VYPR

Vendor CVEs

Codeastro

All CVEs

240 total · sorted by risk
  • CVE-2023-5697LowOct 23, 2023
    risk 0.23cvss 3.5epss 0.01

    A vulnerability classified as problematic has been found in CodeAstro Internet Banking System 1.0. This affects an unknown part of the file pages_withdraw_money.php. The manipulation of the argument account_number with the input 287359614--><!--…

  • CVE-2023-5696LowOct 22, 2023
    risk 0.23cvss 3.5epss 0.00

    A vulnerability was found in CodeAstro Internet Banking System 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file pages_transfer_money.php. The manipulation of the argument account_number with the input…

  • CVE-2023-5695LowOct 22, 2023
    risk 0.23cvss 3.5epss 0.01

    A vulnerability was found in CodeAstro Internet Banking System 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file pages_reset_pwd.php. The manipulation of the argument email with the input…

  • CVE-2023-5694LowOct 22, 2023
    risk 0.23cvss 3.5epss 0.01

    A vulnerability was found in CodeAstro Internet Banking System 1.0. It has been classified as problematic. Affected is an unknown function of the file pages_system_settings.php. The manipulation of the argument sys_name with the input leads to cross…

  • CVE-2024-7815LowAug 15, 2024
    risk 0.19cvss 2.4epss 0.01

    A vulnerability has been found in CodeAstro Online Railway Reservation System 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /admin/admin-update-employee.php of the component Update Employee Page. The manipulation of the…

  • CVE-2026-11491LowJun 8, 2026
    risk 0.16cvss 2.4epss 0.00

    A vulnerability was identified in CodeAstro Human Resource Management System 1.0. Impacted is an unknown function of the file /notice/All_notice of the component Notice Board Management. Such manipulation of the argument Notice Title with the input <svg onload="alert('Stored XSS…

  • CVE-2025-6452LowJun 22, 2025
    risk 0.16cvss 2.4epss 0.00

    A vulnerability was found in CodeAstro Patient Record Management System 1.0. It has been rated as problematic. This issue affects some unknown processing of the component Generate New Report Page. The manipulation of the argument Patient Name/Name leads to cross site scripting.…

  • CVE-2025-6131LowJun 16, 2025
    risk 0.16cvss 2.4epss 0.00

    A vulnerability, which was classified as problematic, was found in CodeAstro Food Ordering System 1.0. Affected is an unknown function of the file /admin/store/edit/ of the component POST Request Parameter Handler. The manipulation of the argument Restaurant Name/Address leads…

  • CVE-2024-7814LowAug 15, 2024
    risk 0.16cvss 2.4epss 0.00

    A vulnerability, which was classified as problematic, was found in CodeAstro Online Railway Reservation System 1.0. Affected is an unknown function of the file /admin/admin-add-employee.php of the component Add Employee Page. The manipulation of the argument emp_fname /emp_lname…

  • CVE-2024-1266LowFeb 7, 2024
    risk 0.16cvss 2.4epss 0.01

    A vulnerability classified as problematic was found in CodeAstro University Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /st_reg.php of the component Student Registration Form. The manipulation of the argument Address leads to…

  • CVE-2024-1265LowFeb 7, 2024
    risk 0.16cvss 2.4epss 0.00

    A vulnerability classified as problematic has been found in CodeAstro University Management System 1.0. Affected is an unknown function of the file /att_add.php of the component Attendance Management. The manipulation of the argument Student Name leads to cross site scripting.…

  • CVE-2024-1022LowJan 29, 2024
    risk 0.16cvss 2.4epss 0.01

    A vulnerability, which was classified as problematic, was found in CodeAstro Simple Student Result Management System 5.6. This affects an unknown part of the file /add_classes.php of the component Add Class Page. The manipulation of the argument Class Name leads to cross site…

  • CVE-2025-69938CriJul 30, 2026
    risk 0.00cvss 9.8epss 0.00

    CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in renew.php via the parameter membershipType.

