Filtered by vendor Codeastro
Subscriptions
Filtered by product Membership Management System
Subscriptions
Total
25 CVE
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2025-69930 | 1 Codeastro | 1 Membership Management System | 2026-08-02 | 9.8 Critical |
| CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /print_membership_card.php?id=1. | ||||
| CVE-2025-69938 | 1 Codeastro | 1 Membership Management System | 2026-08-02 | 9.8 Critical |
| CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in renew.php via the parameter membershipType. | ||||
| CVE-2025-69931 | 1 Codeastro | 1 Membership Management System | 2026-07-31 | N/A |
| CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /delete_membership.php?id=1. | ||||
| CVE-2025-69933 | 1 Codeastro | 1 Membership Management System | 2026-07-31 | 9.8 Critical |
| CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /memberProfile.php?id=1. | ||||
| CVE-2025-69935 | 1 Codeastro | 1 Membership Management System | 2026-07-31 | 9.8 Critical |
| CodeAstro Membership Management System 1.0 is vulnerale to SQL Injection in the report.php and revenue_report.php via the fromDate parameter. | ||||
| CVE-2026-36387 | 1 Codeastro | 1 Membership Management System | 2026-05-07 | 6.5 Medium |
| A Remote Code Execution vulnerability was found in CODEASTRO Membership Management System v1.0 in /add_members.php. This vulnerability affects the file upload functionality, where improper file sanitization allows attackers to inject malicious files which leads RCE. | ||||
| CVE-2025-70149 | 1 Codeastro | 1 Membership Management System | 2026-02-23 | 9.8 Critical |
| CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in print_membership_card.php via the ID parameter. | ||||
| CVE-2025-70150 | 1 Codeastro | 1 Membership Management System | 2026-02-23 | 9.8 Critical |
| CodeAstro Membership Management System 1.0 contains a missing authentication vulnerability in delete_members.php that allows unauthenticated attackers to delete arbitrary member records via the id parameter. | ||||
| CVE-2025-70148 | 1 Codeastro | 1 Membership Management System | 2026-02-20 | 7.5 High |
| Missing authentication and authorization in print_membership_card.php in CodeAstro Membership Management System 1.0 allows unauthenticated attackers to access membership card data of arbitrary users via direct requests with a manipulated id parameter, resulting in insecure direct object reference (IDOR). | ||||
| CVE-2024-48709 | 1 Codeastro | 1 Membership Management System | 2025-11-25 | 5.4 Medium |
| CodeAstro Membership Management System v1.0 is vulnerable to Cross Site Scripting (XSS) via the membershipType parameter in edit_type.php | ||||
| CVE-2025-3998 | 1 Codeastro | 1 Membership Management System | 2025-05-14 | 7.3 High |
| A vulnerability classified as critical was found in CodeAstro Membership Management System 1.0. This vulnerability affects unknown code of the file renew.php?id=6. The manipulation of the argument ID leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. | ||||
| CVE-2024-25866 | 1 Codeastro | 1 Membership Management System | 2025-04-01 | 8.8 High |
| A SQL Injection vulnerability in CodeAstro Membership Management System in PHP v.1.0 allows a remote attacker to execute arbitrary SQL commands via the email parameter in the index.php component. | ||||
| CVE-2024-25867 | 1 Codeastro | 1 Membership Management System | 2025-04-01 | 9.1 Critical |
| A SQL Injection vulnerability in CodeAstro Membership Management System in PHP v.1.0 allows a remote attacker to execute arbitrary SQL commands via the membershipType and membershipAmount parameters in the add_type.php component. | ||||
| CVE-2024-25868 | 1 Codeastro | 1 Membership Management System | 2025-04-01 | 6.1 Medium |
| A Cross Site Scripting (XSS) vulnerability in CodeAstro Membership Management System in PHP v.1.0 allows a remote attacker to execute arbitrary code via the membershipType parameter in the add_type.php component. | ||||
| CVE-2024-25869 | 1 Codeastro | 1 Membership Management System | 2025-04-01 | 8.8 High |
| An Unrestricted File Upload vulnerability in CodeAstro Membership Management System in PHP v.1.0 allows a remote attacker to execute arbitrary code via upload of a crafted php file in the settings.php component. | ||||
| CVE-2024-46470 | 1 Codeastro | 1 Membership Management System | 2025-03-31 | 6.1 Medium |
| Cross Site Scripting vulnerability in CodeAstro Membership Management System 1.0 allows attackers to run malicious JavaScript via the membership_type field in the edit-type.php component. | ||||
| CVE-2024-46471 | 1 Codeastro | 1 Membership Management System | 2025-03-31 | 7.5 High |
| The Directory Listing in /uploads/ Folder in CodeAstro Membership Management System 1.0 exposes the structure and contents of directories, potentially revealing sensitive information. | ||||
| CVE-2024-46472 | 1 Codeastro | 1 Membership Management System | 2025-03-31 | 8.6 High |
| CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection via the parameter 'email' in the Login Page. | ||||
| CVE-2024-45528 | 1 Codeastro | 1 Membership Management System | 2025-03-31 | 5.4 Medium |
| CodeAstro MembershipM-PHP (aka Membership Management System in PHP) 1.0 allows add_members.php fullname stored XSS. | ||||
| CVE-2024-46236 | 1 Codeastro | 1 Membership Management System | 2025-03-31 | 5.4 Medium |
| CodeAstro Membership Management System v1.0 is vulnerable to Cross Site Scripting (XSS) via the address parameter in add_members.php and edit_member.php. | ||||