.php sql injectionPHPGurukul Blood Donor Management System
CVE-2026-90840PHPGurukul Blood Donor Management System Admin Controllers Dashboard.php __construct improper authenticationPHPGurukul Blood Donor Management System
CVE-2026-90575PHPGurukul Small CRM Login Success login.php unserialize deserializationPHPGurukul Small CRM
CVE-2026-90519PHPGurukul Bank Locker Management System add-locker-form.php unrestricted uploadPHPGurukul Bank Locker Management System
CVE-2026-90518PHPGurukul Bank Locker Management System sidebar.php access controlPHPGurukul Bank Locker Management System
CVE-2026-90517PHPGurukul Bank Locker Management System view-assign-locker.php authorizationPHPGurukul Bank Locker Management System
CVE-2026-84308phpseclib — non-constant-time X25519 scalar multiplication permits full private-key recoveryphpseclib
CVE-2026-82424PHPGurukul Student Information System student_edit1.php sql injectionPHPGurukul Student Information System
CVE-2026-75089PHPGurukul Complaint Management System check_availability.php sql injectionPHPGurukul Complaint Management System
CVE-2026-67434PHP_CodeSniffer gitblame report command injection via crafted filenamePHPCSStandards PHP_CodeSniffer
CVE-2026-6704Blog Settings <= 1.0 - Reflected Cross-Site Scripting via 'page' Parameterphpsandeepkumar Blog Settings
CVE-2026-6573PHPEMS Instant Exam Creation exams.master.php temppage server-side request forgeryn/a PHPEMS
CVE-2026-6193PHPGurukul Daily Expense Tracking System register.php sql injectionPHPGurukul Daily Expense Tracking System
CVE-2026-6162PHPGurukul Company Visitor Management System bwdates-reports-details.php cross site scriptingPHPGurukul Company Visitor Management System
CVE-2026-59933PhpSpreadsheet: XLS/OLE sector-chain self-loop causes memory exhaustionPHPOffice PhpSpreadsheet
CVE-2026-59932PhpSpreadsheet: Gnumeric reader unbounded gzip expansion causes memory exhaustionPHPOffice PhpSpreadsheet
CVE-2026-59931PhpSpreadsheet: SSRF bypass via HTTP redirect in WEBSERVICE() domain whitelistPHPOffice PhpSpreadsheet
CVE-2026-5840PHPGurukul News Portal Project check_availability.php sql injectionPHPGurukul News Portal Project
CVE-2026-5839PHPGurukul News Portal Project add-subcategory.php sql injectionPHPGurukul News Portal Project
CVE-2026-5838PHPGurukul News Portal Project add-subadmins.php sql injectionPHPGurukul News Portal Project
CVE-2026-5837PHPGurukul News Portal Project news-details.php sql injectionPHPGurukul News Portal Project
CVE-2026-5814PHPGurukul Online Course Registration check_availability.php sql injectionPHPGurukul Online Course Registration
CVE-2026-5813PHPGurukul Online Course Registration check_availability.php sql injectionPHPGurukul Online Course Registration
CVE-2026-57996phpMyFAQ - Privilege Escalation via Missing SuperAdmin Guard in user/add EndpointphpMyFAQ
CVE-2026-57995phpMyFAQ - Privilege Escalation via Missing Self-Rights Constraint in GroupController::updatePermissionsphpMyFAQ
CVE-2026-57994phpMyFAQ - Information Disclosure of Inactive FAQ Content via Public API EndpointsphpMyFAQ
CVE-2026-57961phpMyFAQ - Authenticated Path Traversal in PDF Export via concatenatePaths FunctionphpMyFAQ
CVE-2026-5641PHPGurukul Online Shopping Portal Project Parameter update-image1.php sql injectionPHPGurukul Online Shopping Portal Project
CVE-2026-5640PHPGurukul Online Shopping Portal Project Parameter update-image2.php sql injectionPHPGurukul Online Shopping Portal Project
CVE-2026-56396phpMyFAQ - Privilege Escalation via Missing Authorization in editUser() and updateUserRights()phpMyFAQ
CVE-2026-5639PHPGurukul Online Shopping Portal Project Parameter update-image3.php sql injectionPHPGurukul Online Shopping Portal Project
CVE-2026-5636PHPGurukul Online Shopping Portal Project Parameter cancelorder.php sql injectionPHPGurukul Online Shopping Portal Project
CVE-2026-5635PHPGurukul Online Shopping Portal Project Parameter categorywise-products.php sql injectionPHPGurukul Online Shopping Portal Project
CVE-2026-5606PHPGurukul Online Shopping Portal Project Parameter order-details.php sql injectionPHPGurukul Online Shopping Portal Project
CVE-2026-5583PHPGurukul Online Shopping Portal Project Parameter my-profile.php sql injectionPHPGurukul Online Shopping Portal Project
