📦 Hospital Management System

by Phpgurukul

🔍 What is Hospital Management System?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-56212

CRITICAL CVSS 9.8 Aug 25, 2025

CVE-2025-56212 is a critical SQL injection vulnerability in phpgurukul Hospital Management System 4.0 that allows attackers to execute arbitrary SQL commands via the docname parameter in add-doctor.ph...

CVE-2020-26629

CRITICAL CVSS 9.8 Jan 10, 2024

CVE-2020-26629 is an unauthenticated arbitrary file upload vulnerability in Hospital Management System V4.0 that allows attackers to upload malicious files to the server. This affects all deployments ...

CVE-2022-24263

CRITICAL CVSS 9.8 Jan 31, 2022

CVE-2022-24263 is a SQL injection vulnerability in Hospital Management System v4.0 that allows attackers to execute arbitrary SQL commands via the email parameter in func.php. This affects all users r...

CVE-2025-56216

HIGH CVSS 8.5 Aug 25, 2025

CVE-2025-56216 is an SQL injection vulnerability in phpgurukul Hospital Management System 4.0 that allows attackers to execute arbitrary SQL commands via the pagetitle parameter in about-us.php. This ...

CVE-2025-7604

HIGH CVSS 7.3 Jul 14, 2025

CVE-2025-7604 is a critical SQL injection vulnerability in PHPGurukul Hospital Management System 4.0 that allows remote attackers to execute arbitrary SQL commands via the Username parameter in /user-...

CVE-2025-7176

HIGH CVSS 7.3 Jul 8, 2025

This critical SQL injection vulnerability in PHPGurukul Hospital Management System 1.0 allows remote attackers to execute arbitrary SQL commands via the viewid parameter in view-medhistory.php. This c...

CVE-2022-46499

HIGH CVSS 8.8 Mar 7, 2024

Hospital Management System 1.0 contains a SQL injection vulnerability in the pat_number parameter at his_admin_view_single_patient.php. This allows attackers to execute arbitrary SQL commands on the d...

CVE-2022-46497

HIGH CVSS 8.1 Mar 7, 2024

Hospital Management System 1.0 contains a SQL injection vulnerability in the pat_number parameter at his_doc_view_single_patien.php. This allows attackers to execute arbitrary SQL commands on the data...

CVE-2023-7172

HIGH CVSS 7.3 Dec 30, 2023

This critical SQL injection vulnerability in PHPGurukul Hospital Management System 1.0 allows attackers to execute arbitrary SQL commands through the Admin Dashboard component. Attackers can potential...

CVE-2022-24226

HIGH CVSS 7.5 Feb 15, 2022

Hospital Management System v4.0 contains a blind SQL injection vulnerability in the register function (func2.php) that allows attackers to execute arbitrary SQL commands without seeing the results dir...

CVE-2022-24646

HIGH CVSS 7.5 Feb 10, 2022

This SQL injection vulnerability in Hospital Management System v4.0 allows attackers to execute arbitrary SQL commands through the txtMsg parameter in contact.php. This could lead to unauthorized data...

CVE-2020-22168

HIGH CVSS 7.5 Jun 22, 2021

CVE-2020-22168 is a SQL injection vulnerability in PHPGurukul Hospital Management System v4.0 that allows remote unauthenticated attackers to execute arbitrary SQL commands. This can lead to unauthori...

CVE-2020-22170

HIGH CVSS 7.5 Jun 22, 2021

CVE-2020-22170 is a SQL injection vulnerability in PHPGurukul Hospital Management System v4.0 that allows remote unauthenticated attackers to execute arbitrary SQL commands. This can lead to unauthori...

CVE-2020-22172

HIGH CVSS 7.5 Jun 22, 2021

CVE-2020-22172 is a SQL injection vulnerability in PHPGurukul Hospital Management System v4.0 that allows remote unauthenticated attackers to execute arbitrary SQL commands through the get_doctor.php ...

CVE-2020-22174

HIGH CVSS 7.5 Jun 22, 2021

CVE-2020-22174 is a SQL injection vulnerability in PHPGurukul Hospital Management System v4.0 that allows remote unauthenticated attackers to execute arbitrary SQL commands via the book-appointment.ph...

CVE-2020-22176

HIGH CVSS 7.5 Jun 22, 2021

CVE-2020-22176 allows remote unauthenticated attackers to access sensitive user information in PHPGurukul Hospital Management System v4.0. This affects all deployments of this specific version that ar...

CVE-2020-22165

HIGH CVSS 7.5 Jun 22, 2021

CVE-2020-22165 is a SQL injection vulnerability in PHPGurukul Hospital Management System v4.0 that allows remote unauthenticated attackers to execute arbitrary SQL queries. This can lead to unauthoriz...

CVE-2025-70063

MEDIUM CVSS 6.5 Feb 18, 2026

This IDOR vulnerability in PHPGurukul Hospital Management System allows authenticated users to access other patients' confidential medical records by manipulating the 'viewid' parameter. Any healthcar...

CVE-2026-2134

MEDIUM CVSS 4.7 Feb 8, 2026

This CVE describes a SQL injection vulnerability in PHPGurukul Hospital Management System 4.0, specifically in the /hms/admin/manage-doctors.php file via the ID parameter. It allows remote attackers t...

CVE-2026-1550

MEDIUM CVSS 6.3 Jan 28, 2026

CVE-2026-1550 is an improper authorization vulnerability in PHPGurukul Hospital Management System 1.0 that allows attackers to bypass access controls on the admin dashboard. Remote attackers can explo...

CVE-2025-56215

MEDIUM CVSS 6.5 Aug 25, 2025

This SQL injection vulnerability in phpgurukul Hospital Management System 4.0 allows attackers to manipulate database queries through the pagetitle parameter in contact.php. Attackers could potentiall...

CVE-2024-56990

MEDIUM CVSS 4.5 Jan 21, 2025

PHPGurukul Hospital Management System 4.0 contains stored cross-site scripting vulnerabilities in patient history and admin view pages. Attackers can inject malicious scripts that execute when legitim...

CVE-2024-56997

MEDIUM CVSS 4.2 Jan 21, 2025

PHPGurukul Hospital Management System 4.0 contains a stored cross-site scripting (XSS) vulnerability in the doctor portal's email parameter. This allows attackers to inject malicious scripts that exec...

CVE-2024-46238

MEDIUM CVSS 5.9 Oct 21, 2024

This CVE describes multiple stored XSS vulnerabilities in PHPGurukul Hospital Management System 4.0. Attackers can inject malicious scripts via the docname parameter in doctor management pages, which ...