Codeastro
Products
50- 40 CVEs
- 28 CVEs
- 23 CVEs
- 18 CVEs
- 14 CVEs
- 14 CVEs
- 8 CVEs
- 7 CVEs
- 7 CVEs
- 7 CVEs
- 6 CVEs
- 6 CVEs
- 6 CVEs
- 5 CVEs
- 5 CVEs
- 5 CVEs
- 5 CVEs
- 5 CVEs
- 5 CVEs
- 4 CVEs
- 4 CVEs
- 4 CVEs
- 4 CVEs
- 4 CVEs
- 4 CVEs
- 4 CVEs
- 4 CVEs
- 3 CVEs
- 3 CVEs
- 3 CVEs
- View all 50 products →
Recent CVEs
240| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-37749 | Cri | 0.64 | 9.8 | 0.01 | Apr 17, 2026 | A SQL injection vulnerability in CodeAstro Simple Attendance Management System v1.0 allows remote unauthenticated attackers to bypass authentication via the username parameter in index.php. | ||
| CVE-2025-70150 | Cri | 0.64 | 9.8 | 0.01 | Feb 18, 2026 | CodeAstro Membership Management System 1.0 contains a missing authentication vulnerability in delete_members.php that allows unauthenticated attackers to delete arbitrary member records via the id parameter. | ||
| CVE-2025-70149 | Cri | 0.64 | 9.8 | 0.00 | Feb 18, 2026 | CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in print_membership_card.php via the ID parameter. | ||
| CVE-2025-25775 | Cri | 0.64 | 9.8 | 0.01 | Apr 25, 2025 | Codeastro Bus Ticket Booking System v1.0 is vulnerable to SQL injection via the kodetiket parameter in /BusTicket-CI/tiket/cekorder. | ||
| CVE-2024-55507 | Cri | 0.64 | 9.8 | 0.01 | Jan 3, 2025 | An issue in CodeAstro Complaint Management System v.1.0 allows a remote attacker to escalate privileges via the delete_e.php component. | ||
| CVE-2024-55509 | Cri | 0.64 | 9.8 | 0.01 | Dec 20, 2024 | SQL injection vulnerability in CodeAstro Complaint Management System v.1.0 allows a remote attacker to execute arbitrary code and escalate privileges via the id parameter of the delete.php component. | ||
| CVE-2022-30817 | Cri | 0.64 | 9.8 | 0.01 | Jun 2, 2022 | Simple Bus Ticket Booking System 1.0 is vulnerable to SQL Injection via /SimpleBusTicket/index.php. | ||
| CVE-2024-25869 | Hig | 0.59 | 8.8 | 0.19 | Feb 28, 2024 | An Unrestricted File Upload vulnerability in CodeAstro Membership Management System in PHP v.1.0 allows a remote attacker to execute arbitrary code via upload of a crafted php file in the settings.php component. | ||
| CVE-2024-25867 | Cri | 0.59 | 9.1 | 0.01 | Feb 28, 2024 | A SQL Injection vulnerability in CodeAstro Membership Management System in PHP v.1.0 allows a remote attacker to execute arbitrary SQL commands via the membershipType and membershipAmount parameters in the add_type.php component. | ||
| CVE-2025-29017 | Hig | 0.57 | 8.8 | 0.01 | Apr 10, 2025 | A Remote Code Execution (RCE) vulnerability exists in Code Astro Internet Banking System 2.0.0 due to improper file upload validation in the profile_pic parameter within pages_view_client.php. | ||
| CVE-2024-55506 | Hig | 0.57 | 8.8 | 0.01 | Dec 18, 2024 | An IDOR vulnerability in CodeAstro's Complaint Management System v1.0 (version with 0 updates) enables an attacker to execute arbitrary code and obtain sensitive information via the delete.php file and modifying the id parameter. | ||
| CVE-2024-55505 | Hig | 0.57 | 8.8 | 0.01 | Dec 18, 2024 | An issue in CodeAstro Complaint Management System v.1.0 allows a remote attacker to escalate privileges via the mess-view.php component. | ||
| CVE-2024-25866 | Hig | 0.57 | 8.8 | 0.01 | Feb 28, 2024 | A SQL Injection vulnerability in CodeAstro Membership Management System in PHP v.1.0 allows a remote attacker to execute arbitrary SQL commands via the email parameter in the index.php component. | ||
| CVE-2022-30822 | Hig | 0.57 | 8.8 | 0.01 | Jun 2, 2022 | In Wedding Management System v1.0, there is an arbitrary file upload vulnerability in the picture upload point of "users_profile.php" file. | ||
| CVE-2022-30821 | Hig | 0.57 | 8.8 | 0.01 | Jun 2, 2022 | In Wedding Management System v1.0, the editing function of the "Services" module in the background management system has an arbitrary file upload vulnerability in the picture upload point of "package_edit.php" file. | ||
| CVE-2022-30820 | Hig | 0.57 | 8.8 | 0.01 | Jun 2, 2022 | In Wedding Management v1.0, there is an arbitrary file upload vulnerability in the picture upload point of "users_edit.php" file. | ||
| CVE-2022-30819 | Hig | 0.57 | 8.8 | 0.01 | Jun 2, 2022 | In Wedding Management System v1.0, there is an arbitrary file upload vulnerability in the picture upload point of "photos_edit.php" file. | ||
| CVE-2024-46472 | Hig | 0.56 | 8.6 | 0.00 | Sep 27, 2024 | CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection via the parameter 'email' in the Login Page. | ||
| CVE-2025-25777 | Hig | 0.52 | 8.0 | 0.00 | Apr 24, 2025 | Insecure Direct Object Reference (IDOR) in Codeastro Bus Ticket Booking System v1.0 allows unauthorized access to user profiles. By manipulating the user ID in the URL, an attacker can access another user's profile without proper authentication or authorization checks. | ||
| CVE-2025-70148 | Hig | 0.49 | 7.5 | 0.00 | Feb 18, 2026 | Missing authentication and authorization in print_membership_card.php in CodeAstro Membership Management System 1.0 allows unauthenticated attackers to access membership card data of arbitrary users via direct requests with a manipulated id parameter, resulting in insecure… |
- risk 0.64cvss 9.8epss 0.01
A SQL injection vulnerability in CodeAstro Simple Attendance Management System v1.0 allows remote unauthenticated attackers to bypass authentication via the username parameter in index.php.
