PatchSiren

PHPGurukul CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM PHPGurukul CVE published 2026-04-09

CVE-2026-5837

A SQL injection vulnerability was found in PHPGurukul News Portal Project 4.1, affecting the /news-details.php file. The vulnerability is due to improper handling of user input in the Comment argument. This allows an attacker to inject malicious SQL code, potentially leading to unauthorized access or data manipulation. The attack can be launched remotely, and the exploit has been made public.

LOW PHPGurukul CVE published 2026-04-06

CVE-2026-5636

A weakness has been identified in PHPGurukul Online Shopping Portal Project 2.1, affecting an unknown part of the file /cancelorder.php of the component Parameter Handler. This manipulation of the argument oid causes SQL injection. The attack may be initiated remotely. Users should review compensating controls and monitor for suspicious activity while remediation is planned.