CVE-2025-69938
- EPSS 0.14%
- Veröffentlicht 30.07.2026 00:00:00
- Zuletzt bearbeitet 31.07.2026 15:16:27
CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in renew.php via the parameter membershipType.
CVE-2025-69937
- EPSS 0.14%
- Veröffentlicht 30.07.2026 00:00:00
- Zuletzt bearbeitet 31.07.2026 16:16:56
CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in the edit_type.php endpoint via the Parameter id.
CVE-2025-69936
- EPSS 0.14%
- Veröffentlicht 30.07.2026 00:00:00
- Zuletzt bearbeitet 31.07.2026 19:17:03
CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /edit_member.php?id=1.
CVE-2025-69935
- EPSS 0.14%
- Veröffentlicht 30.07.2026 00:00:00
- Zuletzt bearbeitet 31.07.2026 19:17:03
CodeAstro Membership Management System 1.0 is vulnerale to SQL Injection in the report.php and revenue_report.php via the fromDate parameter.
CVE-2025-69934
- EPSS 0.14%
- Veröffentlicht 30.07.2026 00:00:00
- Zuletzt bearbeitet 31.07.2026 19:17:03
CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /delete_members.php?id=1.
CVE-2025-69933
- EPSS 0.14%
- Veröffentlicht 30.07.2026 00:00:00
- Zuletzt bearbeitet 31.07.2026 19:17:02
CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /memberProfile.php?id=1.
CVE-2025-69931
- EPSS 0.26%
- Veröffentlicht 30.07.2026 00:00:00
- Zuletzt bearbeitet 03.08.2026 17:16:28
CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /delete_membership.php?id=1.
CVE-2025-69930
- EPSS 0.14%
- Veröffentlicht 30.07.2026 00:00:00
- Zuletzt bearbeitet 31.07.2026 19:17:02
CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /print_membership_card.php?id=1.
CVE-2026-36387
- EPSS 0.26%
- Veröffentlicht 07.05.2026 00:00:00
- Zuletzt bearbeitet 05.07.2026 02:17:48
A Remote Code Execution vulnerability was found in CODEASTRO Membership Management System v1.0 in /add_members.php. This vulnerability affects the file upload functionality, where improper file sanitization allows attackers to inject malicious files ...
CVE-2025-70150
- EPSS 0.57%
- Veröffentlicht 18.02.2026 00:00:00
- Zuletzt bearbeitet 23.02.2026 16:13:10
CodeAstro Membership Management System 1.0 contains a missing authentication vulnerability in delete_members.php that allows unauthenticated attackers to delete arbitrary member records via the id parameter.