CVE-2026-5560PHPGurukul Online Shopping Portal Project Parameter payment-method.php sql injectionPHPGurukul Online Shopping Portal Project
CVE-2026-55599phpseclib: X.509 certificate validation sends attacker-controlled outbound requests (server-side request forgery) via…phpseclib
CVE-2026-55584phpSysInfo: IP allowlist (PSI_ALLOWED) bypass via spoofed X-Forwarded-For / Client-IP headersphpsysinfo
CVE-2026-5558PHPGurukul PHPGurukul Online Shopping Portal Project Parameter pending-orders.php sql injectionPHPGurukul Online Shopping Portal Project
CVE-2026-5552PHPGurukul Online Shopping Portal Project Parameter sub-category.php sql injectionPHPGurukul Online Shopping Portal Project
CVE-2026-5543PHPGurukul User Registration & Login and User Management System yesterday-reg-users.php sql injectionPHPGurukul User Registration & Login and User Management…
CVE-2026-48979PHP Standard Library: HTTP/2 server-side missing content-length validation enables request smugglingphp-standard-library; php-standard-library/h2
CVE-2026-45062FrankenPHP: Unsafe Unicode Handling in CGI Path Splitting Allows Execution of Non-PHP Filesphp frankenphp
CVE-2026-44167phpseclib: CVE-2024-27355 mitigation bypass — OID amplification DoS in ASN1::decodeOID()phpseclib
CVE-2026-40902PhpSpreadsheet: CPU Denial of Service via Unbounded Row Number in XLSX Row DimensionsPHPOffice PhpSpreadsheet
CVE-2026-40863PhpSpreadsheet: CPU Denial of Service via Unbounded Row Index in SpreadsheetML XML ReaderPHPOffice PhpSpreadsheet
CVE-2026-40296PhpSpreadsheet vulnerable to XSS in HTML writer via custom number format codesPHPOffice PhpSpreadsheet
CVE-2026-40194phpseclib has a variable-time HMAC comparison in SSH2::get_binary_packet() using != instead of hash_equals()phpseclib
CVE-2026-35453PhpSpreadsheet XSS via number format text substitution in HTML WriterPHPOffice PhpSpreadsheet
CVE-2026-34084PhpSpreadsheet SSRF and RCE via PHP stream wrappers in IOFactory::loadPHPOffice PhpSpreadsheet
CVE-2026-3403PHPGurukul Student Record Management System edit-subject.php cross site scriptingPHPGurukul Student Record Management System
CVE-2026-3402PHPGurukul Student Record Management System edit-course.php cross site scriptingPHPGurukul Student Record Management System
CVE-2026-24895FrankenPHP affected by Path Confusion via Unicode casing in CGI path splitting allows execution of arbitrary filesphp frankenphp
CVE-2026-2179PHPGurukul Hospital Management System manage-users.php sql injectionPHPGurukul Hospital Management System
CVE-2026-2134PHPGurukul Hospital Management System manage-doctors.php sql injectionPHPGurukul Hospital Management System
CVE-2026-2088PHPGurukul Beauty Parlour Management System accepted-appointment.php sql injectionPHPGurukul Beauty Parlour Management System
CVE-2026-19207PHPGurukul Company Visitor Management System manage-newvisitors.php cross site scriptingPHPGurukul Company Visitor Management System
CVE-2026-1550PHPGurukul Hospital Management System Admin Dashboard adminviews.py improper authorizationPHPGurukul Hospital Management System
CVE-2026-15324SysBasics Customize My Account for WooCommerce <= 4.4.14 - Authenticated (Shop Manager+) Stored Cross-Site Scripting…phppoet SysBasics Customize My Account for WooCommerce –…
CVE-2026-12137SysBasics Customize My Account for WooCommerce <= 4.3.6 - Reflected Cross-Site Scripting via 'tab' Parameterphppoet SysBasics Customize My Account for WooCommerce –…
CVE-2026-12136SysBasics Customize My Account for WooCommerce <= 4.3.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via…phppoet SysBasics Customize My Account for WooCommerce –…
CVE-2026-1160PHPGurukul Directory Management System Search index.php sql injectionPHPGurukul Directory Management System
CVE-2026-1141PHPGurukul News Portal Add Sub-Admin add-subadmins.php improper authorizationPHPGurukul News Portal
CVE-2026-0803PHPGurukul Online Course Registration System enroll.php sql injectionPHPGurukul Online Course Registration System
CVE-2026-0733PHPGurukul Online Course Registration System manage-students.php sql injectionPHPGurukul Online Course Registration System
