VendorsPHPGurukulsmall_crmall versions
Vulnerabilities

PHPGurukul Small CRM

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

19CVEs
CVE-2024-3691
PHPGurukul Small CRM Registration Page sql injection
Published 2024-04-12 · Analyzed
9.8EPSS 0.009
CVE-2024-12999
PHPGurukul Small CRM edit-user.php sql injection
Published 2024-12-29 · Analyzed
9.8EPSS 0.005
CVE-2024-13000
PHPGurukul Small CRM quote-details.php sql injection
Published 2024-12-29 · Analyzed
9.8EPSS 0.005
CVE-2025-11053
PHPGurukul Small CRM forgot-password.php sql injection
Published 2025-09-27 · Analyzed
9.8EPSS 0.004
CVE-2025-10664
PHPGurukul Small CRM create-ticket.php sql injection
Published 2025-09-18 · Analyzed
9.8EPSS 0.004
CVE-2025-10114
PHPGurukul Small CRM profile.php sql injection
Published 2025-09-09 · Analyzed
9.8EPSS 0.004
CVE-2024-13001
PHPGurukul Small CRM index.php sql injection
Published 2024-12-29 · Analyzed
9.8EPSS 0.004
CVE-2025-10079
PHPGurukul Small CRM get-quote.php sql injection
Published 2025-09-08 · Analyzed
9.8EPSS 0.004
CVE-2024-3690
PHPGurukul Small CRM Change Password sql injection
Published 2024-04-12 · Analyzed
8.8EPSS 0.013
CVE-2025-15390
PHPGurukul Small CRM edit-user.php authorization
Published 2025-12-31 · Modified
8.8EPSS 0.004
CVE-2025-5226
PHPGurukul Small CRM change-password.php sql injection
Published 2025-05-27 · Analyzed
7.5EPSS 0.004
CVE-2025-5227
PHPGurukul Small CRM manage-tickets.php sql injection
Published 2025-05-27 · Analyzed
7.5EPSS 0.004
CVE-2025-50484
Improper session invalidation in the component /crm/change-password.php of PHPGurukul Small CRM v3.0 allows attackers to execute a session hijacking attack.
Published 2025-07-28 · Modified
7.1EPSS 0.003
CVE-2024-44648
PHPGurukul Small CRM 3.0 is vulnerable to SQL Injection via id and adminremark parameters in quote-details.php.
Published 2025-11-17 · Analyzed
6.5EPSS 0.002
CVE-2024-44644
PHPGurukul Small CRM 3.0 is vulnerable to SQL Injection via the frm_id and aremark parameters in manage-tickets.php.
Published 2025-11-17 · Analyzed
6.5EPSS 0.002
CVE-2024-44641
PHPGurukul Small CRM 3.0 is vulnerable to SQL Injection via the oldpass parameter in change-password.php.
Published 2025-11-17 · Analyzed
6.5EPSS 0.002
CVE-2024-44647
PHPGurukul Small CRM 3.0 is vulnerable to Cross Site Scripting (XSS) via the aremark parameter in manage-tickets.php.
Published 2025-11-17 · Analyzed
6.1EPSS 0.002
CVE-2025-9834
PHPGurukul Small CRM registration.php cross site scripting
Published 2025-09-02 · Analyzed
5.4EPSS 0.003
CVE-2024-48170
PHPGurukul Small CRM 3.0 is vulnerable to Cross Site Scripting (XSS) via a crafted payload injected into the name in the profile.php.
Published 2025-02-10 · Modified
5.4EPSS 0.002