- risk 0.64cvss 9.8epss 0.01
CodeAstro Membership Management System 1.0 contains a missing authentication vulnerability in delete_members.php that allows unauthenticated attackers to delete arbitrary member records via the id parameter.
- risk 0.64cvss 9.8epss 0.00
CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in print_membership_card.php via the ID parameter.
- risk 0.64cvss 9.8epss 0.01
Codeastro Bus Ticket Booking System v1.0 is vulnerable to SQL injection via the kodetiket parameter in /BusTicket-CI/tiket/cekorder.
- risk 0.64cvss 9.8epss 0.01
An issue in CodeAstro Complaint Management System v.1.0 allows a remote attacker to escalate privileges via the delete_e.php component.
- risk 0.64cvss 9.8epss 0.01
SQL injection vulnerability in CodeAstro Complaint Management System v.1.0 allows a remote attacker to execute arbitrary code and escalate privileges via the id parameter of the delete.php component.
- risk 0.64cvss 9.8epss 0.01
Simple Bus Ticket Booking System 1.0 is vulnerable to SQL Injection via /SimpleBusTicket/index.php.
- risk 0.59cvss 8.8epss 0.19
An Unrestricted File Upload vulnerability in CodeAstro Membership Management System in PHP v.1.0 allows a remote attacker to execute arbitrary code via upload of a crafted php file in the settings.php component.
- risk 0.59cvss 9.1epss 0.01
A SQL Injection vulnerability in CodeAstro Membership Management System in PHP v.1.0 allows a remote attacker to execute arbitrary SQL commands via the membershipType and membershipAmount parameters in the add_type.php component.
- risk 0.57cvss 8.8epss 0.01
A Remote Code Execution (RCE) vulnerability exists in Code Astro Internet Banking System 2.0.0 due to improper file upload validation in the profile_pic parameter within pages_view_client.php.
- risk 0.57cvss 8.8epss 0.01
An IDOR vulnerability in CodeAstro's Complaint Management System v1.0 (version with 0 updates) enables an attacker to execute arbitrary code and obtain sensitive information via the delete.php file and modifying the id parameter.
- risk 0.57cvss 8.8epss 0.01
An issue in CodeAstro Complaint Management System v.1.0 allows a remote attacker to escalate privileges via the mess-view.php component.
- risk 0.57cvss 8.8epss 0.01
A SQL Injection vulnerability in CodeAstro Membership Management System in PHP v.1.0 allows a remote attacker to execute arbitrary SQL commands via the email parameter in the index.php component.
- risk 0.57cvss 8.8epss 0.01
In Wedding Management System v1.0, there is an arbitrary file upload vulnerability in the picture upload point of "users_profile.php" file.
- risk 0.57cvss 8.8epss 0.01
In Wedding Management System v1.0, the editing function of the "Services" module in the background management system has an arbitrary file upload vulnerability in the picture upload point of "package_edit.php" file.
- risk 0.57cvss 8.8epss 0.01
In Wedding Management v1.0, there is an arbitrary file upload vulnerability in the picture upload point of "users_edit.php" file.
- risk 0.57cvss 8.8epss 0.01
In Wedding Management System v1.0, there is an arbitrary file upload vulnerability in the picture upload point of "photos_edit.php" file.
- risk 0.56cvss 8.6epss 0.00
CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection via the parameter 'email' in the Login Page.
- risk 0.52cvss 8.0epss 0.00
Insecure Direct Object Reference (IDOR) in Codeastro Bus Ticket Booking System v1.0 allows unauthorized access to user profiles. By manipulating the user ID in the URL, an attacker can access another user's profile without proper authentication or authorization checks.
- risk 0.49cvss 7.5epss 0.00
Missing authentication and authorization in print_membership_card.php in CodeAstro Membership Management System 1.0 allows unauthenticated attackers to access membership card data of arbitrary users via direct requests with a manipulated id parameter, resulting in insecure…