CVE-2026-0730PHPGurukul Staff Leave Management System SVG File adminviews.py UPDATE_STAFF cross site scriptingPHPGurukul Staff Leave Management System
CVE-2026-0547PHPGurukul Online Course Registration Student Registration edit-student-profile.php unrestricted uploadPHPGurukul Online Course Registration
CVE-2025-9933PHPGurukul Beauty Parlour Management System view-appointment.php sql injectionPHPGurukul Beauty Parlour Management System
CVE-2025-9932PHPGurukul Beauty Parlour Management System update-image.php sql injectionPHPGurukul Beauty Parlour Management System
CVE-2025-9831PHPGurukul Beauty Parlour Management System edit-services.php sql injectionPHPGurukul Beauty Parlour Management System
CVE-2025-9830PHPGurukul Beauty Parlour Management System add-customer-services.php sql injectionPHPGurukul Beauty Parlour Management System
CVE-2025-9829PHPGurukul Beauty Parlour Management System signup.php sql injectionPHPGurukul Beauty Parlour Management System
CVE-2025-9814PHPGurukul Beauty Parlour Management System contact-us.php sql injectionPHPGurukul Beauty Parlour Management System
CVE-2025-9756PHPGurukul User Management System change-emailid.php sql injectionPHPGurukul User Management System
CVE-2025-9729PHPGurukul Online Course Registration student-registration.php sql injectionPHPGurukul Online Course Registration
CVE-2025-9656PHPGurukul Directory Management System add-directory.php cross site scriptingPHPGurukul Directory Management System
CVE-2025-9307PHPGurukul Online Course Registration session.php sql injectionPHPGurukul Online Course Registration
CVE-2025-9302PHPGurukul User Management System signup.php sql injectionPHPGurukul User Management System
CVE-2025-9024PHPGurukul Beauty Parlour Management System book-appointment.php sql injectionPHPGurukul Beauty Parlour Management System
CVE-2025-9017PHPGurukul Zoo Management System add-foreigner-ticket.php cross site scriptingPHPGurukul Zoo Management System
CVE-2025-9013PHPGurukul Online Shopping Portal Project password-recovery.php sql injectionPHPGurukul Online Shopping Portal Project
CVE-2025-9012PHPGurukul Online Shopping Portal Project bill-ship-addresses.php sql injectionPHPGurukul Online Shopping Portal Project
CVE-2025-9011PHPGurukul Online Shopping Portal Project signup.php sql injectionPHPGurukul Online Shopping Portal Project
CVE-2025-8955PHPGurukul Hospital Management System edit-doctor.php sql injectionPHPGurukul Hospital Management System
CVE-2025-8954PHPGurukul Hospital Management System doctor-specilization.php sql injectionPHPGurukul Hospital Management System
CVE-2025-8951PHPGurukul Teachers Record Management System search.php sql injectionPHPGurukul Teachers Record Management System
CVE-2025-8431PHPGurukul Boat Booking System add-boat.php sql injectionPHPGurukul Boat Booking System
CVE-2025-8179PHPGurukul Local Services Search Engine Management System changeimage.php sql injectionPHPGurukul Local Services Search Engine Management System
CVE-2025-8158PHPGurukul Login and User Management System yesterday-reg-users.php sql injectionPHPGurukul Login and User Management System
CVE-2025-8157PHPGurukul User Registration & Login and User Management lastthirtyays-reg-users.php sql injectionPHPGurukul User Registration & Login and User Management
CVE-2025-8156PHPGurukul User Registration & Login and User Management lastsevendays-reg-users.php sql injectionPHPGurukul User Registration & Login and User Management
CVE-2025-8134PHPGurukul BP Monitoring Management System bwdates-report-result.php sql injectionPHPGurukul BP Monitoring Management System
CVE-2025-8115PHPGurukul Taxi Stand Management System new-autoortaxi-entry-form.php cross site scriptingPHPGurukul Taxi Stand Management System
CVE-2025-7946PHPGurukul Apartment Visitors Management System HTTP POST Request search-visitor.php cross site scriptingPHPGurukul Apartment Visitors Management System
CVE-2025-7944PHPGurukul Taxi Stand Management System search.php cross site scriptingPHPGurukul Taxi Stand Management System
CVE-2025-7943PHPGurukul Taxi Stand Management System search-autoortaxi.php cross site scriptingPHPGurukul Taxi Stand Management System
CVE-2025-7942PHPGurukul Taxi Stand Management System admin-profile.php cross site scriptingPHPGurukul Taxi Stand Management System
