Home/Product/phpgurukul hospital management system
Product

phpgurukul hospital management system

140 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2025-70064
all versions
PHPGurukul Hospital Management System v4.0 contains a Privilege Escalation vulnerability. A low-privileged user (Patient) can dire
8.8HIGH
CVE-2025-70063
all versions
The 'Medical History' module in PHPGurukul Hospital Management System v4.0 contains an Insecure Direct Object Reference (IDOR) vul
6.5MEDIUM
CVE-2025-70062
all versions
PHPGurukul Hospital Management System v4.0 contains a Cross-Site Request Forgery (CSRF) vulnerability in the 'Add Doctor' module.
6.5MEDIUM
CVE-2026-2179
all versions
A vulnerability was determined in PHPGurukul Hospital Management System 4.0. This impacts an unknown function of the file /admin/m
4.7MEDIUM
CVE-2026-2134
all versions
A security vulnerability has been detected in PHPGurukul Hospital Management System 4.0. The affected element is an unknown functi
4.7MEDIUM
CVE-2026-1550
all versions
A security flaw has been discovered in PHPGurukul Hospital Management System 1.0. Affected by this issue is some unknown functiona
6.3MEDIUM
CVE-2025-63514
all versions
kishan0725 Hospital Management System has a Cross-Site Scripting (XSS) vulnerability in appsearch.php via the email parameter.
6.1MEDIUM
CVE-2025-63513
all versions
kishan0725 Hospital Management System v4 has an Insecure Direct Object Reference (IDOR) vulnerability in the appointment cancellat
6.5MEDIUM
CVE-2025-63512
all versions
kishan0725 Hospital Management System/ v4 is vulnerable to SQL Injection in admin-panel1.php, specifically in the deleting doctor
6.5MEDIUM
CVE-2025-11609
all versions
A flaw has been found in code-projects Hospital Management System 1.0. Affected is the function session of the component express-s
3.7LOW
CVE-2025-56216
all versions
phpgurukul Hospital Management System 4.0 is vulnerable to SQL Injection in about-us.php via the pagetitle parameter.
8.5HIGH
CVE-2025-56215
all versions
phpgurukul Hospital Management System 4.0 is vulnerable to SQL Injection in contact.php via the pagetitle parameter.
6.5MEDIUM
CVE-2025-56214
all versions
phpgurukul Hospital Management System 4.0 is vulnerable to SQL Injection in index.php via the username parameter.
9.8CRITICAL
CVE-2025-56212
all versions
phpgurukul Hospital Management System 4.0 is vulnerable to SQL Injection in add-doctor.php via the docname parameter.
9.8CRITICAL
CVE-2025-8955
all versions
A vulnerability has been found in PHPGurukul Hospital Management System 4.0. This vulnerability affects unknown code of the file /
7.3HIGH
CVE-2025-8954
all versions
A vulnerability was identified in PHPGurukul Hospital Management System 4.0. This affects an unknown part of the file /admin/docto
7.3HIGH
CVE-2023-41532
all versions
Hospital Management System v4 was discovered to contain a SQL injection vulnerability via the doctor_contact parameter in doctorse
8.8HIGH
CVE-2023-41531
all versions
Hospital Management System v4 was discovered to contain multiple SQL injection vulnerabilities in func3.php via the username1 and
8.8HIGH
CVE-2023-41530
all versions
Hospital Management System v4 was discovered to contain a SQL injection vulnerability via the app_contact parameter in appsearch.p
9.8CRITICAL
CVE-2023-41529
all versions
Hospital Management System v4 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities in func2.php via the f
6.1MEDIUM
CVE-2023-41528
all versions
Hospital Management System v4 was discovered to contain multiple SQL injection vulnerabilities in contact.php via the txtname, txt
9.8CRITICAL
CVE-2023-41527
all versions
Hospital Management System v4 was discovered to contain a SQL injection vulnerability via the password2 parameter in func.php.
