VendorsPHPGurukulnews_portalall versions
Vulnerabilities

PHPGurukul News Portal

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

13CVEs
CVE-2025-69992
phpgurukul News Portal Project V4.1 has File Upload Vulnerability via upload.php, which enables the upload of files of any format to the server without identity authentication.
Published 2026-01-13 · Analyzed
9.8EPSS 0.006
CVE-2025-4873
PHPGurukul News Portal Login index.php sql injection
Published 2025-05-18 · Analyzed
9.8EPSS 0.006
CVE-2025-4874
PHPGurukul News Portal Project contactus.php sql injection
Published 2025-05-18 · Analyzed
9.8EPSS 0.006
CVE-2025-4880
PHPGurukul News Portal aboutus.php sql injection
Published 2025-05-18 · Analyzed
9.8EPSS 0.006
CVE-2025-1859
PHPGurukul News Portal login.php sql injection
Published 2025-03-03 · Analyzed
9.8EPSS 0.005
CVE-2025-69991
phpgurukul News Portal Project V4.1 is vulnerable to SQL Injection in check_availablity.php.
Published 2026-01-13 · Analyzed
9.8EPSS 0.005
CVE-2025-69990
phpgurukul News Portal Project V4.1 has an Arbitrary File Deletion Vulnerability in remove_file.php. The parameter file can cause any file to be deleted.
Published 2026-01-13 · Analyzed
9.1EPSS 0.005
CVE-2026-1141
PHPGurukul News Portal Add Sub-Admin add-subadmins.php improper authorization
Published 2026-01-19 · Modified
8.8EPSS 0.003
CVE-2025-12615
PHPGurukul News Portal settings.py hard-coded key
Published 2025-11-03 · Analyzed
8.1EPSS 0.004
CVE-2026-1424
PHPGurukul News Portal Profile Pic unrestricted upload
Published 2026-01-26 · Analyzed
7.2EPSS 0.005
CVE-2026-1142
PHPGurukul News Portal cross-site request forgery
Published 2026-01-19 · Analyzed
6.5EPSS 0.002
CVE-2021-37808
SQL Injection vulnerabilities exist in https://phpgurukul.com News Portal Project 3.1 via the (1) category, (2) subcategory, (3) sucatdescription, and (4) username parameters, the server response is about (N) seconds delay respectively which mean it is vulnerable to MySQL Blind (Time Based). An attacker can use sqlmap to further the exploitation for extracting sensitive information from the database.
Published 2021-10-27 · Modified
5.9EPSS 0.018
CVE-2025-12616
PHPGurukul News Portal settings.py insertion of sensitive information into debugging code
Published 2025-11-03 · Modified
5.9EPSS 0.005