CVE-2025-7941PHPGurukul Time Table Generator System profile.php cross site scriptingPHPGurukul Time Table Generator System
CVE-2025-7927PHPGurukul Online Banquet Booking System view-user-queries.php sql injectionPHPGurukul Online Banquet Booking System
CVE-2025-7926PHPGurukul Online Banquet Booking System booking-search.php cross site scriptingPHPGurukul Online Banquet Booking System
CVE-2025-7925PHPGurukul Online Banquet Booking System login.php cross site scriptingPHPGurukul Online Banquet Booking System
CVE-2025-7924PHPGurukul Online Banquet Booking System admin-profile.php cross site scriptingPHPGurukul Online Banquet Booking System
CVE-2025-7858PHPGurukul Apartment Visitors Management System HTTP POST Request admin-profile.php cross site scriptingPHPGurukul Apartment Visitors Management System
CVE-2025-7857PHPGurukul Apartment Visitors Management System HTTP POST Request bwdates-passreports-details.php cross site scriptingPHPGurukul Apartment Visitors Management System
CVE-2025-7856PHPGurukul Apartment Visitors Management System HTTP POST Request pass-details.php cross site scriptingPHPGurukul Apartment Visitors Management System
CVE-2025-7834PHPGurukul Complaint Management System cross-site request forgeryPHPGurukul Complaint Management System
CVE-2025-7819PHPGurukul Apartment Visitors Management System HTTP POST Request create-pass.php cross site scriptingPHPGurukul Apartment Visitors Management System
CVE-2025-7818PHPGurukul Apartment Visitors Management System HTTP POST Request category.php cross site scriptingPHPGurukul Apartment Visitors Management System
CVE-2025-7817PHPGurukul Apartment Visitors Management System HTTP POST Request bwdates-reports.php cross site scriptingPHPGurukul Apartment Visitors Management System
CVE-2025-7816PHPGurukul Apartment Visitors Management System HTTP POST Request visitor-detail.php cross site scriptingPHPGurukul Apartment Visitors Management System
CVE-2025-7815PHPGurukul Apartment Visitors Management System HTTP POST Request manage-newvisitors.php cross site scriptingPHPGurukul Apartment Visitors Management System
CVE-2025-7802PHPGurukul Complaint Management System complaint-search.php cross site scriptingPHPGurukul Complaint Management System
CVE-2025-7791PHPGurukul Online Security Guards Hiring System search.php cross site scriptingPHPGurukul Online Security Guards Hiring System
CVE-2025-7767PHPGurukul Art Gallery Management System edit-art-medium-detail.php cross site scriptingPHPGurukul Art Gallery Management System
CVE-2025-7757PHPGurukul Land Record System edit-property.php sql injectionPHPGurukul Land Record System
CVE-2025-7604PHPGurukul Hospital Management System user-login.php sql injectionPHPGurukul Hospital Management System
CVE-2025-7601PHPGurukul Online Library Management System student-history.php cross site scriptingPHPGurukul Online Library Management System
CVE-2025-7600PHPGurukul Online Library Management System student-history.php sql injectionPHPGurukul Online Library Management System
CVE-2025-7599PHPGurukul Dairy Farm Shop Management System invoice.php sql injectionPHPGurukul Dairy Farm Shop Management System
CVE-2025-7592PHPGurukul Dairy Farm Shop Management System invoices.php sql injectionPHPGurukul Dairy Farm Shop Management System
CVE-2025-7591PHPGurukul Dairy Farm Shop Management System view-invoice.php sql injectionPHPGurukul Dairy Farm Shop Management System
CVE-2025-7590PHPGurukul Dairy Farm Shop Management System edit-category.php sql injectionPHPGurukul Dairy Farm Shop Management System
CVE-2025-7589PHPGurukul Dairy Farm Shop Management System edit-company.php sql injectionPHPGurukul Dairy Farm Shop Management System
CVE-2025-7588PHPGurukul Dairy Farm Shop Management System edit-product.php sql injectionPHPGurukul Dairy Farm Shop Management System
CVE-2025-7585PHPGurukul Online Fire Reporting System manage-site.php sql injectionPHPGurukul Online Fire Reporting System
CVE-2025-7584PHPGurukul Online Fire Reporting System add-team.php sql injectionPHPGurukul Online Fire Reporting System
CVE-2025-7583PHPGurukul Online Fire Reporting System all-requests.php sql injectionPHPGurukul Online Fire Reporting System