  • CVE-2025-69937CriJul 30, 2026
    risk 0.00cvss 9.8epss 0.00

    CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in the edit_type.php endpoint via the Parameter id.

  • CVE-2025-69936CriJul 30, 2026
    risk 0.00cvss 9.8epss 0.00

    CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /edit_member.php?id=1.

  • CVE-2025-69935CriJul 30, 2026
    risk 0.00cvss 9.8epss 0.00

    CodeAstro Membership Management System 1.0 is vulnerale to SQL Injection in the report.php and revenue_report.php via the fromDate parameter.

  • CVE-2025-69934CriJul 30, 2026
    risk 0.00cvss 9.8epss 0.00

    CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /delete_members.php?id=1.

  • CVE-2025-69933CriJul 30, 2026
    risk 0.00cvss 9.8epss 0.00

    CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /memberProfile.php?id=1.

  • CVE-2025-69931CriJul 30, 2026
    risk 0.00cvss 9.8epss 0.00

    CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /delete_membership.php?id=1.

  • CVE-2025-69930CriJul 30, 2026
    risk 0.00cvss 9.8epss 0.00

    CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /print_membership_card.php?id=1.

  • CVE-2026-16765HigJul 23, 2026
    risk 0.00cvss 7.3epss 0.00

    A vulnerability was determined in CodeAstro Online Classroom 1.0. Affected by this issue is some unknown functionality of the file /OnlineClassroom/loginlinkadmin.php. Executing a manipulation of the argument aid can lead to sql injection. The attack can be executed remotely.…

  • CVE-2026-15559MedJul 13, 2026
    risk 0.00cvss 6.3epss 0.00

    A vulnerability was detected in CodeAstro Simple Online Leave Management System 1.0. This affects an unknown part of the file /SimpleOnlineLeave/admin/accept.php of the component POST Handler. Performing a manipulation of the argument appid results in sql injection. The attack…

  • CVE-2026-15558MedJul 13, 2026
    risk 0.00cvss 6.3epss 0.00

    A security vulnerability has been detected in CodeAstro Simple Online Leave Management System 1.0. Affected by this issue is some unknown functionality of the file /SimpleOnlineLeave/admin/deletemp.php. Such manipulation of the argument ID leads to sql injection. The attack can…

  • CVE-2026-15523MedJul 13, 2026
    risk 0.00cvss 6.3epss 0.00

    A weakness has been identified in CodeAstro Simple Online Leave Management System 1.0. Affected by this issue is some unknown functionality of the file /SimpleOnlineLeave/admin/dashboard.php. This manipulation of the argument Name causes sql injection. The attack can be…

  • CVE-2026-15134HigJul 9, 2026
    risk 0.00cvss 7.3epss 0.00

    A vulnerability was determined in CodeAstro Simple Online Leave Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /SimpleOnlineLeave/index.php. Executing a manipulation of the argument email can lead to sql injection. The attack may be…

  • CVE-2026-14799MedJul 6, 2026
    risk 0.00cvss 6.3epss 0.00

    A security flaw has been discovered in CodeAstro Ecommerce Website 1.0. Impacted is an unknown function of the file /customer/my_account.php?my_wishlist. The manipulation of the argument delete_wishlist results in sql injection. The attack can be launched remotely. The exploit…

  • CVE-2026-14798MedJul 6, 2026
    risk 0.00cvss 6.3epss 0.00

    A vulnerability was identified in CodeAstro Apartment Visitor Management System 1.0. This issue affects some unknown processing of the file /apartment-visitor/visitor-entry.php. The manipulation of the argument visname leads to sql injection. The attack can be initiated…

  • CVE-2026-14797MedJul 6, 2026
    risk 0.00cvss 6.3epss 0.00

    A vulnerability was determined in CodeAstro Apartment Visitor Management System 1.0. This vulnerability affects unknown code of the file /apartment-visitor/edit-apartment.php. Executing a manipulation of the argument editid can lead to sql injection. It is possible to launch the…

