VendorsPHPGurukulhospital_management_systemall versions
Vulnerabilities

PHPGurukul Hospital Management System

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

62CVEs
CVE-2022-24263
Hospital Management System v4.0 was discovered to contain a SQL injection vulnerability in /Hospital-Management-System-master/func.php via the email parameter.
Published 2022-01-31 · Modified
9.81 PoCEPSS 0.082
CVE-2023-31498
A privilege escalation issue was found in PHP Gurukul Hospital Management System In v.4.0 allows a remote attacker to execute arbitrary code and access sensitive information via the session token parameter.
Published 2023-05-11 · Modified
9.8EPSS 0.021
CVE-2020-26629
A JQuery Unrestricted Arbitrary File Upload vulnerability was discovered in Hospital Management System V4.0 which allows an unauthenticated attacker to upload any file to the server.
Published 2024-01-10 · Modified
9.8EPSS 0.012
CVE-2024-51360
An issue in Hospital Management System In PHP V4.0 allows a remote attacker to execute arbitrary code via the hms/doctor/edit-profile.php file
Published 2025-05-23 · Modified
9.8EPSS 0.009
CVE-2024-0360
PHPGurukul Hospital Management System edit-doctor-specialization.php sql injection
Published 2024-01-10 · Modified
9.8EPSS 0.007
CVE-2024-0361
PHPGurukul Hospital Management System contact.php sql injection
Published 2024-01-10 · Modified
9.8EPSS 0.007
CVE-2024-0362
PHPGurukul Hospital Management System change-password.php sql injection
Published 2024-01-10 · Modified
9.8EPSS 0.006
CVE-2024-0363
PHPGurukul Hospital Management System patient-search.php sql injection
Published 2024-01-10 · Modified
9.8EPSS 0.006
CVE-2025-7176
PHPGurukul Hospital Management System view-medhistory.php sql injection
Published 2025-07-08 · Analyzed
9.8EPSS 0.006
CVE-2024-0364
PHPGurukul Hospital Management System query-details.php sql injection
Published 2024-01-10 · Modified
9.8EPSS 0.005
CVE-2025-56212
phpgurukul Hospital Management System 4.0 is vulnerable to SQL Injection in add-doctor.php via the docname parameter.
Published 2025-08-25 · Modified
9.8EPSS 0.004
CVE-2025-7604
PHPGurukul Hospital Management System user-login.php sql injection
Published 2025-07-14 · Analyzed
9.8EPSS 0.004
CVE-2025-56214
phpgurukul Hospital Management System 4.0 is vulnerable to SQL Injection in index.php via the username parameter.
Published 2025-08-25 · Modified
9.8EPSS 0.004
CVE-2020-5192
PHPGurukul Hospital Management System in PHP v4.0 suffers from multiple SQL injection vulnerabilities: multiple pages and parameters are not validating user input, and allow for the application's database and information to be fully compromised.
Published 2020-01-06 · Modified
8.81 PoCEPSS 0.168
CVE-2020-35745
PHPGURUKUL Hospital Management System V 4.0 does not properly restrict access to admin/dashboard.php, which allows attackers to access all data of users, doctors, patients, change admin password, get appointment history and access all session logs.
Published 2021-01-07 · Modified
8.8EPSS 0.017
CVE-2021-35387
Hospital Management System v 4.0 is vulnerable to SQL Injection via file:hospital/hms/admin/view-patient.php.
Published 2022-10-28 · Modified
8.8EPSS 0.008
CVE-2022-46499
Hospital Management System 1.0 was discovered to contain a SQL injection vulnerability via the pat_number parameter at his_admin_view_single_patient.php.
Published 2024-03-07 · Analyzed
8.8EPSS 0.005
CVE-2025-70064
PHPGurukul Hospital Management System v4.0 contains a Privilege Escalation vulnerability. A low-privileged user (Patient) can directly access the Administrator Dashboard and all sub-modules (e.g., User Logs, Doctor Management) by manually browsing to the /admin/ directory after authentication. This allows any self-registered user to takeover the application, view confidential logs, and modify system data.
Published 2026-02-18 · Analyzed
8.8EPSS 0.005
CVE-2026-1550
PHPGurukul Hospital Management System Admin Dashboard adminviews.py improper authorization
Published 2026-01-28 · Analyzed
8.8EPSS 0.004
CVE-2025-56216
phpgurukul Hospital Management System 4.0 is vulnerable to SQL Injection in about-us.php via the pagetitle parameter.
Published 2025-08-25 · Modified
8.5EPSS 0.003
CVE-2022-46497
Hospital Management System 1.0 was discovered to contain a SQL injection vulnerability via the pat_number parameter at his_doc_view_single_patien.php.
Published 2024-03-07 · Analyzed
8.1EPSS 0.005
CVE-2022-24646
Hospital Management System v4.0 was discovered to contain a SQL injection vulnerability in /Hospital-Management-System-master/contact.php via the txtMsg parameters.
