VYPR

Vendor CVEs

Codeastro

All CVEs

244 total · sorted by risk
  • CVE-2025-25776MedApr 28, 2025
    risk 0.33cvss 5.0epss 0.00

    Cross-Site Scripting (XSS) vulnerability exists in the User Registration and User Profile features of Codeastro Bus Ticket Booking System v1.0 allows an attacker to execute arbitrary code into the Full Name and Address fields during user registration or profile editing.

  • CVE-2022-43086MedNov 1, 2022
    risk 0.32cvss 4.9epss 0.01

    Restaurant POS System v1.0 was discovered to contain a SQL injection vulnerability via update_customer.php.

  • CVE-2026-12175MedJun 13, 2026
    risk 0.31cvss 4.7epss 0.00

    A vulnerability was detected in CodeAstro Student Attendance Management System 1.0. Impacted is an unknown function of the file /attendance-php/Admin/createStudents.php. Performing a manipulation of the argument admissionNumber results in sql injection. Remote exploitation of…

  • CVE-2026-7028MedApr 26, 2026
    risk 0.31cvss 4.7epss 0.00

    A security flaw has been discovered in CodeAstro Online Job Portal 1.0. The affected element is an unknown function of the file /admin/jobs-admins/delete-jobs.php of the component All Jobs Page. Performing a manipulation of the argument ID results in sql injection. The attack is…

  • CVE-2025-14900MedDec 19, 2025
    risk 0.31cvss 4.7epss 0.00

    A security vulnerability has been detected in CodeAstro Real Estate Management System 1.0. Affected is an unknown function of the file /admin/userdelete.php of the component Administrator Endpoint. Such manipulation of the argument ID leads to sql injection. The attack may be…

  • CVE-2025-14899MedDec 19, 2025
    risk 0.31cvss 4.7epss 0.00

    A weakness has been identified in CodeAstro Real Estate Management System 1.0. This impacts an unknown function of the file /admin/stateadd.php of the component Administrator Endpoint. This manipulation causes sql injection. The attack may be initiated remotely. The exploit has…

  • CVE-2025-14898MedDec 19, 2025
    risk 0.31cvss 4.7epss 0.00

    A security flaw has been discovered in CodeAstro Real Estate Management System 1.0. This affects an unknown function of the file /admin/userbuilderdelete.php of the component Administrator Endpoint. The manipulation results in sql injection. The attack can be launched remotely.…

  • CVE-2025-14897MedDec 19, 2025
    risk 0.31cvss 4.7epss 0.00

    A vulnerability was identified in CodeAstro Real Estate Management System 1.0. The impacted element is an unknown function of the file /admin/useragentdelete.php of the component Administrator Endpoint. The manipulation leads to sql injection. The attack can be initiated…

  • CVE-2025-12610MedNov 3, 2025
    risk 0.31cvss 4.7epss 0.00

    A vulnerability was determined in CodeAstro Gym Management System 1.0. This affects an unknown part of the file /admin/view-progress-report.php. Executing a manipulation of the argument ID can lead to sql injection. The attack may be launched remotely. The exploit has been…

  • CVE-2025-12609MedNov 3, 2025
    risk 0.31cvss 4.7epss 0.00

    A vulnerability was found in CodeAstro Gym Management System 1.0. Affected by this issue is some unknown functionality of the file /admin/update-progress.php. Performing a manipulation of the argument id/ini_weight results in sql injection. The attack may be initiated remotely.…

  • CVE-2025-29018MedApr 9, 2025
    risk 0.31cvss 4.8epss 0.00

    A Stored Cross-Site Scripting (XSS) vulnerability exists in the name parameter of pages_add_acc_type.php in Code Astro Internet Banking System 2.0.0.

