VYPR

Vendor CVEs

Codeastro

All CVEs

240 total · sorted by risk
  • CVE-2025-11359MedOct 7, 2025
    risk 0.41cvss 6.3epss 0.00

    A security vulnerability has been detected in code-projects Simple Banking System 1.0. The affected element is an unknown function of the file /transfermoney.php. The manipulation of the argument ID leads to sql injection. Remote exploitation of the attack is possible. The…

  • CVE-2025-11358MedOct 7, 2025
    risk 0.41cvss 6.3epss 0.00

    A weakness has been identified in code-projects Simple Banking System 1.0. Impacted is an unknown function of the file /removeuser.php. Executing manipulation of the argument ID can lead to sql injection. The attack may be launched remotely. The exploit has been made available…

  • CVE-2025-11357MedOct 7, 2025
    risk 0.41cvss 6.3epss 0.00

    A security flaw has been discovered in code-projects Simple Banking System 1.0. This issue affects some unknown processing of the file /createuser.php. Performing manipulation of the argument Name results in sql injection. The attack may be initiated remotely. The exploit has…

  • CVE-2025-11114MedSep 28, 2025
    risk 0.41cvss 6.3epss 0.00

    A flaw has been found in CodeAstro Online Leave Application 1.0. Affected by this vulnerability is an unknown functionality of the file /leaveAplicationForm.php. Executing manipulation of the argument absence[] can lead to sql injection. The attack may be launched remotely. The…

  • CVE-2025-11113MedSep 28, 2025
    risk 0.41cvss 6.3epss 0.00

    A vulnerability was detected in CodeAstro Online Leave Application 1.0. Affected is an unknown function of the file /signup.php. Performing manipulation of the argument city results in sql injection. The attack may be initiated remotely. The exploit is now public and may be…

  • CVE-2025-11104MedSep 28, 2025
    risk 0.41cvss 6.3epss 0.00

    A vulnerability was detected in CodeAstro Electricity Billing System 1.0. Affected by this issue is some unknown functionality of the file /admin/bill.php. The manipulation of the argument uid results in sql injection. The attack may be launched remotely. The exploit is now…

  • CVE-2025-10780MedSep 22, 2025
    risk 0.41cvss 6.3epss 0.00

    A vulnerability was determined in CodeAstro Simple Pharmacy Management 1.0. This affects an unknown function of the file /view.php. This manipulation of the argument bar_code causes sql injection. Remote exploitation of the attack is possible. The exploit has been publicly…

  • CVE-2025-9942MedSep 4, 2025
    risk 0.41cvss 6.3epss 0.00

    A vulnerability has been found in CodeAstro Real Estate Management System 1.0. Affected is an unknown function of the file /submitproperty.php. The manipulation leads to unrestricted upload. The attack may be initiated remotely. The exploit has been disclosed to the public and…

  • CVE-2025-9941MedSep 4, 2025
    risk 0.41cvss 6.3epss 0.00

    A flaw has been found in CodeAstro Real Estate Management System 1.0. This impacts an unknown function of the file /register.php. Executing manipulation of the argument uimage can lead to unrestricted upload. The attack can be launched remotely. The exploit has been published…

  • CVE-2025-9847MedSep 3, 2025
    risk 0.41cvss 6.3epss 0.00

    A weakness has been identified in ScriptAndTools Real Estate Management System 1.0. Impacted is an unknown function of the file register.php. This manipulation of the argument uimage causes unrestricted upload. Remote exploitation of the attack is possible. The exploit has been…

  • CVE-2025-5611MedJun 4, 2025
    risk 0.41cvss 6.3epss 0.00

    A vulnerability, which was classified as critical, was found in CodeAstro Real Estate Management System 1.0. This affects an unknown part of the file /submitpropertyupdate.php. The manipulation of the argument ID leads to sql injection. It is possible to initiate the attack…

