VendorsPHPGurukuldairy_farm_shop_management_systemall versions
Vulnerabilities

PHPGurukul Dairy Farm Shop Management System

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

24CVEs
CVE-2022-29007
Multiple SQL injection vulnerabilities via the username and password parameters in the Admin panel of Dairy Farm Shop Management System v1.0 allows attackers to bypass authentication.
Published 2022-05-11 · Modified
9.8EPSS 0.193
CVE-2020-5307
PHPGurukul Dairy Farm Shop Management System 1.0 is vulnerable to SQL injection, as demonstrated by the username parameter in index.php, the category and CategoryCode parameters in add-category.php, the CompanyName parameter in add-company.php, and the ProductName and ProductPrice parameters in add-product.php.
Published 2020-01-07 · Modified
9.8EPSS 0.157
CVE-2020-36062
Dairy Farm Shop Management System v1.0 was discovered to contain hardcoded credentials in the source code which allows attackers access to the control panel if compromised.
Published 2022-02-11 · Modified
9.8EPSS 0.023
CVE-2022-40944
Dairy Farm Shop Management System 1.0 is vulnerable to SQL Injection via sales-report-ds.php file.
Published 2022-09-30 · Modified
9.8EPSS 0.012
CVE-2022-40943
Dairy Farm Shop Management System 1.0 is vulnerable to SQL Injection via bwdate-report-ds.php file.
Published 2022-09-30 · Modified
9.8EPSS 0.011
CVE-2025-5579
PHPGurukul Dairy Farm Shop Management System search-product.php sql injection
Published 2025-06-04 · Analyzed
9.8EPSS 0.008
CVE-2025-5578
PHPGurukul Dairy Farm Shop Management System sales-report-details.php sql injection
Published 2025-06-04 · Analyzed
9.8EPSS 0.008
CVE-2024-0355
PHPGurukul Dairy Farm Shop Management System add-category.php sql injection
Published 2024-01-09 · Modified
9.8EPSS 0.007
CVE-2025-5575
PHPGurukul Dairy Farm Shop Management System add-product.php sql injection
Published 2025-06-04 · Analyzed
9.8EPSS 0.007
CVE-2025-5577
PHPGurukul Dairy Farm Shop Management System profile.php sql injection
Published 2025-06-04 · Analyzed
9.8EPSS 0.006
CVE-2025-5576
PHPGurukul Dairy Farm Shop Management System bwdate-report-details.php sql injection
Published 2025-06-04 · Analyzed
9.8EPSS 0.006
CVE-2025-5574
PHPGurukul Dairy Farm Shop Management System add-company.php sql injection
Published 2025-06-04 · Analyzed
9.8EPSS 0.006
CVE-2025-7589
PHPGurukul Dairy Farm Shop Management System edit-company.php sql injection
Published 2025-07-14 · Analyzed
8.8EPSS 0.003
CVE-2025-7592
PHPGurukul Dairy Farm Shop Management System invoices.php sql injection
Published 2025-07-14 · Analyzed
8.8EPSS 0.003
CVE-2025-7588
PHPGurukul Dairy Farm Shop Management System edit-product.php sql injection
Published 2025-07-14 · Analyzed
8.8EPSS 0.003
CVE-2025-7590
PHPGurukul Dairy Farm Shop Management System edit-category.php sql injection
Published 2025-07-14 · Analyzed
8.8EPSS 0.003
CVE-2025-7591
PHPGurukul Dairy Farm Shop Management System view-invoice.php sql injection
Published 2025-07-14 · Analyzed
8.8EPSS 0.003
CVE-2025-7599
PHPGurukul Dairy Farm Shop Management System invoice.php sql injection
Published 2025-07-14 · Analyzed
8.8EPSS 0.003
CVE-2025-51672
A time-based blind SQL injection vulnerability was identified in the PHPGurukul Dairy Farm Shop Management System 1.3. The vulnerability exists in the manage-companies.php file and allows remote attackers to execute arbitrary SQL code via the companyname parameter in a POST request.
Published 2025-06-26 · Analyzed
8.0EPSS 0.004
CVE-2023-41594
Dairy Farm Shop Management System Using PHP and MySQL v1.1 was discovered to contain multiple SQL injection vulnerabilities in the Login function via the Username and Password parameters.
Published 2023-09-08 · Modified
7.5EPSS 0.010
CVE-2020-5308
PHPGurukul Dairy Farm Shop Management System 1.0 is vulnerable to XSS, as demonstrated by the category and CategoryCode parameters in add-category.php, the CompanyName parameter in add-company.php, and the ProductName parameter in add-product.php.
Published 2020-01-09 · Modified
6.1EPSS 0.013
CVE-2024-46241
PHPGurukul Dairy Farm Shop Management System v1.1 is vulnerable to Cross-Site Scripting (XSS) via the pname parameter in add_product.php and edit_product.php.
Published 2024-09-23 · Analyzed
5.9EPSS 0.002
CVE-2023-41593
Multiple cross-site scripting (XSS) vulnerabilities in Dairy Farm Shop Management System Using PHP and MySQL v1.1 allow attackers to execute arbitrary web scripts and HTML via a crafted payload injected into the Category and Category Field parameters.
Published 2023-09-11 · Modified
5.4EPSS 0.009
CVE-2025-51671
A SQL injection vulnerability was discovered in the PHPGurukul Dairy Farm Shop Management System 1.3. The vulnerability allows remote attackers to execute arbitrary SQL code via the category and categorycode parameters in a POST request to the manage-categories.php file.
Published 2025-06-26 · Analyzed
5.4EPSS 0.003