  • CVE-2026-14796MedJul 6, 2026
    risk 0.00cvss 6.3epss 0.00

    A vulnerability was found in CodeAstro Apartment Visitor Management System 1.0. This affects an unknown part of the file /apartment-visitor/report.php. Performing a manipulation of the argument fromdate results in sql injection. It is possible to initiate the attack remotely.…

  • CVE-2026-14795MedJul 6, 2026
    risk 0.00cvss 6.3epss 0.00

    A vulnerability has been found in CodeAstro Apartment Visitor Management System 1.0. Affected by this issue is some unknown functionality of the file /apartment-visitor/action-visitor.php. Such manipulation of the argument remark leads to sql injection. The attack may be…

  • CVE-2026-14767MedJul 5, 2026
    risk 0.00cvss 6.3epss 0.00

    A security flaw has been discovered in CodeAstro Ecommerce Website 1.0. This affects an unknown part of the file /ecommerce-website-php/customer/confirm.php of the component POST Parameter Handler. The manipulation of the argument invoice_no results in sql injection. The attack…

  • CVE-2026-14766MedJul 5, 2026
    risk 0.00cvss 6.3epss 0.00

    A vulnerability was identified in CodeAstro Apartment Visitor Management System 1.0. Affected by this issue is some unknown functionality of the file /apartment-visitor/search-result.php of the component POST Parameter Handler. The manipulation of the argument searchdata leads…

  • CVE-2026-14689MedJul 5, 2026
    risk 0.00cvss 6.3epss 0.00

    A security flaw has been discovered in CodeAstro Apartment Visitor Management System 1.0. The impacted element is an unknown function of the file /apartment-visitor/add-apartment.php. The manipulation of the argument apartmentno results in sql injection. The attack may be…

  • CVE-2026-14640HigJul 4, 2026
    risk 0.00cvss 7.3epss 0.00

    A vulnerability was found in CodeAstro Apartment Visitor Management System 1.0. Affected is an unknown function of the file /index.php of the component Login. Performing a manipulation of the argument Username results in sql injection. Remote exploitation of the attack is…

  • CVE-2026-14639MedJul 4, 2026
    risk 0.00cvss 6.3epss 0.00

    A vulnerability has been found in CodeAstro Ecommerce Website 1.0. This impacts an unknown function of the file /ecommerce-website-php/customer/my_account.php?edit_account. Such manipulation of the argument c_name leads to sql injection. The attack may be launched remotely. The…

  • CVE-2026-13558LowJun 29, 2026
    risk 0.00cvss 3.5epss 0.00

    A security flaw has been discovered in CodeAstro Complaint Management System 1.0. This issue affects some unknown processing of the file /report/addreport of the component Report Handler. Performing a manipulation of the argument Report Title results in cross site scripting.…

  • CVE-2026-13549MedJun 29, 2026
    risk 0.00cvss 5.4epss 0.00

    A security flaw has been discovered in CodeAstro Complaint Management System 1.0. The affected element is the function deletereport of the file application/controllers/Report.php of the component Report Endpoint. The manipulation results in authorization bypass. The attack can…

  • CVE-2026-13537MedJun 29, 2026
    risk 0.00cvss 4.3epss 0.00

    A vulnerability was found in CodeAstro Human Resource Management System 1.0. Impacted is an unknown function. The manipulation results in cross-site request forgery. The attack may be launched remotely. The exploit has been made public and could be used.

  • CVE-2026-13535MedJun 29, 2026
    risk 0.00cvss 6.3epss 0.00

    A flaw has been found in CodeAstro Human Resource Management System 1.0. This vulnerability affects the function GetFileInfo of the file hrsystem/application/models/Employee_model.php of the component View Endpoint. Executing a manipulation of the argument ID can lead to sql…

  • CVE-2026-13525MedJun 29, 2026
    risk 0.00cvss 6.3epss 0.00

    A vulnerability was detected in CodeAstro Human Resource Management System 1.0. This issue affects the function emselectByCode of the file application/models/Employee_model.php of the component Update_Earn_Leave Endpoint. The manipulation of the argument emid results in sql…

Page 5 of 5