9.8CRITICAL
CVE-2023-41526
all versions
Hospital Management System v4 was discovered to contain multiple SQL injection vulnerabilities in func1.php via the username3 and
9.8CRITICAL
CVE-2023-41525
all versions
Hospital Management System v4 was discovered to contain a SQL injection vulnerability via the patient_contact parameter in patient
9.8CRITICAL
CVE-2023-40992
all versions
Hospital Management System 4 is vulnerable to a SQL injection in /Hospital-Management-System-master/func.php via the password2 par
6.5MEDIUM
CVE-2025-7604
all versions
A vulnerability was found in PHPGurukul Hospital Management System 4.0. It has been declared as critical. Affected by this vulnera
7.3HIGH
CVE-2025-7176
all versions
A vulnerability was found in PHPGurukul Hospital Management System 1.0. It has been declared as critical. Affected by this vulnera
7.3HIGH
CVE-2025-6613
all versions
A vulnerability classified as problematic was found in PHPGurukul Hospital Management System 4.0. Affected by this vulnerability i
3.5LOW
CVE-2025-6570
all versions
A vulnerability, which was classified as critical, has been found in PHPGurukul Hospital Management System 4.0. Affected by this i
6.3MEDIUM
CVE-2025-5584
all versions
A vulnerability was found in PHPGurukul Hospital Management System 4.0. It has been classified as problematic. Affected is an unkn
2.4LOW
CVE-2024-51360
all versions
An issue in Hospital Management System In PHP V4.0 allows a remote attacker to execute arbitrary code via the hms/doctor/edit-prof
9.8CRITICAL
CVE-2023-43958
all versions
An arbitrary file upload vulnerability in the component /jquery-file-upload/server/php/index.php of Hospital Management System v4.
9.8CRITICAL
CVE-2025-3206
all versions
A vulnerability has been found in code-projects Hospital Management System 1.0 and classified as critical. This vulnerability affe
6.3MEDIUM
CVE-2024-56990
all versions
PHPGurukul Hospital Management System 4.0 is vulnerable to Cross Site Scripting (XSS) in /view-medhistory.php and /admin/view-pati
4.5MEDIUM
CVE-2024-56998
all versions
PHPGurukul Hospital Management System 4.0 is vulnerable to Cross Site Scripting (XSS) in /edit-profile.php via the parameter $addr
4.2MEDIUM
CVE-2024-56997
all versions
PHPGurukul Hospital Management System 4.0 is vulnerable to Cross Site Scripting (XSS) in /doctor/index.php via the 'Email' paramet
4.2MEDIUM
CVE-2024-12983
all versions
A vulnerability classified as problematic has been found in code-projects Hospital Management System 1.0. This affects an unknown
2.4LOW
CVE-2024-12976
all versions
A vulnerability, which was classified as critical, has been found in CodeZips Hospital Management System 1.0. Affected by this iss
7.3HIGH
CVE-2024-12969
all versions
A vulnerability, which was classified as critical, has been found in code-projects Hospital Management System 1.0. Affected by thi
7.3HIGH
CVE-2024-11678
all versions
A vulnerability was found in CodeAstro Hospital Management System 1.0. It has been declared as problematic. This vulnerability aff
3.5LOW
CVE-2024-11677
all versions
A vulnerability was found in CodeAstro Hospital Management System 1.0. It has been classified as problematic. This affects an unkn
3.5LOW
CVE-2024-11676
all versions
A vulnerability was found in CodeAstro Hospital Management System 1.0 and classified as problematic. Affected by this issue is som
3.5LOW
CVE-2024-11675
all versions
A vulnerability has been found in CodeAstro Hospital Management System 1.0 and classified as problematic. Affected by this vulnera
3.5LOW
CVE-2024-11674
all versions
A vulnerability, which was classified as critical, was found in CodeAstro Hospital Management System 1.0. Affected is an unknown f
6.3MEDIUM
CVE-2024-11102
all versions
A vulnerability was found in SourceCodester Hospital Management System 1.0. It has been rated as problematic. Affected by this iss
3.5LOW
CVE-2024-11073
all versions
A vulnerability classified as problematic has been found in SourceCodester Hospital Management System 1.0. This affects an unknown
4.3MEDIUM
CVE-2024-10807
all versions