  • CVE-2025-5610MedJun 4, 2025
    risk 0.41cvss 6.3epss 0.00

    A vulnerability, which was classified as critical, has been found in CodeAstro Real Estate Management System 1.0. Affected by this issue is some unknown functionality of the file /submitpropertydelete.php. The manipulation of the argument ID leads to sql injection. The attack…

  • CVE-2025-5582MedJun 4, 2025
    risk 0.41cvss 6.3epss 0.00

    A vulnerability was found in CodeAstro Real Estate Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /profile.php. The manipulation of the argument content leads to sql injection. The attack may be initiated remotely.…

  • CVE-2025-3205MedApr 4, 2025
    risk 0.41cvss 6.3epss 0.00

    A vulnerability, which was classified as critical, was found in CodeAstro Student Grading System 1.0. This affects an unknown part of the file studentsubject.php. The manipulation of the argument studentId leads to sql injection. It is possible to initiate the attack remotely.…

  • CVE-2025-3204MedApr 4, 2025
    risk 0.41cvss 6.3epss 0.00

    A vulnerability, which was classified as critical, has been found in CodeAstro Car Rental System 1.0. Affected by this issue is some unknown functionality of the file /returncar.php. The manipulation of the argument ID leads to sql injection. The attack may be launched remotely.…

  • CVE-2024-13070MedDec 31, 2024
    risk 0.41cvss 6.3epss 0.01

    A vulnerability was found in CodeAstro Online Food Ordering System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /admin/update_users.php of the component Update User Page. The manipulation of the argument user_upd…

  • CVE-2024-12981MedDec 27, 2024
    risk 0.41cvss 6.3epss 0.01

    A vulnerability was found in CodeAstro Car Rental System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /bookingconfirm.php. The manipulation of the argument driver_id_from_dropdown leads to sql injection. The attack…

  • CVE-2024-12941MedDec 26, 2024
    risk 0.41cvss 6.3epss 0.00

    A vulnerability was found in CodeAstro Blood Donor Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /pages/deletedannounce.php. The manipulation of the argument id leads to sql injection. The attack may be initiated…

  • CVE-2024-11674MedNov 26, 2024
    risk 0.41cvss 6.3epss 0.01

    A vulnerability, which was classified as critical, was found in CodeAstro Hospital Management System 1.0. Affected is an unknown function of the file /backend/doc/his_doc_update-account.php. The manipulation of the argument doc_dpic leads to unrestricted upload. It is possible…

  • CVE-2024-2351MedMar 9, 2024
    risk 0.41cvss 6.3epss 0.01

    A vulnerability classified as critical was found in CodeAstro Ecommerce Site 1.0. Affected by this vulnerability is an unknown functionality of the file action.php of the component Search. The manipulation of the argument cat_id/brand_id/keyword leads to sql injection. The…

  • CVE-2024-2333MedMar 9, 2024
    risk 0.41cvss 6.3epss 0.01

    A vulnerability classified as critical has been found in CodeAstro Membership Management System 1.0. Affected is an unknown function of the file /add_members.php. The manipulation of the argument fullname leads to sql injection. It is possible to launch the attack remotely. The…

  • CVE-2024-1924MedFeb 27, 2024
    risk 0.41cvss 6.3epss 0.00

    A vulnerability was found in CodeAstro Membership Management System 1.0. It has been classified as critical. This affects an unknown part of the file /get_membership_amount.php. The manipulation of the argument membershipTypeId leads to sql injection. It is possible to initiate…

  • CVE-2024-1268MedFeb 7, 2024
    risk 0.41cvss 6.3epss 0.01

    A vulnerability, which was classified as critical, was found in CodeAstro Restaurant POS System 1.0. This affects an unknown part of the file update_product.php. The manipulation leads to unrestricted upload. It is possible to initiate the attack remotely. The exploit has been…

  • CVE-2024-0543MedJan 15, 2024
    risk 0.41cvss 6.3epss 0.01

    A vulnerability classified as critical has been found in CodeAstro Real Estate Management System up to 1.0. This affects an unknown part of the file propertydetail.php. The manipulation of the argument pid leads to sql injection. It is possible to initiate the attack remotely.…

