VendorsCodeAstromembership_management_system1.0
Vulnerabilities

CodeAstro Membership Management System 1.0

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

19CVEs
CVE-2025-70150
CodeAstro Membership Management System 1.0 contains a missing authentication vulnerability in delete_members.php that allows unauthenticated attackers to delete arbitrary member records via the id parameter.
Published 2026-02-18 · Modified
9.8EPSS 0.007
CVE-2025-3998
CodeAstro Membership Management System renew.php sql injection
Published 2025-04-28 · Analyzed
9.8EPSS 0.005
CVE-2025-70149
CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in print_membership_card.php via the ID parameter.
Published 2026-02-18 · Modified
9.8EPSS 0.004
CVE-2024-25867
A SQL Injection vulnerability in CodeAstro Membership Management System in PHP v.1.0 allows a remote attacker to execute arbitrary SQL commands via the membershipType and membershipAmount parameters in the add_type.php component.
Published 2024-02-28 · Analyzed
9.1EPSS 0.007
CVE-2024-25869
An Unrestricted File Upload vulnerability in CodeAstro Membership Management System in PHP v.1.0 allows a remote attacker to execute arbitrary code via upload of a crafted php file in the settings.php component.
Published 2024-02-28 · Analyzed
8.8EPSS 0.187
CVE-2024-25866
A SQL Injection vulnerability in CodeAstro Membership Management System in PHP v.1.0 allows a remote attacker to execute arbitrary SQL commands via the email parameter in the index.php component.
Published 2024-02-28 · Analyzed
8.8EPSS 0.008
CVE-2024-46472
CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection via the parameter 'email' in the Login Page.
Published 2024-09-27 · Analyzed
8.6EPSS 0.004
CVE-2024-46471
The Directory Listing in /uploads/ Folder in CodeAstro Membership Management System 1.0 exposes the structure and contents of directories, potentially revealing sensitive information.
Published 2024-09-27 · Analyzed
7.5EPSS 0.005
CVE-2025-70148
Missing authentication and authorization in print_membership_card.php in CodeAstro Membership Management System 1.0 allows unauthenticated attackers to access membership card data of arbitrary users via direct requests with a manipulated id parameter, resulting in insecure direct object reference (IDOR).
Published 2026-02-18 · Modified
7.5EPSS 0.004
CVE-2024-2333
CodeAstro Membership Management System add_members.php sql injection
Published 2024-03-09 · Analyzed
7.2EPSS 0.007
CVE-2024-1819
CodeAstro Membership Management System Add Members Tab unrestricted upload
Published 2024-02-23 · Analyzed
7.2EPSS 0.007
CVE-2024-1818
CodeAstro Membership Management System Logo unrestricted upload
Published 2024-02-23 · Analyzed
7.2EPSS 0.007
CVE-2024-2149
CodeAstro Membership Management System settings.php sql injection
Published 2024-03-03 · Analyzed
7.2EPSS 0.006
CVE-2024-1924
CodeAstro Membership Management System get_membership_amount.php sql injection
Published 2024-02-27 · Analyzed
6.5EPSS 0.005
CVE-2024-25868
A Cross Site Scripting (XSS) vulnerability in CodeAstro Membership Management System in PHP v.1.0 allows a remote attacker to execute arbitrary code via the membershipType parameter in the add_type.php component.
Published 2024-02-28 · Analyzed
6.1EPSS 0.006
CVE-2024-46470
Cross Site Scripting vulnerability in CodeAstro Membership Management System 1.0 allows attackers to run malicious JavaScript via the membership_type field in the edit-type.php component.
Published 2024-09-27 · Analyzed
6.1EPSS 0.004
CVE-2024-48709
CodeAstro Membership Management System v1.0 is vulnerable to Cross Site Scripting (XSS) via the membershipType parameter in edit_type.php
Published 2024-10-21 · Analyzed
5.4EPSS 0.003
CVE-2024-45528
CodeAstro MembershipM-PHP (aka Membership Management System in PHP) 1.0 allows add_members.php fullname stored XSS.
Published 2024-09-02 · Analyzed
5.4EPSS 0.003
CVE-2024-46236
CodeAstro Membership Management System v1.0 is vulnerable to Cross Site Scripting (XSS) via the address parameter in add_members.php and edit_member.php.
Published 2024-10-21 · Analyzed
5.4EPSS 0.003