CVE-2025-25351: Phpgurukul Daily Expense Tracker System

Critical severity, CVSS 9.8. EPSS: 0.5% chance of exploitation in the next 30 days.

PHPGurukul Daily Expense Tracker System v1.1 is vulnerable to SQL Injection in /dets/add-expense.php via the dateexpense parameter.

Affected products

  • Phpgurukul Daily Expense Tracker System: version 1.1 only

Published 2025-02-12. Last modified 2026-06-17.