VYPR

Vendor CVEs

Codeastro

All CVEs

240 total · sorted by risk
  • CVE-2026-37749CriApr 17, 2026
    risk 0.64cvss 9.8epss 0.01

    A SQL injection vulnerability in CodeAstro Simple Attendance Management System v1.0 allows remote unauthenticated attackers to bypass authentication via the username parameter in index.php.

  • CVE-2025-70150CriFeb 18, 2026
    risk 0.64cvss 9.8epss 0.01

    CodeAstro Membership Management System 1.0 contains a missing authentication vulnerability in delete_members.php that allows unauthenticated attackers to delete arbitrary member records via the id parameter.

  • CVE-2025-70149CriFeb 18, 2026
    risk 0.64cvss 9.8epss 0.00

    CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in print_membership_card.php via the ID parameter.

  • CVE-2025-25775CriApr 25, 2025
    risk 0.64cvss 9.8epss 0.01

    Codeastro Bus Ticket Booking System v1.0 is vulnerable to SQL injection via the kodetiket parameter in /BusTicket-CI/tiket/cekorder.

  • CVE-2024-55507CriJan 3, 2025
    risk 0.64cvss 9.8epss 0.01

    An issue in CodeAstro Complaint Management System v.1.0 allows a remote attacker to escalate privileges via the delete_e.php component.

  • CVE-2024-55509CriDec 20, 2024
    risk 0.64cvss 9.8epss 0.01

    SQL injection vulnerability in CodeAstro Complaint Management System v.1.0 allows a remote attacker to execute arbitrary code and escalate privileges via the id parameter of the delete.php component.

  • CVE-2022-30817CriJun 2, 2022
    risk 0.64cvss 9.8epss 0.01

    Simple Bus Ticket Booking System 1.0 is vulnerable to SQL Injection via /SimpleBusTicket/index.php.

  • CVE-2024-25869HigFeb 28, 2024
    risk 0.59cvss 8.8epss 0.19

    An Unrestricted File Upload vulnerability in CodeAstro Membership Management System in PHP v.1.0 allows a remote attacker to execute arbitrary code via upload of a crafted php file in the settings.php component.

  • CVE-2024-25867CriFeb 28, 2024
    risk 0.59cvss 9.1epss 0.01

    A SQL Injection vulnerability in CodeAstro Membership Management System in PHP v.1.0 allows a remote attacker to execute arbitrary SQL commands via the membershipType and membershipAmount parameters in the add_type.php component.

  • CVE-2025-29017HigApr 10, 2025
    risk 0.57cvss 8.8epss 0.01

    A Remote Code Execution (RCE) vulnerability exists in Code Astro Internet Banking System 2.0.0 due to improper file upload validation in the profile_pic parameter within pages_view_client.php.

  • CVE-2024-55506HigDec 18, 2024
    risk 0.57cvss 8.8epss 0.01

    An IDOR vulnerability in CodeAstro's Complaint Management System v1.0 (version with 0 updates) enables an attacker to execute arbitrary code and obtain sensitive information via the delete.php file and modifying the id parameter.

  • CVE-2024-55505HigDec 18, 2024
    risk 0.57cvss 8.8epss 0.01

    An issue in CodeAstro Complaint Management System v.1.0 allows a remote attacker to escalate privileges via the mess-view.php component.

  • CVE-2024-25866HigFeb 28, 2024
    risk 0.57cvss 8.8epss 0.01

    A SQL Injection vulnerability in CodeAstro Membership Management System in PHP v.1.0 allows a remote attacker to execute arbitrary SQL commands via the email parameter in the index.php component.

  • CVE-2022-30822HigJun 2, 2022
    risk 0.57cvss 8.8epss 0.01

    In Wedding Management System v1.0, there is an arbitrary file upload vulnerability in the picture upload point of "users_profile.php" file.

  • CVE-2022-30821HigJun 2, 2022
    risk 0.57cvss 8.8epss 0.01

    In Wedding Management System v1.0, the editing function of the "Services" module in the background management system has an arbitrary file upload vulnerability in the picture upload point of "package_edit.php" file.

  • CVE-2022-30820HigJun 2, 2022
    risk 0.57cvss 8.8epss 0.01

    In Wedding Management v1.0, there is an arbitrary file upload vulnerability in the picture upload point of "users_edit.php" file.

  • CVE-2022-30819HigJun 2, 2022
    risk 0.57cvss 8.8epss 0.01

    In Wedding Management System v1.0, there is an arbitrary file upload vulnerability in the picture upload point of "photos_edit.php" file.

  • CVE-2024-46472HigSep 27, 2024
    risk 0.56cvss 8.6epss 0.00

    CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection via the parameter 'email' in the Login Page.