A vulnerability was found in PHPGurukul Hospital Management System 4.0. It has been rated as problematic. This issue affects some
2.4LOW
CVE-2024-10806
all versions
A vulnerability was found in PHPGurukul Hospital Management System 4.0. It has been declared as problematic. This vulnerability af
2.4LOW
CVE-2024-10350
all versions
A vulnerability was found in code-projects Hospital Management System 1.0. It has been declared as critical. This vulnerability af
4.7MEDIUM
CVE-2024-46239
all versions
Multiple cross-site scripting vulnerabilities exist in PHPGurukul Hospital Management System 4.0 via the docname parameter in /doc
5.9MEDIUM
CVE-2024-46238
all versions
Multiple Cross Site Scripting (XSS) vulnerabilities exist in PHPGurukul Hospital Management System 4.0 via the docname parameter i
5.9MEDIUM
CVE-2024-10170
all versions
A vulnerability, which was classified as critical, has been found in code-projects Hospital Management System 1.0. This issue affe
6.3MEDIUM
CVE-2024-10169
all versions
A vulnerability classified as critical was found in code-projects Hospital Management System 1.0. This vulnerability affects unkno
6.3MEDIUM
CVE-2024-46237
all versions
PHPGurukul Hospital Management System 4.0 is vulnerable to Cross Site Scripting (XSS) via the patname, pataddress, and medhis para
5.4MEDIUM
CVE-2024-45983
all versions
A Cross-Site Request Forgery (CSRF) vulnerability exists in kishan0725's Hospital Management System version 6.3.5. The vulnerabili
6.3MEDIUM
CVE-2024-8944
all versions
A vulnerability, which was classified as critical, was found in code-projects Hospital Management System 1.0. This affects an unkn
7.3HIGH
CVE-2024-8569
all versions
A vulnerability has been found in code-projects Hospital Management System 1.0 and classified as critical. Affected by this vulner
7.3HIGH
CVE-2024-8368
all versions
A vulnerability was found in code-projects Hospital Management System 1.0. It has been rated as critical. Affected by this issue i
7.3HIGH
CVE-2024-28320
all versions
Insecure Direct Object References (IDOR) vulnerability in Hospital Management System 1.0 allows attackers to manipulate user param
7.6HIGH
CVE-2022-46499
all versions
Hospital Management System 1.0 was discovered to contain a SQL injection vulnerability via the pat_number parameter at his_admin_v
8.8HIGH
CVE-2022-46498
all versions
Hospital Management System 1.0 was discovered to contain a SQL injection vulnerability via the doc_number parameter at his_admin_v
2.7LOW
CVE-2022-46497
all versions
Hospital Management System 1.0 was discovered to contain a SQL injection vulnerability via the pat_number parameter at his_doc_vie
8.1HIGH
CVE-2020-26630
all versions
A Time-Based SQL Injection vulnerability was discovered in Hospital Management System V4.0 which can allow an attacker to dump dat
4.9MEDIUM
CVE-2020-26629
all versions
A JQuery Unrestricted Arbitrary File Upload vulnerability was discovered in Hospital Management System V4.0 which allows an unauth
9.8CRITICAL
CVE-2020-26628
all versions
A Cross-Site Scripting (XSS) vulnerability was discovered in Hospital Management System V4.0 which allows an attacker to execute a
6.1MEDIUM
CVE-2020-26627
all versions
A Time-Based SQL Injection vulnerability was discovered in Hospital Management System V4.0 which can allow an attacker to dump dat
4.9MEDIUM
CVE-2024-0364
all versions
A vulnerability, which was classified as critical, was found in PHPGurukul Hospital Management System 1.0. This affects an unknown
5.5MEDIUM
CVE-2024-0363
all versions
A vulnerability, which was classified as critical, has been found in PHPGurukul Hospital Management System 1.0. Affected by this i
5.5MEDIUM
CVE-2024-0362
all versions
A vulnerability classified as critical was found in PHPGurukul Hospital Management System 1.0. Affected by this vulnerability is a
5.5MEDIUM
CVE-2024-0361
all versions
A vulnerability classified as critical has been found in PHPGurukul Hospital Management System 1.0. Affected is an unknown functio
5.5MEDIUM
CVE-2024-0360
all versions
