VendorsPHPGurukuldoctor_appointment_management_system1.0.0
Vulnerabilities

PHPGurukul Doctor Appointment Management System 1.0.0

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

12CVEs
CVE-2025-2383
PHPGurukul Doctor Appointment Management System search.php sql injection
Published 2025-03-17 · Analyzed
9.8EPSS 0.005
CVE-2025-2640
PHPGurukul Doctor Appointment Management System appointment-bwdates-reports-details.php sql injection
Published 2025-03-23 · Analyzed
9.8EPSS 0.005
CVE-2025-2649
PHPGurukul Doctor Appointment Management System check-appointment.php sql injection
Published 2025-03-23 · Analyzed
9.8EPSS 0.005
CVE-2024-4294
PHPGurukul Doctor Appointment Management System view-appointment-detail.php resource injection
Published 2024-04-27 · Analyzed
8.8EPSS 0.009
CVE-2025-45805
In phpgurukul Doctor Appointment Management System 1.0, an authenticated doctor user can inject arbitrary JavaScript code into their profile name. This payload is subsequently rendered without proper sanitization, when a user visits the website and selects the doctor to book an appointment.
Published 2025-09-03 · Modified
7.6EPSS 0.004
CVE-2025-50493
Improper session invalidation in the component /doctor/change-password.php of PHPGurukul Doctor Appointment Management System v1 allows attackers to execute a session hijacking attack.
Published 2025-07-28 · Modified
7.5EPSS 0.003
CVE-2022-45728
Doctor Appointment Management System v1.0.0 was discovered to contain a cross-site scripting (XSS) vulnerability.
Published 2023-01-12 · Modified
6.1EPSS 0.005
CVE-2022-45730
A cross-site scripting (XSS) vulnerability in Doctor Appointment Management System v1.0.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Search function.
Published 2023-01-25 · Modified
6.1EPSS 0.005
CVE-2022-45729
A cross-site scripting (XSS) vulnerability in Doctor Appointment Management System v1.0.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Employee ID parameter.
Published 2023-01-12 · Modified
6.1EPSS 0.005
CVE-2022-46128
phpgurukul Doctor Appointment Management System V 1.0.0 is vulnerable to Cross Site Scripting (XSS) via searchdata=.
Published 2023-01-25 · Modified
6.1EPSS 0.005
CVE-2024-4293
PHPGurukul Doctor Appointment Management System appointment-bwdates-reports-details.php cross site scripting
Published 2024-04-27 · Analyzed
5.4EPSS 0.006
CVE-2024-48807
Cross Site Scripting vulnerability in PHPGurukul Doctor Appointment Management System v.1.0 allows a local attacker to execute arbitrary code via the search parameter.
Published 2024-10-30 · Analyzed
5.4EPSS 0.003