  • CVE-2025-25777HigApr 24, 2025
    risk 0.52cvss 8.0epss 0.00

    Insecure Direct Object Reference (IDOR) in Codeastro Bus Ticket Booking System v1.0 allows unauthorized access to user profiles. By manipulating the user ID in the URL, an attacker can access another user's profile without proper authentication or authorization checks.

  • CVE-2025-70148HigFeb 18, 2026
    risk 0.49cvss 7.5epss 0.00

    Missing authentication and authorization in print_membership_card.php in CodeAstro Membership Management System 1.0 allows unauthenticated attackers to access membership card data of arbitrary users via direct requests with a manipulated id parameter, resulting in insecure…

  • CVE-2024-56889HigFeb 6, 2025
    risk 0.49cvss 7.5epss 0.01

    Incorrect access control in the endpoint /admin/m_delete.php of CodeAstro Complaint Management System v1.0 allows unauthorized attackers to arbitrarily delete complaints via modification of the id parameter.

  • CVE-2024-46471HigSep 27, 2024
    risk 0.49cvss 7.5epss 0.01

    The Directory Listing in /uploads/ Folder in CodeAstro Membership Management System 1.0 exposes the structure and contents of directories, potentially revealing sensitive information.

  • CVE-2024-13038HigDec 30, 2024
    risk 0.48cvss 7.3epss 0.01

    A vulnerability was found in CodeAstro Simple Loan Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /index.php of the component Login. The manipulation of the argument email leads to sql injection.…

  • CVE-2024-12944HigDec 26, 2024
    risk 0.48cvss 7.3epss 0.01

    A vulnerability was found in CodeAstro House Rental Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /signin.php. The manipulation of the argument u/p leads to sql injection. The attack may be launched…

  • CVE-2024-12943HigDec 26, 2024
    risk 0.48cvss 7.3epss 0.01

    A vulnerability was found in CodeAstro House Rental Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /ownersignup.php. The manipulation of the argument f/e/p/m/o/n/c/s/ci/a leads to sql injection. The…

  • CVE-2024-0247HigJan 5, 2024
    risk 0.48cvss 7.3epss 0.01

    A vulnerability classified as critical was found in CodeAstro Online Food Ordering System 1.0. This vulnerability affects unknown code of the file /admin/ of the component Admin Panel. The manipulation of the argument Username leads to sql injection. The attack can be initiated…

  • CVE-2026-11582HigJun 8, 2026
    risk 0.47cvss 7.3epss 0.00

    A flaw has been found in CodeAstro Student Attendance Management System 1.0. The impacted element is an unknown function of the file /attendance-php/index.php. Executing a manipulation of the argument Username can lead to sql injection. The attack may be performed from remote.…

  • CVE-2026-10261HigJun 1, 2026
    risk 0.47cvss 7.3epss 0.00

    A flaw has been found in CodeAstro Online Job Portal 1.0. This affects an unknown function of the file /users/application_status.php. Executing a manipulation of the argument ID can lead to sql injection. It is possible to launch the attack remotely. The exploit has been…

  • CVE-2026-10260HigJun 1, 2026
    risk 0.47cvss 7.3epss 0.00

    A vulnerability was detected in CodeAstro Online Job Portal 1.0. The impacted element is an unknown function of the file /admin/jobs-admins/delete-jobs.php. Performing a manipulation of the argument ID results in sql injection. It is possible to initiate the attack remotely. The…

  • CVE-2026-8132HigMay 8, 2026
    risk 0.47cvss 7.3epss 0.00

    A weakness has been identified in CodeAstro Leave Management System 1.0. Affected is an unknown function of the file /login.php. This manipulation of the argument txt_username causes sql injection. The attack can be initiated remotely. The exploit has been made available to the…

  • CVE-2025-13280HigNov 17, 2025
    risk 0.47cvss 7.3epss 0.00

    A vulnerability was determined in CodeAstro Simple Inventory System 1.0. The impacted element is an unknown function of the file /index.php of the component Login. Executing a manipulation of the argument Username can lead to sql injection. The attack may be launched remotely.…

  • CVE-2025-11118HigSep 28, 2025
    risk 0.47cvss 7.3epss 0.00

    A vulnerability was identified in CodeAstro Student Grading System 1.0. This issue affects some unknown processing of the file /adminLogin.php. Such manipulation of the argument staffId leads to sql injection. The attack may be performed from remote. The exploit is publicly…

  • CVE-2025-9848HigSep 3, 2025
    risk 0.47cvss 7.3epss 0.01

    A security vulnerability has been detected in ScriptAndTools Real Estate Management System 1.0. The affected element is an unknown function of the file /admin/userlist.php. Such manipulation leads to execution after redirect. The attack can be executed remotely. The exploit has…

