VendorsPHPGurukulbeauty_parlour_management_systemall versions
Vulnerabilities

PHPGurukul Beauty Parlour Management System

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

28CVEs
CVE-2024-53480
Phpgurukul's Beauty Parlour Management System v1.1 is vulnerable to SQL Injection in `login.php` via the `emailcont` parameter.
Published 2024-12-10 · Modified
9.8EPSS 0.006
CVE-2025-4861
PHPGurukul Beauty Parlour Management System admin-profile.php sql injection
Published 2025-05-18 · Analyzed
9.8EPSS 0.006
CVE-2025-4758
PHPGurukul Beauty Parlour Management System contact.php sql injection
Published 2025-05-16 · Analyzed
9.8EPSS 0.005
CVE-2025-4757
PHPGurukul Beauty Parlour Management System forgot-password.php sql injection
Published 2025-05-16 · Analyzed
9.8EPSS 0.005
CVE-2024-51065
Phpgurukul Beauty Parlour Management System v1.1 is vulnerable to SQL Injection in admin/index.php via the the username parameter.
Published 2024-10-31 · Modified
9.8EPSS 0.005
CVE-2025-11503
PHPGurukul Beauty Parlour Management System manage-services.php sql injection
Published 2025-10-08 · Modified
9.8EPSS 0.005
CVE-2025-11505
PHPGurukul Beauty Parlour Management System new-appointment.php sql injection
Published 2025-10-08 · Analyzed
9.8EPSS 0.005
CVE-2025-9829
PHPGurukul Beauty Parlour Management System signup.php sql injection
Published 2025-09-02 · Analyzed
9.8EPSS 0.005
CVE-2025-10403
PHPGurukul Beauty Parlour Management System view-enquiry.php sql injection
Published 2025-09-14 · Analyzed
9.8EPSS 0.004
CVE-2025-9933
PHPGurukul Beauty Parlour Management System view-appointment.php sql injection
Published 2025-09-03 · Analyzed
9.8EPSS 0.004
CVE-2025-9932
PHPGurukul Beauty Parlour Management System update-image.php sql injection
Published 2025-09-03 · Analyzed
9.8EPSS 0.004
CVE-2025-9831
PHPGurukul Beauty Parlour Management System edit-services.php sql injection
Published 2025-09-02 · Analyzed
9.8EPSS 0.004
CVE-2025-9830
PHPGurukul Beauty Parlour Management System add-customer-services.php sql injection
Published 2025-09-02 · Analyzed
9.8EPSS 0.004
CVE-2025-10459
PHPGurukul Beauty Parlour Management System all-appointment.php sql injection
Published 2025-09-15 · Analyzed
9.8EPSS 0.004
CVE-2025-9814
PHPGurukul Beauty Parlour Management System contact-us.php sql injection
Published 2025-09-02 · Analyzed
9.8EPSS 0.004
CVE-2025-11507
PHPGurukul Beauty Parlour Management System search-invoices.php sql injection
Published 2025-10-08 · Modified
9.8EPSS 0.004
CVE-2025-11506
PHPGurukul Beauty Parlour Management System search-appointment.php sql injection
Published 2025-10-08 · Modified
9.8EPSS 0.004
CVE-2025-11416
PHPGurukul Beauty Parlour Management System invoices.php sql injection
Published 2025-10-07 · Modified
9.8EPSS 0.004
CVE-2025-11415
PHPGurukul Beauty Parlour Management System customer-list.php sql injection
Published 2025-10-07 · Analyzed
9.8EPSS 0.004
CVE-2025-10402
PHPGurukul Beauty Parlour Management System readenq.php sql injection
Published 2025-09-14 · Analyzed
9.8EPSS 0.004
CVE-2025-9024
PHPGurukul Beauty Parlour Management System book-appointment.php sql injection
Published 2025-08-15 · Analyzed
9.8EPSS 0.004
CVE-2026-2088
PHPGurukul Beauty Parlour Management System accepted-appointment.php sql injection
Published 2026-02-07 · Analyzed
9.8EPSS 0.004
CVE-2025-11330
PHPGurukul Beauty Parlour Management System sales-reports-detail.php sql injection
Published 2025-10-06 · Analyzed
8.8EPSS 0.003
CVE-2024-51066
An Insecure Direct Object Reference (IDOR) vulnerability in appointment-detail.php in Phpgurukul's Beauty Parlour Management System v1.1 allows unauthorized access to the Personally Identifiable Information (PII) of other customers.
Published 2024-10-31 · Modified
7.5EPSS 0.005
CVE-2021-27545
SQL Injection in the "add-services.php" component of PHPGurukul Beauty Parlour Management System v1.0 allows remote attackers to obtain sensitive database information by injecting SQL commands into the "sername" parameter.
Published 2021-04-15 · Modified
6.5EPSS 0.020
CVE-2024-53481
A Cross Site Scripting (XSS) vulnerability in the profile.php of PHPGurukul Beauty Parlour Management System v1.1 allows remote attackers to execute arbitrary code by injecting arbitrary HTML into the "Firstname" and "Last name" parameters.
Published 2024-12-10 · Modified
6.1EPSS 0.005
CVE-2024-37798
Cross-site scripting (XSS) vulnerability in search-appointment.php in the Admin Panel in Phpgurukul Beauty Parlour Management System 1.0 allows remote attackers to inject arbitrary web script or HTML via the search input field.
Published 2024-06-17 · Analyzed
5.9EPSS 0.003
CVE-2021-27544
Cross Site Scripting (XSS) in the "add-services.php" component of PHPGurukul Beauty Parlour Management System v1.0 allows remote attackers to execute arbitrary code by injecting arbitrary HTML into the "sername" parameter.
Published 2021-04-15 · Modified
4.8EPSS 0.011