  • CVE-2024-0194MedJan 2, 2024
    risk 0.41cvss 6.3epss 0.01

    A vulnerability, which was classified as critical, has been found in CodeAstro Internet Banking System up to 1.0. This issue affects some unknown processing of the file pages_account.php of the component Profile Picture Handler. The manipulation leads to unrestricted upload. The…

  • CVE-2023-5796MedOct 26, 2023
    risk 0.41cvss 6.3epss 0.01

    A vulnerability was found in CodeAstro POS System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /setting of the component Logo Handler. The manipulation leads to unrestricted upload. The attack may be launched remotely. The…

  • CVE-2023-5795MedOct 26, 2023
    risk 0.41cvss 6.3epss 0.01

    A vulnerability was found in CodeAstro POS System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /profil of the component Profile Picture Handler. The manipulation leads to unrestricted upload. The attack can be…

  • CVE-2023-5693MedOct 22, 2023
    risk 0.41cvss 6.3epss 0.01

    A vulnerability was found in CodeAstro Internet Banking System 1.0 and classified as critical. This issue affects some unknown processing of the file pages_reset_pwd.php. The manipulation of the argument email leads to sql injection. The attack may be initiated remotely. The…

  • CVE-2025-29015MedApr 17, 2025
    risk 0.40cvss 6.1epss 0.00

    Code Astro Internet Banking System 2.0.0 is vulnerable to Cross Site Scripting (XSS) via the name parameter in /admin/pages_account.php.

  • CVE-2024-46470MedSep 27, 2024
    risk 0.40cvss 6.1epss 0.00

    Cross Site Scripting vulnerability in CodeAstro Membership Management System 1.0 allows attackers to run malicious JavaScript via the membership_type field in the edit-type.php component.

  • CVE-2024-25868MedFeb 28, 2024
    risk 0.40cvss 6.1epss 0.01

    A Cross Site Scripting (XSS) vulnerability in CodeAstro Membership Management System in PHP v.1.0 allows a remote attacker to execute arbitrary code via the membershipType parameter in the add_type.php component.

  • CVE-2026-6201MedApr 13, 2026
    risk 0.35cvss 5.4epss 0.00

    A vulnerability was identified in CodeAstro Online Job Portal 1.0. The impacted element is an unknown function of the file /jobs/job-delete.php of the component Delete Job Posting Handler. Such manipulation of the argument ID leads to improper access controls. The attack can be…

  • CVE-2025-6329MedJun 20, 2025
    risk 0.35cvss 5.4epss 0.00

    A vulnerability was found in ScriptAndTools Real Estate Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file userdelete.php of the component User Delete Handler. The manipulation of the argument ID leads to authorization…

  • CVE-2024-13067MedDec 31, 2024
    risk 0.35cvss 5.3epss 0.01

    A vulnerability was found in CodeAstro Online Food Ordering System 1.0 and classified as critical. This issue affects some unknown processing of the file /admin/all_users.php of the component All Users Page. The manipulation leads to improper access controls. The attack may be…

  • CVE-2024-48709MedOct 21, 2024
    risk 0.35cvss 5.4epss 0.00

    CodeAstro Membership Management System v1.0 is vulnerable to Cross Site Scripting (XSS) via the membershipType parameter in edit_type.php

  • CVE-2024-46236MedOct 21, 2024
    risk 0.35cvss 5.4epss 0.00

    CodeAstro Membership Management System v1.0 is vulnerable to Cross Site Scripting (XSS) via the address parameter in add_members.php and edit_member.php.

  • CVE-2024-45528MedSep 2, 2024
    risk 0.35cvss 5.4epss 0.00

    CodeAstro MembershipM-PHP (aka Membership Management System in PHP) 1.0 allows add_members.php fullname stored XSS.