  • CVE-2025-7147HigJul 7, 2025
    risk 0.47cvss 7.3epss 0.00

    A vulnerability has been found in CodeAstro Patient Record Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /login.php. The manipulation of the argument uname leads to sql injection. The attack can be…

  • CVE-2025-5583HigJun 4, 2025
    risk 0.47cvss 7.3epss 0.00

    A vulnerability classified as critical has been found in CodeAstro Real Estate Management System 1.0. Affected is an unknown function of the file /register.php. The manipulation leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed…

  • CVE-2025-5581HigJun 4, 2025
    risk 0.47cvss 7.3epss 0.01

    A vulnerability was found in CodeAstro Real Estate Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /admin/index.php. The manipulation of the argument User leads to sql injection. The attack can be initiated remotely.…

  • CVE-2025-5580HigJun 4, 2025
    risk 0.47cvss 7.3epss 0.01

    A vulnerability was found in CodeAstro Real Estate Management System 1.0. It has been classified as critical. This affects an unknown part of the file /login.php. The manipulation of the argument email leads to sql injection. It is possible to initiate the attack remotely. The…

  • CVE-2025-5128HigMay 24, 2025
    risk 0.47cvss 7.3epss 0.01

    A vulnerability, which was classified as critical, was found in ScriptAndTools Real-Estate-website-in-PHP 1.0. Affected is an unknown function of the file /admin/ of the component Admin Login Panel. The manipulation of the argument Password leads to sql injection. It is possible…

  • CVE-2025-4811HigMay 16, 2025
    risk 0.47cvss 7.3epss 0.00

    A vulnerability was found in CodeAstro Pharmacy Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /index.php of the component Login. The manipulation of the argument Username leads to sql injection. The attack…

  • CVE-2025-4066HigApr 29, 2025
    risk 0.47cvss 7.3epss 0.01

    A vulnerability was found in ScriptAndTools Online-Travling-System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /admin/addpackage.php. The manipulation leads to improper access controls. The attack may be initiated remotely. The…

  • CVE-2025-4065HigApr 29, 2025
    risk 0.47cvss 7.3epss 0.00

    A vulnerability was found in ScriptAndTools Online-Travling-System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /admin/addadvertisement.php. The manipulation leads to improper access controls. The attack can be initiated remotely.…

  • CVE-2025-3998HigApr 28, 2025
    risk 0.47cvss 7.3epss 0.01

    A vulnerability classified as critical was found in CodeAstro Membership Management System 1.0. This vulnerability affects unknown code of the file renew.php?id=6. The manipulation of the argument ID leads to sql injection. The attack can be initiated remotely. The exploit has…

  • CVE-2024-56924HigJan 22, 2025
    risk 0.47cvss 7.3epss 0.00

    A Cross Site Request Forgery (CSRF) vulnerability in Code Astro Internet banking system 2.0.0 allows remote attackers to execute arbitrary JavaScript on the admin page (pages_account), potentially leading to unauthorized actions such as changing account settings or stealing…

  • CVE-2024-1824HigFeb 23, 2024
    risk 0.47cvss 7.3epss 0.01

    A vulnerability, which was classified as critical, has been found in CodeAstro House Rental Management System 1.0. Affected by this issue is some unknown functionality of the file signing.php. The manipulation of the argument uname/password leads to sql injection. The attack may…

  • CVE-2022-43085HigNov 1, 2022
    risk 0.47cvss 7.2epss 0.01

    An arbitrary file upload vulnerability in add_product.php of Restaurant POS System v1.0 allows attackers to execute arbitrary code via a crafted PHP file.

  • CVE-2022-30836HigJun 2, 2022
    risk 0.47cvss 7.2epss 0.01

    Wedding Management System v1.0 is vulnerable to SQL Injection. via Wedding-Management/admin/select.php.

  • CVE-2022-30835HigJun 2, 2022
    risk 0.47cvss 7.2epss 0.01

    Wedding Management System v1.0 is vulnerable to SQL Injection. via /Wedding-Management/admin/budget.php?booking_id=.

  • CVE-2022-30834HigJun 2, 2022
    risk 0.47cvss 7.2epss 0.01

    Wedding Management System v1.0 is vulnerable to SQL Injection via /Wedding-Management/admin/client_manage_account_details.php?booking_id=31&user_id=

  • CVE-2022-30833HigJun 2, 2022
    risk 0.47cvss 7.2epss 0.01

    Wedding Management System v1.0 is vulnerable to SQL Injection via /Wedding-Management/admin/client_edit.php?booking=31&user_id=.

  • CVE-2022-30832HigJun 2, 2022
    risk 0.47cvss 7.2epss 0.01

    Wedding Management System v1.0 is vulnerable to SQL Injection via /Wedding-Management/admin/client_assign.php?booking=31&user_id=.

Page 1 of 5