  • CVE-2024-11058MedNov 10, 2024
    risk 0.31cvss 4.7epss 0.01

    A vulnerability was found in CodeAstro Real Estate Management System up to 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /aboutedit.php of the component About Us Page. The manipulation of the argument id leads to sql injection. The…

  • CVE-2024-11000MedNov 8, 2024
    risk 0.31cvss 4.7epss 0.01

    A vulnerability classified as problematic was found in CodeAstro Real Estate Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /aboutedit.php of the component About Us Page. The manipulation of the argument aimage leads to unrestricted…

  • CVE-2024-10999MedNov 8, 2024
    risk 0.31cvss 4.7epss 0.01

    A vulnerability classified as problematic has been found in CodeAstro Real Estate Management System 1.0. Affected is an unknown function of the file /aboutadd.php of the component About Us Page. The manipulation of the argument aimage leads to unrestricted upload. It is possible…

  • CVE-2024-7910MedAug 18, 2024
    risk 0.31cvss 4.7epss 0.01

    A vulnerability was found in CodeAstro Online Railway Reservation System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /admin/emp-profile-avatar.php of the component Profile Photo Update Handler. The manipulation leads to…

  • CVE-2024-2149MedMar 3, 2024
    risk 0.31cvss 4.7epss 0.01

    A vulnerability classified as critical was found in CodeAstro Membership Management System 1.0. This vulnerability affects unknown code of the file settings.php. The manipulation of the argument currency leads to sql injection. The attack can be initiated remotely. The exploit…

  • CVE-2024-1819MedFeb 23, 2024
    risk 0.31cvss 4.7epss 0.01

    A vulnerability was found in CodeAstro Membership Management System 1.0. It has been classified as critical. This affects an unknown part of the component Add Members Tab. The manipulation of the argument Member Photo leads to unrestricted upload. It is possible to initiate the…

  • CVE-2024-1818MedFeb 23, 2024
    risk 0.31cvss 4.7epss 0.01

    A vulnerability was found in CodeAstro Membership Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /uploads/ of the component Logo Handler. The manipulation leads to unrestricted upload. The attack may be launched…

  • CVE-2025-7133MedJul 7, 2025
    risk 0.28cvss 4.3epss 0.00

    A vulnerability classified as problematic has been found in CodeAstro Online Movie Ticket Booking System 1.0. This affects an unknown part. The manipulation leads to cross-site request forgery. It is possible to initiate the attack remotely. The exploit has been disclosed to the…

  • CVE-2025-6664MedJun 25, 2025
    risk 0.28cvss 4.3epss 0.00

    A vulnerability, which was classified as problematic, was found in CodeAstro Patient Record Management System 1.0. Affected is an unknown function. The manipulation leads to cross-site request forgery. It is possible to launch the attack remotely. The exploit has been disclosed…

  • CVE-2025-6478MedJun 22, 2025
    risk 0.28cvss 4.3epss 0.00

    A vulnerability was found in CodeAstro Expense Management System 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality. The manipulation leads to cross-site request forgery. The attack may be launched remotely.

  • CVE-2025-3557MedApr 14, 2025
    risk 0.28cvss 4.3epss 0.00

    A vulnerability, which was classified as problematic, has been found in ScriptAndTools eCommerce-website-in-PHP 3.0. Affected by this issue is some unknown functionality. The manipulation leads to cross-site request forgery. The attack may be launched remotely. The exploit has…

  • CVE-2024-1825MedFeb 23, 2024
    risk 0.28cvss 4.3epss 0.00

    A vulnerability, which was classified as problematic, was found in CodeAstro House Rental Management System 1.0. This affects an unknown part of the component User Registration Page. The manipulation of the argument address with the input …

  • CVE-2024-0345MedJan 9, 2024
    risk 0.28cvss 4.3epss 0.01

    A vulnerability, which was classified as problematic, was found in CodeAstro Vehicle Booking System 1.0. This affects an unknown part of the file usr/usr-register.php of the component User Registration. The manipulation of the argument Full_Name/Last_Name/Address with the input…

  • CVE-2024-0343MedJan 9, 2024
    risk 0.28cvss 4.3epss 0.01

    A vulnerability classified as problematic was found in CodeAstro Simple House Rental System 5.6. Affected by this vulnerability is an unknown functionality of the component Login Panel. The manipulation leads to cross site scripting. The attack can be launched remotely. The…

