CVE-2025-69938
- EPSS 0.14%
- Veröffentlicht 30.07.2026 00:00:00
- Zuletzt bearbeitet 01.10.2026 08:10:00
CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in renew.php via the parameter membershipType.
CVE-2025-69937
- EPSS 0.14%
- Veröffentlicht 30.07.2026 00:00:00
- Zuletzt bearbeitet 01.10.2026 08:10:00
CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in the edit_type.php endpoint via the Parameter id.
CVE-2025-69936
- EPSS 0.14%
- Veröffentlicht 30.07.2026 00:00:00
- Zuletzt bearbeitet 01.10.2026 23:10:00
CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /edit_member.php?id=1.
CVE-2025-69935
- EPSS 0.14%
- Veröffentlicht 30.07.2026 00:00:00
- Zuletzt bearbeitet 01.10.2026 08:10:00
CodeAstro Membership Management System 1.0 is vulnerale to SQL Injection in the report.php and revenue_report.php via the fromDate parameter.
CVE-2025-69934
- EPSS 0.14%
- Veröffentlicht 30.07.2026 00:00:00
- Zuletzt bearbeitet 01.10.2026 23:10:00
CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /delete_members.php?id=1.
CVE-2025-69933
- EPSS 0.14%
- Veröffentlicht 30.07.2026 00:00:00
- Zuletzt bearbeitet 05.10.2026 18:10:00
CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /memberProfile.php?id=1.
CVE-2025-69931
- EPSS 0.26%
- Veröffentlicht 30.07.2026 00:00:00
- Zuletzt bearbeitet 05.10.2026 18:10:00
CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /delete_membership.php?id=1.
CVE-2025-69930
- EPSS 0.14%
- Veröffentlicht 30.07.2026 00:00:00
- Zuletzt bearbeitet 05.10.2026 18:10:00
CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /print_membership_card.php?id=1.
CVE-2026-36387
- EPSS 0.26%
- Veröffentlicht 07.05.2026 00:00:00
- Zuletzt bearbeitet 05.07.2026 02:17:48
A Remote Code Execution vulnerability was found in CODEASTRO Membership Management System v1.0 in /add_members.php. This vulnerability affects the file upload functionality, where improper file sanitization allows attackers to inject malicious files ...
CVE-2025-70150
- EPSS 0.57%
- Veröffentlicht 18.02.2026 00:00:00
- Zuletzt bearbeitet 08.09.2026 20:17:28
CodeAstro Membership Management System 1.0 contains a missing authentication vulnerability in delete_members.php that allows unauthenticated attackers to delete arbitrary member records via the id parameter.