A vulnerability was found in PHPGurukul Hospital Management System 1.0. It has been rated as critical. This issue affects some unk
5.5MEDIUM
CVE-2024-0286
all versions
A vulnerability, which was classified as problematic, was found in PHPGurukul Hospital Management System 1.0. This affects an unkn
4.3MEDIUM
CVE-2023-7173
all versions
A vulnerability, which was classified as problematic, was found in PHPGurukul Hospital Management System 1.0. This affects an unkn
4.3MEDIUM
CVE-2023-7172
all versions
A vulnerability, which was classified as critical, has been found in PHPGurukul Hospital Management System 1.0. Affected by this i
7.3HIGH
CVE-2023-43909
all versions
Hospital Management System thru commit 4770d was discovered to contain a SQL injection vulnerability via the app_contact parameter
9.1CRITICAL
CVE-2023-4176
all versions
A vulnerability was found in SourceCodester Hospital Management System 1.0. It has been classified as critical. This affects an un
6.3MEDIUM
CVE-2023-3811
all versions
A vulnerability was found in Hospital Management System 1.0. It has been rated as critical. This issue affects some unknown proces
6.3MEDIUM
CVE-2023-3810
all versions
A vulnerability was found in Hospital Management System 1.0. It has been declared as critical. This vulnerability affects unknown
6.3MEDIUM
CVE-2023-3809
all versions
A vulnerability was found in Hospital Management System 1.0. It has been classified as critical. This affects an unknown part of t
6.3MEDIUM
CVE-2023-3808
all versions
A vulnerability was found in Hospital Management System 1.0 and classified as critical. Affected by this issue is some unknown fun
6.3MEDIUM
CVE-2023-34651
all versions
PHPgurukl Hospital Management System v.1.0 is vulnerable to Cross Site Scripting (XSS).
6.1MEDIUM
CVE-2023-31498
all versions
A privilege escalation issue was found in PHP Gurukul Hospital Management System In v.4.0 allows a remote attacker to execute arbi
9.8CRITICAL
CVE-2022-48120
<= 2021-03-13
SQL Injection vulnerability in kishan0725 Hospital Management System thru commit 4770d740f2512693ef8fd9aa10a8d17f79fad9bd (on Marc
9.8CRITICAL
CVE-2022-46093
all versions
Hospital Management System v1.0 is vulnerable to SQL Injection. Attackers can gain administrator privileges without the need for a
8.2HIGH
CVE-2021-35388
all versions
Hospital Management System v 4.0 is vulnerable to Cross Site Scripting (XSS) via /hospital/hms/admin/patient-search.php.
5.4MEDIUM
CVE-2021-35387
all versions
Hospital Management System v 4.0 is vulnerable to SQL Injection via file:hospital/hms/admin/view-patient.php.
8.8HIGH
CVE-2022-42206
all versions
PHPGurukul Hospital Management System In PHP V 4.0 is vulnerable to Cross Site Scripting (XSS) via doctor/view-patient.php, admin/
5.4MEDIUM
CVE-2022-42205
all versions
PHPGurukul Hospital Management System In PHP V 4.0 is vulnerable to Cross Site Scripting (XSS) via add-patient.php.
5.4MEDIUM
CVE-2022-38637
all versions
Hospital Management System v1.0 was discovered to contain multiple SQL injection vulnerabilities via the Username and Password par
9.8CRITICAL
CVE-2022-34590
all versions
Hospital Management System v1.0 was discovered to contain a SQL injection vulnerability via the editid parameter in /HMS/admin.php
7.2HIGH
CVE-2022-32095
all versions
Hospital Management System v1.0 was discovered to contain a SQL injection vulnerability via the editid parameter at orders.php.
9.8CRITICAL
CVE-2022-32094
all versions
Hospital Management System v1.0 was discovered to contain a SQL injection vulnerability via the loginid parameter at doctorlogin.p
9.8CRITICAL
CVE-2022-32093
all versions
Hospital Management System v1.0 was discovered to contain a SQL injection vulnerability via the loginid parameter at adminlogin.ph
9.8CRITICAL
CVE-2021-44095
all versions
A SQL injection vulnerability exists in ProjectWorlds Hospital Management System in php 1.0 on login page that allows a remote att
9.8CRITICAL
CVE-2022-30516
all versions
In Hospital-Management-System v1.0, the editid parameter in the doctor.php page is vulnerable to SQL injection attacks.
