VendorsPHPGurukulhostel_management_system2.1
Vulnerabilities

PHPGurukul Hostel Management System 2.1

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

9CVEs
CVE-2025-45953
A vulnerability was found in PHPGurukul Hostel Management System 2.1 in the /hostel/change-password.php file of the user panel - Change Password component. Improper handling of session data allows a Session Hijacking attack, exploitable remotely
Published 2025-04-28 · Modified
9.1EPSS 0.004
CVE-2021-43137
Cross-Site Scripting (XSS) and Cross-Site Request Forgery (CSRF) vulnerability exits in hostel management system 2.1 via the name field in my-profile.php. Chaining to this both vulnerabilities leads to account takeover.
Published 2021-12-01 · Modified
8.8EPSS 0.005
CVE-2025-63611
Cross-Site Scripting in phpgurukul Hostel Management System v2.1 user-provided complaint fields (Explain the Complaint) submitted via /register-complaint.php are stored and rendered unescaped in the admin viewer (/admin/complaint-details.php?cid=<id>). When an administrator opens the complaint, injected HTML/JavaScript executes in the admin's browser.
Published 2026-01-08 · Analyzed
8.7EPSS 0.003
CVE-2023-36939
Cross-Site Scripting (XSS) vulnerability in Hostel Management System v2.1 allows an attacker to execute arbitrary code via a crafted payload to the search booking field.
Published 2023-07-10 · Modified
6.1EPSS 0.006
CVE-2020-25270
PHPGurukul hostel-management-system 2.1 allows XSS via Guardian Name, Guardian Relation, Guardian Contact no, Address, or City.
Published 2020-10-08 · Modified
5.41 PoCEPSS 0.032
CVE-2023-36375
Cross Site Scripting vulnerability in Hostel Management System v2.1 allows an attacker to execute arbitrary code via a crafted payload to the Guardian name, Guardian relation, complimentary address, city, permanent address, and city parameters in the Book Hostel & Room Details page.
Published 2023-07-10 · Modified
5.4EPSS 0.009
CVE-2025-13577
PHPGurukul Hostel Management System register-complaint.php cross site scripting
Published 2025-11-24 · Modified
5.4EPSS 0.002
CVE-2025-28129
Phpgurukul Hostel Management System 2.1 is vulnerable to clickjacking.
Published 2025-10-06 · Analyzed
5.4EPSS 0.002
CVE-2023-36376
Cross-Site Scripting (XSS) vulnerability in Hostel Management System v.2.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the add course section.
Published 2023-07-10 · Modified
4.8EPSS 0.006