  • CVE-2024-7912MedAug 18, 2024
    risk 0.35cvss 5.3epss 0.01

    A vulnerability was found in CodeAstro Online Railway Reservation System 1.0. It has been declared as problematic. This vulnerability affects unknown code of the file /admin/assets/. The manipulation leads to exposure of information through directory listing. The attack can be…

  • CVE-2024-2076MedMar 1, 2024
    risk 0.35cvss 5.3epss 0.01

    A vulnerability was found in CodeAstro House Rental Management System 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file booking.php/owner.php/tenant.php. The manipulation leads to missing authentication. The attack may be…

  • CVE-2024-1823MedFeb 23, 2024
    risk 0.35cvss 5.3epss 0.01

    A vulnerability classified as critical was found in CodeAstro Simple Voting System 1.0. Affected by this vulnerability is an unknown functionality of the file users.php of the component Backend. The manipulation leads to improper access controls. The attack can be launched…

  • CVE-2024-1199MedFeb 3, 2024
    risk 0.35cvss 5.4epss 0.01

    A vulnerability has been found in CodeAstro Employee Task Management System 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file \employee-tasks-php\attendance-info.php. The manipulation of the argument aten_id leads to denial…

  • CVE-2026-7071MedApr 27, 2026
    risk 0.34cvss 5.3epss 0.00

    A security vulnerability has been detected in CodeAstro Online Job Portal 1.0. Affected by this vulnerability is an unknown functionality of the file /users/user-cvs/. The manipulation leads to file and directory information exposure. Remote exploitation of the attack is…

  • CVE-2026-3137MedFeb 25, 2026
    risk 0.34cvss 5.3epss 0.00

    A security vulnerability has been detected in CodeAstro Food Ordering System 1.0. This affects an unknown function of the file food_ordering.exe. Such manipulation leads to stack-based buffer overflow. The attack can only be performed from a local environment. The exploit has…

  • CVE-2025-4067MedApr 29, 2025
    risk 0.34cvss 5.3epss 0.01

    A vulnerability classified as critical has been found in ScriptAndTools Online-Travling-System 1.0. Affected is an unknown function of the file /admin/viewpackage.php. The manipulation leads to improper access controls. It is possible to launch the attack remotely. The exploit…

  • CVE-2025-4064MedApr 29, 2025
    risk 0.34cvss 5.3epss 0.01

    A vulnerability was found in ScriptAndTools Online-Travling-System 1.0. It has been classified as critical. This affects an unknown part of the file /admin/viewenquiry.php. The manipulation leads to improper access controls. It is possible to initiate the attack remotely. The…

  • CVE-2025-3975MedApr 27, 2025
    risk 0.34cvss 5.3epss 0.01

    A vulnerability was found in ScriptAndTools eCommerce-website-in-PHP 3.0 and classified as problematic. This issue affects some unknown processing of the file /admin/subscriber-csv.php. The manipulation leads to information disclosure. The attack may be initiated remotely. The…

  • CVE-2025-25776MedApr 28, 2025
    risk 0.33cvss 5.0epss 0.00

    Cross-Site Scripting (XSS) vulnerability exists in the User Registration and User Profile features of Codeastro Bus Ticket Booking System v1.0 allows an attacker to execute arbitrary code into the Full Name and Address fields during user registration or profile editing.

  • CVE-2022-43086MedNov 1, 2022
    risk 0.32cvss 4.9epss 0.01

    Restaurant POS System v1.0 was discovered to contain a SQL injection vulnerability via update_customer.php.

  • CVE-2026-12175MedJun 13, 2026
    risk 0.31cvss 4.7epss 0.00

    A vulnerability was detected in CodeAstro Student Attendance Management System 1.0. Impacted is an unknown function of the file /attendance-php/Admin/createStudents.php. Performing a manipulation of the argument admissionNumber results in sql injection. Remote exploitation of…

  • CVE-2026-7028MedApr 26, 2026
    risk 0.31cvss 4.7epss 0.00

    A security flaw has been discovered in CodeAstro Online Job Portal 1.0. The affected element is an unknown function of the file /admin/jobs-admins/delete-jobs.php of the component All Jobs Page. Performing a manipulation of the argument ID results in sql injection. The attack is…