Critical severity9.8NVD Advisory· Published Feb 18, 2026· Updated Jun 17, 2026
CVE-2025-70150
CVE-2025-70150
Description
CodeAstro Membership Management System 1.0 contains a missing authentication vulnerability in delete_members.php that allows unauthenticated attackers to delete arbitrary member records via the id parameter.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
31.0+ 1 more
- (no CPE)range: 1.0
- cpe:2.3:a:codeastro:membership_management_system:1.0:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
2- youngkevinn.github.io/posts/CVE-2025-70150-Membership-Unauth-Delete/nvdExploitMitigationThird Party Advisory
- www.phpscriptsonline.com/product/membership-management-softwarenvdProduct
News mentions
0No linked articles in our index yet.