  • CVE-2023-6774MedDec 13, 2023
    risk 0.28cvss 4.3epss 0.01

    A vulnerability was found in CodeAstro POS and Inventory Management System 1.0 and classified as problematic. Affected by this issue is some unknown functionality of the file /accounts_con/register_account. The manipulation of the argument Username with the input…

  • CVE-2023-6773MedDec 13, 2023
    risk 0.28cvss 4.3epss 0.01

    A vulnerability has been found in CodeAstro POS and Inventory Management System 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /accounts_con/register_account of the component User Creation Handler. The manipulation of…

  • CVE-2025-3556LowApr 14, 2025
    risk 0.24cvss 3.7epss 0.01

    A vulnerability classified as problematic was found in ScriptAndTools eCommerce-website-in-PHP 3.0. Affected by this vulnerability is an unknown functionality of the file /admin/login.php. The manipulation leads to improper restriction of excessive authentication attempts. The…

  • CVE-2025-3555LowApr 14, 2025
    risk 0.24cvss 3.7epss 0.01

    A vulnerability classified as problematic has been found in ScriptAndTools eCommerce-website-in-PHP 3.0. Affected is an unknown function of the file /login.php. The manipulation leads to improper restriction of excessive authentication attempts. It is possible to launch the…

  • CVE-2026-12130LowJun 12, 2026
    risk 0.23cvss 3.5epss 0.00

    A security flaw has been discovered in CodeAstro Human Resource Management System 1.0. This affects an unknown part of the file /Projects/Add_Projects of the component Projects Management Page. The manipulation of the argument protitle results in cross site scripting. The attack…

  • CVE-2026-12129LowJun 12, 2026
    risk 0.23cvss 3.5epss 0.00

    A vulnerability was identified in CodeAstro Human Resource Management System 1.0. Affected by this issue is some unknown functionality of the file /dashboard/add_tod of the component Dashboard Interface. The manipulation of the argument todo_data leads to cross site scripting.…

  • CVE-2025-9940LowSep 4, 2025
    risk 0.23cvss 3.5epss 0.00

    A vulnerability was detected in CodeAstro Real Estate Management System 1.0. This affects an unknown function of the file /feature.php. Performing manipulation of the argument msg results in cross site scripting. The attack can be initiated remotely. The exploit is now public…

  • CVE-2025-9939LowSep 4, 2025
    risk 0.23cvss 3.5epss 0.00

    A security vulnerability has been detected in CodeAstro Real Estate Management System 1.0. The impacted element is an unknown function of the file /propertyview.php. Such manipulation of the argument msg leads to cross site scripting. It is possible to launch the attack…

  • CVE-2025-9237LowAug 20, 2025
    risk 0.23cvss 3.5epss 0.00

    A vulnerability was found in CodeAstro Ecommerce Website 1.0. This impacts an unknown function of the file /customer/my_account.php?edit_account of the component Edit Your Account Page. Performing manipulation of the argument Username results in cross site scripting. It is…

  • CVE-2025-7153LowJul 8, 2025
    risk 0.23cvss 3.5epss 0.00

    A vulnerability classified as problematic was found in CodeAstro Simple Hospital Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /doctor.html of the component POST Parameter Handler. The manipulation of the argument First Name/Last…

  • CVE-2025-7148LowJul 7, 2025
    risk 0.23cvss 3.5epss 0.00

    A vulnerability was found in CodeAstro Simple Hospital Management System 1.0 and classified as problematic. Affected by this issue is some unknown functionality of the file /patient.html of the component POST Parameter Handler. The manipulation leads to cross site scripting. The…

  • CVE-2024-11678LowNov 26, 2024
    risk 0.23cvss 3.5epss 0.00

    A vulnerability was found in CodeAstro Hospital Management System 1.0. It has been declared as problematic. This vulnerability affects unknown code of the file /backend/doc/his_doc_register_patient.php. The manipulation of the argument pat_fname/pat_ailment/pat_lname/pat_age/pat_…