Published 2022-02-10 · Modified
7.8EPSS 0.017
CVE-2020-22165
PHPGurukul Hospital Management System in PHP v4.0 has a SQL injection vulnerability in \hms\user-login.php. Remote unauthenticated users can exploit the vulnerability to obtain database sensitive information.
Published 2021-06-22 · Modified
7.5EPSS 0.063
CVE-2020-22168
PHPGurukul Hospital Management System in PHP v4.0 has a SQL injection vulnerability in \hms\change-emaild.php. Remote unauthenticated users can exploit the vulnerability to obtain database sensitive information.
Published 2021-06-22 · Modified
7.5EPSS 0.022
CVE-2020-22170
PHPGurukul Hospital Management System in PHP v4.0 has a SQL injection vulnerability in \hms\get_doctor.php. Remote unauthenticated users can exploit the vulnerability to obtain database sensitive information.
Published 2021-06-22 · Modified
7.5EPSS 0.022
CVE-2020-22166
PHPGurukul Hospital Management System in PHP v4.0 has a SQL injection vulnerability in \hms\forgot-password.php. Remote unauthenticated users can exploit the vulnerability to obtain database sensitive information.
Published 2021-06-22 · Modified
7.5EPSS 0.022
CVE-2020-22171
PHPGurukul Hospital Management System in PHP v4.0 has a SQL injection vulnerability in \hms\registration.php. Remote unauthenticated users can exploit the vulnerability to obtain database sensitive information.
Published 2021-06-22 · Modified
7.5EPSS 0.022
CVE-2020-22172
PHPGurukul Hospital Management System in PHP v4.0 has a SQL injection vulnerability in \hms\get_doctor.php. Remote unauthenticated users can exploit the vulnerability to obtain database sensitive information.
Published 2021-06-22 · Modified
7.5EPSS 0.022
CVE-2020-22173
PHPGurukul Hospital Management System in PHP v4.0 has a SQL injection vulnerability in \hms\edit-profile.php. Remote unauthenticated users can exploit the vulnerability to obtain database sensitive information.
Published 2021-06-22 · Modified
7.5EPSS 0.022
CVE-2020-22174
PHPGurukul Hospital Management System in PHP v4.0 has a SQL injection vulnerability in \hms\book-appointment.php. Remote unauthenticated users can exploit the vulnerability to obtain database sensitive information.
Published 2021-06-22 · Modified
7.5EPSS 0.022
CVE-2020-22175
PHPGurukul Hospital Management System in PHP v4.0 has a SQL injection vulnerability in \hms\admin\betweendates-detailsreports.php. Remote unauthenticated users can exploit the vulnerability to obtain database sensitive information.
Published 2021-06-22 · Modified
7.5EPSS 0.022
CVE-2020-22169
PHPGurukul Hospital Management System in PHP v4.0 has a SQL injection vulnerability in \hms\appointment-history.php. Remote unauthenticated users can exploit the vulnerability to obtain database sensitive information.
Published 2021-06-22 · Modified
7.5EPSS 0.022
CVE-2020-22164
PHPGurukul Hospital Management System in PHP v4.0 has a SQL injection vulnerability in \hms\check_availability.php. Remote unauthenticated users can exploit the vulnerability to obtain database sensitive information.
Published 2021-06-22 · Modified
7.5EPSS 0.022
CVE-2020-22176
PHPGurukul Hospital Management System in PHP v4.0 has a sensitive information disclosure vulnerability in multiple areas. Remote unauthenticated users can exploit the vulnerability to obtain user sensitive information.
Published 2021-06-22 · Modified
7.5EPSS 0.021
CVE-2022-24226
Hospital Management System v4.0 was discovered to contain a blind SQL injection vulnerability via the register function in func2.php.
Published 2022-02-15 · Modified
7.5EPSS 0.017
CVE-2023-7172
PHPGurukul Hospital Management System Admin Dashboard sql injection
Published 2023-12-30 · Modified
7.5EPSS 0.015
CVE-2026-2179
PHPGurukul Hospital Management System manage-users.php sql injection
Published 2026-02-08 · Analyzed
7.2EPSS 0.003
CVE-2026-2134
PHPGurukul Hospital Management System manage-doctors.php sql injection
Published 2026-02-08 · Analyzed
7.2EPSS 0.003
CVE-2025-70063
The 'Medical History' module in PHPGurukul Hospital Management System v4.0 contains an Insecure Direct Object Reference (IDOR) vulnerability. The application fails to verify that the requested 'viewid' parameter belongs to the currently authenticated patient. This allows a user to access the confidential medical records of other patients by iterating the 'viewid' integer.
Published 2026-02-18 · Analyzed
6.5EPSS 0.003
CVE-2025-56215
phpgurukul Hospital Management System 4.0 is vulnerable to SQL Injection in contact.php via the pagetitle parameter.
Published 2025-08-25 · Modified
6.5EPSS 0.003
1 / 2Next →