9.8CRITICAL
CVE-2022-30012
all versions
In the POST request of the appointment.php page of HMS v.0, there are SQL injection vulnerabilities in multiple parameters, and da
7.5HIGH
CVE-2022-30011
all versions
In HMS 1.0 when requesting appointment.php through POST, multiple parameters can lead to a SQL injection vulnerability.
9.8CRITICAL
CVE-2022-28929
all versions
Hospital Management System v1.0 was discovered to contain a SQL injection vulnerability via the delid parameter at viewtreatmentre
9.8CRITICAL
CVE-2022-30449
all versions
Hospital Management System in PHP with Source Code (HMS) 1.0 was discovered to contain a SQL injection vulnerability via the editi
9.8CRITICAL
CVE-2022-30448
all versions
Hospital Management System in PHP with Source Code (HMS) 1.0 was discovered to contain a File upload vulnerability in treatmentrec
9.8CRITICAL
CVE-2022-27420
all versions
Hospital Management System v1.0 was discovered to contain a SQL injection vulnerability via the patient_contact parameter in patie
9.8CRITICAL
CVE-2022-27413
all versions
Hospital Management System v1.0 was discovered to contain a SQL injection vulnerability via the adminname parameter in admin.php.
9.8CRITICAL
CVE-2022-27299
all versions
Hospital Management System v1.0 was discovered to contain a SQL injection vulnerability via the component room.php.
9.8CRITICAL
CVE-2022-26546
all versions
Hospital Management System v1.0 was discovered to lack an authorization component, allowing attackers to access sensitive informat
9.1CRITICAL
CVE-2022-24136
all versions
Hospital Management System v1.0 is affected by an unrestricted upload of dangerous file type vulerability in treatmentrecord.php.
9.8CRITICAL
CVE-2022-25493
all versions
HMS v1.0 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via treatmentrecord.php.
6.1MEDIUM
CVE-2022-25492
all versions
HMS v1.0 was discovered to contain a SQL injection vulnerability via the medicineid parameter in ajaxmedicine.php.
9.8CRITICAL
CVE-2022-25491
all versions
HMS v1.0 was discovered to contain a SQL injection vulnerability via the editid parameter in appointment.php.
7.5HIGH
CVE-2022-25490
all versions
HMS v1.0 was discovered to contain a SQL injection vulnerability via the editid parameter in department.php.
9.8CRITICAL
CVE-2022-25409
all versions
Hospital Management System v1.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the demail paramet
5.4MEDIUM
CVE-2022-25408
all versions
Hospital Management System v1.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the dpassword para
5.4MEDIUM
CVE-2022-25407
all versions
Hospital Management System v1.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Doctor paramet
5.4MEDIUM
CVE-2022-25403
all versions
HMS v1.0 was discovered to contain a SQL injection vulnerability via the component admin.php.
9.8CRITICAL
CVE-2022-25402
all versions
An incorrect access control issue in HMS v1.0 allows unauthenticated attackers to read and modify all PHP files.
9.1CRITICAL
CVE-2022-24226
all versions
Hospital Management System v4.0 was discovered to contain a blind SQL injection vulnerability via the register function in func2.p
7.5HIGH
CVE-2022-24646
all versions
Hospital Management System v4.0 was discovered to contain a SQL injection vulnerability in /Hospital-Management-System-master/cont
7.5HIGH
CVE-2022-24263
all versions
Hospital Management System v4.0 was discovered to contain a SQL injection vulnerability in /Hospital-Management-System-master/func
9.8CRITICAL
CVE-2021-39411
all versions
Multiple Cross Site Scripting (XSS) vulnerabilities exist in PHPGurukul Hospital Management System 4.0 via the (1) searchdata para
6.1MEDIUM
CVE-2021-38757
all versions
Persistent cross-site scripting (XSS) in Hospital Management System targeted towards web admin through contact.php.