  • CVE-2024-11677LowNov 26, 2024
    risk 0.23cvss 3.5epss 0.00

    A vulnerability was found in CodeAstro Hospital Management System 1.0. It has been classified as problematic. This affects an unknown part of the file /backend/admin/his_admin_add_vendor.php of the component Add Vendor Details Page. The manipulation of the argument…

  • CVE-2024-11676LowNov 26, 2024
    risk 0.23cvss 3.5epss 0.00

    A vulnerability was found in CodeAstro Hospital Management System 1.0 and classified as problematic. Affected by this issue is some unknown functionality of the file /backend/admin/his_admin_add_lab_equipment.php of the component Add Laboratory Equipment Page. The manipulation…

  • CVE-2024-11675LowNov 26, 2024
    risk 0.23cvss 3.5epss 0.00

    A vulnerability has been found in CodeAstro Hospital Management System 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /backend/admin/his_admin_register_patient.php of the component Add Patient Details Page. The…

  • CVE-2024-1267LowFeb 7, 2024
    risk 0.23cvss 3.5epss 0.00

    A vulnerability, which was classified as problematic, has been found in CodeAstro Restaurant POS System 1.0. Affected by this issue is some unknown functionality of the file create_account.php. The manipulation of the argument Full Name leads to cross site scripting. The attack…

  • CVE-2024-1103LowJan 31, 2024
    risk 0.23cvss 3.5epss 0.01

    A vulnerability was found in CodeAstro Real Estate Management System 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file profile.php of the component Feedback Form. The manipulation of the argument Your Feedback with the input…

  • CVE-2024-1031LowJan 30, 2024
    risk 0.23cvss 3.5epss 0.00

    A vulnerability was found in CodeAstro Expense Management System 1.0. It has been declared as problematic. This vulnerability affects unknown code of the file templates/5-Add-Expenses.php of the component Add Expenses Page. The manipulation of the argument item leads to cross…

  • CVE-2024-0958LowJan 27, 2024
    risk 0.23cvss 3.5epss 0.01

    A vulnerability was found in CodeAstro Stock Management System 1.0 and classified as problematic. This issue affects some unknown processing of the file /index.php of the component Add Category Handler. The manipulation of the argument Category Name/Category Description leads to…

  • CVE-2024-0782LowJan 22, 2024
    risk 0.23cvss 3.5epss 0.01

    A vulnerability has been found in CodeAstro Online Railway Reservation System 1.0 and classified as problematic. This vulnerability affects unknown code of the file pass-profile.php. The manipulation of the argument First Name/Last Name/User Name leads to cross site scripting.…

  • CVE-2024-0781LowJan 22, 2024
    risk 0.23cvss 3.5epss 0.01

    A vulnerability, which was classified as problematic, was found in CodeAstro Internet Banking System 1.0. This affects an unknown part of the file pages_client_signup.php. The manipulation of the argument Client Full Name with the input <meta http-equiv="refresh" content="0;…

  • CVE-2024-0773LowJan 22, 2024
    risk 0.23cvss 3.5epss 0.01

    A vulnerability classified as problematic was found in CodeAstro Internet Banking System 1.0. Affected by this vulnerability is an unknown functionality of the file pages_client_signup.php. The manipulation of the argument Client Full Name leads to cross site scripting. The…

  • CVE-2024-0424LowJan 11, 2024
    risk 0.23cvss 3.5epss 0.01

    A vulnerability classified as problematic has been found in CodeAstro Simple Banking System 1.0. This affects an unknown part of the file createuser.php of the component Create a User Page. The manipulation leads to cross site scripting. It is possible to initiate the attack…

  • CVE-2024-0423LowJan 11, 2024
    risk 0.23cvss 3.5epss 0.01

    A vulnerability was found in CodeAstro Online Food Ordering System 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file dishes.php. The manipulation of the argument res_id leads to cross site scripting. The attack may be…

  • CVE-2024-0422LowJan 11, 2024
    risk 0.23cvss 3.5epss 0.01

    A vulnerability was found in CodeAstro POS and Inventory Management System 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /new_item of the component New Item Creation Page. The manipulation of the argument…

Page 4 of 5