VendorsPHPGurukulcyber_cafe_management_system1.0
Vulnerabilities

PHPGurukul Cyber Cafe Management System 1.0

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

20CVEs
CVE-2022-29009
Multiple SQL injection vulnerabilities via the username and password parameters in the Admin panel of Cyber Cafe Management System Project v1.0 allows attackers to bypass authentication.
Published 2022-05-11 · Modified
9.8EPSS 0.229
CVE-2024-30980
SQL Injection vulnerability in phpgurukul Cyber Cafe Management System Using PHP & MySQL 1.0 allows attackers to run arbitrary SQL commands via the Computer Location parameter in manage-computer.php page.
Published 2024-04-17 · Analyzed
9.8EPSS 0.007
CVE-2025-4304
PHPGurukul Cyber Cafe Management System adminprofile.php sql injection
Published 2025-05-06 · Analyzed
9.8EPSS 0.006
CVE-2025-4226
PHPGurukul/Campcodes Cyber Cafe Management System add-computer.php sql injection
Published 2025-05-03 · Modified
9.8EPSS 0.006
CVE-2025-5358
PHPGurukul/Campcodes Cyber Cafe Management System bwdates-reports-details.php sql injection
Published 2025-05-30 · Analyzed
9.8EPSS 0.005
CVE-2024-30982
SQL Injection vulnerability in phpgurukul Cyber Cafe Management System Using PHP & MySQL 1.0 allows attackers to run arbitrary SQL commands via the upid parameter in the /view-user-detail.php file.
Published 2024-04-17 · Analyzed
9.8EPSS 0.005
CVE-2024-30981
SQL Injection vulnerability in /edit-computer-detail.php in phpgurukul Cyber Cafe Management System Using PHP & MySQL v1.0 allows attackers to run arbitrary SQL commands via editid in the application URL.
Published 2024-04-17 · Analyzed
9.8EPSS 0.005
CVE-2025-7165
PHPGurukul/Campcodes Cyber Cafe Management System forgot-password.php sql injection
Published 2025-07-08 · Analyzed
9.8EPSS 0.005
CVE-2025-7164
PHPGurukul/Campcodes Cyber Cafe Management System index.php sql injection
Published 2025-07-08 · Analyzed
9.8EPSS 0.005
CVE-2025-70892
Phpgurukul Cyber Cafe Management System v1.0 contains a SQL Injection vulnerability in the user management module. The application fails to properly validate user-supplied input in the username parameter of the add-users.php endpoint.
Published 2026-01-15 · Analyzed
9.8EPSS 0.005
CVE-2025-4696
PHPGurukul/Campcodes Cyber Cafe Management System search.php sql injection
Published 2025-05-15 · Analyzed
8.8EPSS 0.005
CVE-2025-4695
PHPGurukul/Campcodes Cyber Cafe Management System add-users.php sql injection
Published 2025-05-15 · Analyzed
8.8EPSS 0.004
CVE-2025-70893
A time-based blind SQL Injection vulnerability exists in PHPGurukul Cyber Cafe Management System v1.0 within the adminprofile.php endpoint. The application fails to properly sanitize user-supplied input provided via the adminname parameter, allowing authenticated attackers to inject arbitrary SQL expressions.
Published 2026-01-15 · Analyzed
8.8EPSS 0.004
CVE-2024-30983
SQL Injection vulnerability in phpgurukul Cyber Cafe Management System Using PHP & MySQL 1.0 allows attackers to run arbitrary SQL commands via the compname parameter in /edit-computer-detail.php file.
Published 2024-04-17 · Analyzed
7.3EPSS 0.003
CVE-2023-34666
Cross-site scripting (XSS) vulnerability in Phpgurukul Cyber Cafe Management System 1.0 allows remote attackers to inject arbitrary web script or HTML via the admin username parameter.
Published 2023-06-15 · Modified
6.1EPSS 0.007
CVE-2025-11390
PHPGurukul Cyber Cafe Management System POST Parameter search.php cross site scripting
Published 2025-10-07 · Modified
6.1EPSS 0.004
CVE-2025-70890
A stored cross-site scripting (XSS) vulnerability exists in Cyber Cafe Management System v1.0. An authenticated attacker can inject arbitrary JavaScript code into the username parameter via the add-users.php endpoint. The injected payload is stored and executed in the victim s browser when the affected page is accessed.
Published 2026-01-15 · Analyzed
6.1EPSS 0.003
CVE-2025-70891
A stored cross-site scripting (XSS) vulnerability exists in Phpgurukul Cyber Cafe Management System v1.0 within the user management module. The application does not properly sanitize or encode user-supplied input submitted via the uadd parameter in the add-users.php endpoint. An authenticated attacker can inject arbitrary JavaScript code that is persistently stored in the database. The malicious payload is triggered when a privileged user clicks the View button on the view-allusers.php page.
Published 2026-01-15 · Analyzed
6.1EPSS 0.003
CVE-2024-30979
Cross Site Scripting vulnerability in Cyber Cafe Management System 1.0 allows a remote attacker to execute arbitrary code via the compname parameter in edit-computer-details.php.
Published 2024-04-17 · Analyzed
5.9EPSS 0.005
CVE-2023-38920
Cross Site Scripting vulnerability in Cyber Cafe Management System v.1.0 allows a local attacker to execute arbitrary code via a crafted script to the adminname parameter.
Published 2024-11-13 · Analyzed
4.8EPSS 0.004