VendorsPHPGurukulzoo_management_systemall versions
Vulnerabilities

PHPGurukul Zoo Management System

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

37CVEs
CVE-2022-27351
Zoo Management System v1.0 was discovered to contain an arbitrary file upload vulnerability via /public_html/apply_vacancy. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file.
Published 2022-04-08 · Modified
9.8EPSS 0.035
CVE-2025-7160
PHPGurukul Zoo Management System index.php sql injection
Published 2025-07-08 · Analyzed
9.8EPSS 0.018
CVE-2023-41615
Zoo Management System v1.0 was discovered to contain multiple SQL injection vulnerabilities in the Admin sign-in page via the username and password fields.
Published 2023-09-08 · Modified
9.8EPSS 0.010
CVE-2022-2804
SourceCodester Zoo Management System apply_vacancy.php unrestricted upload
Published 2022-08-12 · Modified
9.8EPSS 0.010
CVE-2022-2803
SourceCodester Zoo Management System animals.php sql injection
Published 2022-08-12 · Modified
9.8EPSS 0.008
CVE-2024-25350
SQL Injection vulnerability in /zms/admin/edit-ticket.php in PHPGurukul Zoo Management System 1.0 via tickettype and tprice parameters.
Published 2024-02-28 · Analyzed
9.8EPSS 0.006
CVE-2025-4910
PHPGurukul Zoo Management System edit-animal-details.php sql injection
Published 2025-05-19 · Analyzed
9.8EPSS 0.006
CVE-2025-3231
PHPGurukul Zoo Management System aboutus.php sql injection
Published 2025-04-04 · Analyzed
9.8EPSS 0.006
CVE-2025-2656
PHPGurukul Zoo Management System login.php sql injection
Published 2025-03-23 · Analyzed
9.8EPSS 0.005
CVE-2025-4911
PHPGurukul Zoo Management System view-foreigner-ticket.php sql injection
Published 2025-05-19 · Analyzed
9.8EPSS 0.005
CVE-2025-4766
PHPGurukul Zoo Management System profile.php sql injection
Published 2025-05-16 · Analyzed
9.8EPSS 0.005
CVE-2025-4765
PHPGurukul Zoo Management System contactus.php sql injection
Published 2025-05-16 · Analyzed
9.8EPSS 0.005
CVE-2024-5357
PHPGurukul Zoo Management System forgot-password.php sql injection
Published 2024-05-26 · Analyzed
9.8EPSS 0.005
CVE-2024-5360
PHPGurukul Zoo Management System foreigner-bwdates-reports-details.php sql injection
Published 2024-05-26 · Analyzed
9.8EPSS 0.004
CVE-2024-5358
PHPGurukul Zoo Management System normal-search.php sql injection
Published 2024-05-26 · Analyzed
9.8EPSS 0.004
CVE-2024-5359
PHPGurukul Zoo Management System foreigner-search.php sql injection
Published 2024-05-26 · Analyzed
9.8EPSS 0.004
CVE-2022-27992
Zoo Management System v1.0 was discovered to contain a SQL injection vulnerability at /public_html/animals via the class_id parameter.
Published 2022-04-08 · Modified
8.8EPSS 0.015
CVE-2025-6930
PHPGurukul Zoo Management System manage-foreigners-ticket.php sql injection
Published 2025-06-30 · Analyzed
8.8EPSS 0.004
CVE-2025-6929
PHPGurukul Zoo Management System view-normal-ticket.php sql injection
Published 2025-06-30 · Analyzed
8.8EPSS 0.004
CVE-2025-7161
PHPGurukul Zoo Management System add-normal-ticket.php sql injection
Published 2025-07-08 · Analyzed
8.8EPSS 0.003
CVE-2025-7159
PHPGurukul Zoo Management System manage-animals.php sql injection
Published 2025-07-08 · Analyzed
8.8EPSS 0.003
CVE-2025-7158
PHPGurukul Zoo Management System manage-normal-ticket.php sql injection
Published 2025-07-08 · Analyzed
8.8EPSS 0.003
CVE-2025-7162
PHPGurukul Zoo Management System add-foreigners-ticket.php sql injection
Published 2025-07-08 · Analyzed
8.8EPSS 0.003
CVE-2025-7163
PHPGurukul Zoo Management System add-animals.php sql injection
Published 2025-07-08 · Analyzed
8.8EPSS 0.003
CVE-2020-25487
PHPGURUKUL Zoo Management System Using PHP and MySQL version 1.0 is affected by: SQL Injection via zms/animal-detail.php.
Published 2020-09-22 · Modified
7.8EPSS 0.005
CVE-2022-40924
Zoo Management System v1.0 has an arbitrary file upload vulnerability in the picture upload point of the "save_animal" file of the "Animals" module in the background management system.
Published 2022-09-26 · Modified
7.2EPSS 0.012
CVE-2022-40925
Zoo Management System v1.0 has an arbitrary file upload vulnerability in the picture upload point of the "save_event" file of the "Events" module in the background management system.
Published 2022-09-26 · Modified
7.2EPSS 0.011
CVE-2022-40932
In Zoo Management System v1.0, there is an arbitrary file upload vulnerability in the picture upload point of the "gallery" file of the "Gallery" module in the background management system.
Published 2022-09-22 · Modified
7.2EPSS 0.011
CVE-2024-5361
PHPGurukul Zoo Management System normal-bwdates-reports-details.php sql injection
Published 2024-05-26 · Analyzed
7.2EPSS 0.004
CVE-2022-31897
SourceCodester Zoo Management System 1.0 is vulnerable to Cross Site Scripting (XSS) via public_html/register_visitor?msg=.
Published 2022-06-29 · Modified
6.1EPSS 0.009
CVE-2021-4232
Zoo Management System manage-ticket.php cross site scripting
Published 2022-05-26 · Modified
6.1EPSS 0.005
CVE-2025-9017
PHPGurukul Zoo Management System add-foreigner-ticket.php cross site scripting
Published 2025-08-15 · Analyzed
6.1EPSS 0.004
CVE-2022-33075
A stored cross-site scripting (XSS) vulnerability in the Add Classification function of Zoo Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via unspecified vectors.
Published 2022-07-05 · Modified
5.4EPSS 0.006
CVE-2022-1816
Zoo Management System Content Module cross site scripting
Published 2022-05-23 · Modified
5.4EPSS 0.006
CVE-2022-31914
Zoo Management System v1.0 is vulnerable to Cross Site Scripting (XSS) via zms/admin/public_html/save_animal?an_id=24.
Published 2022-06-16 · Modified
5.4EPSS 0.005
CVE-2023-41614
A stored cross-site scripting (XSS) vulnerability in the Add Animal Details function of Zoo Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Description of Animal parameter.
Published 2023-09-21 · Modified
4.8EPSS 0.004
CVE-2024-25351
SQL Injection vulnerability in /zms/admin/changeimage.php in PHPGurukul Zoo Management System 1.0 allows attackers to run arbitrary SQL commands via the editid parameter.
Published 2024-02-28 · Analyzed
3.8EPSS 0.004