6.1MEDIUM
CVE-2021-38756
all versions
Persistent cross-site scripting (XSS) in Hospital Management System targeted towards web admin through prescribe.php.
6.1MEDIUM
CVE-2021-38755
all versions
Unauthenticated doctor entry deletion in Hospital Management System in admin-panel1.php.
5.3MEDIUM
CVE-2021-38754
all versions
SQL Injection vulnerability in Hospital Management System due to lack of input validation in messearch.php.
9.8CRITICAL
CVE-2020-22176
all versions
PHPGurukul Hospital Management System in PHP v4.0 has a sensitive information disclosure vulnerability in multiple areas. Remote u
7.5HIGH
CVE-2020-22175
all versions
PHPGurukul Hospital Management System in PHP v4.0 has a SQL injection vulnerability in \hms\admin\betweendates-detailsreports.php.
7.5HIGH
CVE-2020-22174
all versions
PHPGurukul Hospital Management System in PHP v4.0 has a SQL injection vulnerability in \hms\book-appointment.php. Remote unauthent
7.5HIGH
CVE-2020-22173
all versions
PHPGurukul Hospital Management System in PHP v4.0 has a SQL injection vulnerability in \hms\edit-profile.php. Remote unauthenticat
7.5HIGH
CVE-2020-22172
all versions
PHPGurukul Hospital Management System in PHP v4.0 has a SQL injection vulnerability in \hms\get_doctor.php. Remote unauthenticated
7.5HIGH
CVE-2020-22171
all versions
PHPGurukul Hospital Management System in PHP v4.0 has a SQL injection vulnerability in \hms\registration.php. Remote unauthenticat
7.5HIGH
CVE-2020-22170
all versions
PHPGurukul Hospital Management System in PHP v4.0 has a SQL injection vulnerability in \hms\get_doctor.php. Remote unauthenticated
7.5HIGH
CVE-2020-22169
all versions
PHPGurukul Hospital Management System in PHP v4.0 has a SQL injection vulnerability in \hms\appointment-history.php. Remote unauth
7.5HIGH
CVE-2020-22168
all versions
PHPGurukul Hospital Management System in PHP v4.0 has a SQL injection vulnerability in \hms\change-emaild.php. Remote unauthentica
7.5HIGH
CVE-2020-22167
all versions
PHPGurukul Hospital Management System in PHP v4.0 has a Persistent Cross-Site Scripting vulnerability in \hms\admin\appointment-hi
5.4MEDIUM
CVE-2020-22166
all versions
PHPGurukul Hospital Management System in PHP v4.0 has a SQL injection vulnerability in \hms\forgot-password.php. Remote unauthenti
7.5HIGH
CVE-2020-22165
all versions
PHPGurukul Hospital Management System in PHP v4.0 has a SQL injection vulnerability in \hms\user-login.php. Remote unauthenticated
7.5HIGH
CVE-2020-22164
all versions
PHPGurukul Hospital Management System in PHP v4.0 has a SQL injection vulnerability in \hms\check_availability.php. Remote unauthe
7.5HIGH
CVE-2020-35745
all versions
PHPGURUKUL Hospital Management System V 4.0 does not properly restrict access to admin/dashboard.php, which allows attackers to ac
8.8HIGH
CVE-2020-25271
all versions
PHPGurukul hospital-management-system-in-php 4.0 allows XSS via admin/patient-search.php, doctor/search.php, book-appointment.php,
5.4MEDIUM
CVE-2020-5193
all versions
PHPGurukul Hospital Management System in PHP v4.0 suffers from multiple reflected XSS vulnerabilities via the searchdata or Doctor
6.1MEDIUM
CVE-2020-5192
all versions
PHPGurukul Hospital Management System in PHP v4.0 suffers from multiple SQL injection vulnerabilities: multiple pages and paramete
8.8HIGH
CVE-2020-5191
all versions
PHPGurukul Hospital Management System in PHP v4.0 suffers from multiple Persistent XSS vulnerabilities.
6.1MEDIUM
threatengine.sh