CVE-2025-7582PHPGurukul Online Fire Reporting System assigned-requests.php sql injectionPHPGurukul Online Fire Reporting System
CVE-2025-7563PHPGurukul Online Fire Reporting System completed-requests.php sql injectionPHPGurukul Online Fire Reporting System
CVE-2025-7562PHPGurukul Online Fire Reporting System new-requests.php sql injectionPHPGurukul Online Fire Reporting System
CVE-2025-7561PHPGurukul Online Fire Reporting System team-ontheway-requests.php sql injectionPHPGurukul Online Fire Reporting System
CVE-2025-7560PHPGurukul Online Fire Reporting System workin-progress-requests.php sql injectionPHPGurukul Online Fire Reporting System
CVE-2025-7559PHPGurukul Online Fire Reporting System bwdates-report-result.php sql injectionPHPGurukul Online Fire Reporting System
CVE-2025-7543PHPGurukul User Registration & Login and User Management System manage-users.php sql injectionPHPGurukul User Registration & Login and User Management…
CVE-2025-7542PHPGurukul User Registration & Login and User Management System user-profile.php sql injectionPHPGurukul User Registration & Login and User Management…
CVE-2025-7534PHPGurukul Student Result Management System GET Parameter notice-details.php sql injectionPHPGurukul Student Result Management System
CVE-2025-7522PHPGurukul Vehicle Parking Management System bwdates-reports-details.php sql injectionPHPGurukul Vehicle Parking Management System
CVE-2025-7521PHPGurukul Vehicle Parking Management System index.php sql injectionPHPGurukul Vehicle Parking Management System
CVE-2025-7520PHPGurukul Vehicle Parking Management System manage-category.php sql injectionPHPGurukul Vehicle Parking Management System
CVE-2025-7492PHPGurukul Vehicle Parking Management System manage-incomingvehicle.php sql injectionPHPGurukul Vehicle Parking Management System
CVE-2025-7491PHPGurukul Vehicle Parking Management System manage-outgoingvehicle.php sql injectionPHPGurukul Vehicle Parking Management System
CVE-2025-7490PHPGurukul Vehicle Parking Management System reg-users.php sql injectionPHPGurukul Vehicle Parking Management System
CVE-2025-7489PHPGurukul Vehicle Parking Management System search-vehicle.php sql injectionPHPGurukul Vehicle Parking Management System
CVE-2025-7484PHPGurukul Vehicle Parking Management System view-outgoingvehicle-detail.php sql injectionPHPGurukul Vehicle Parking Management System
CVE-2025-7483PHPGurukul Vehicle Parking Management System forgot-password.php sql injectionPHPGurukul Vehicle Parking Management System
CVE-2025-7482PHPGurukul Vehicle Parking Management System print.php sql injectionPHPGurukul Vehicle Parking Management System
CVE-2025-7481PHPGurukul Vehicle Parking Management System profile.php sql injectionPHPGurukul Vehicle Parking Management System
CVE-2025-7480PHPGurukul Vehicle Parking Management System signup.php sql injectionPHPGurukul Vehicle Parking Management System
CVE-2025-7479PHPGurukul Vehicle Parking Management System view--detail.php sql injectionPHPGurukul Vehicle Parking Management System
CVE-2025-7177PHPGurukul Car Washing Management System editcar-washpoint.php sql injectionPHPGurukul Car Washing Management System
CVE-2025-7176PHPGurukul Hospital Management System view-medhistory.php sql injectionPHPGurukul Hospital Management System
CVE-2025-7165PHPGurukul/Campcodes Cyber Cafe Management System forgot-password.php sql injectionPHPGurukul Cyber Cafe Management System; Campcodes Cyber…
CVE-2025-7164PHPGurukul/Campcodes Cyber Cafe Management System index.php sql injectionPHPGurukul Cyber Cafe Management System; Campcodes Cyber…
CVE-2025-7163PHPGurukul Zoo Management System add-animals.php sql injectionPHPGurukul Zoo Management System
CVE-2025-7162PHPGurukul Zoo Management System add-foreigners-ticket.php sql injectionPHPGurukul Zoo Management System
CVE-2025-7161PHPGurukul Zoo Management System add-normal-ticket.php sql injectionPHPGurukul Zoo Management System
CVE-2025-7160PHPGurukul Zoo Management System index.php sql injectionPHPGurukul Zoo Management System
CVE-2025-7159PHPGurukul Zoo Management System manage-animals.php sql injectionPHPGurukul Zoo Management System
200 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.
Everything on this page is free. Public data. Withholding it protects nothing.