CVE-2026-36387
- EPSS 0.27%
- Veröffentlicht 07.05.2026 00:00:00
- Zuletzt bearbeitet 07.05.2026 18:45:48
A Remote Code Execution vulnerability was found in CODEASTRO Membership Management System v1.0 in /add_members.php. This vulnerability affects the file upload functionality, where improper file sanitization allows attackers to inject malicious files ...
CVE-2025-70150
- EPSS 0.57%
- Veröffentlicht 18.02.2026 00:00:00
- Zuletzt bearbeitet 23.02.2026 16:13:10
CodeAstro Membership Management System 1.0 contains a missing authentication vulnerability in delete_members.php that allows unauthenticated attackers to delete arbitrary member records via the id parameter.
CVE-2025-70148
- EPSS 0.39%
- Veröffentlicht 18.02.2026 00:00:00
- Zuletzt bearbeitet 20.02.2026 13:55:58
Missing authentication and authorization in print_membership_card.php in CodeAstro Membership Management System 1.0 allows unauthenticated attackers to access membership card data of arbitrary users via direct requests with a manipulated id parameter...
CVE-2025-70149
- EPSS 0.35%
- Veröffentlicht 18.02.2026 00:00:00
- Zuletzt bearbeitet 23.02.2026 16:13:40
CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in print_membership_card.php via the ID parameter.
CVE-2025-3998
- EPSS 0.42%
- Veröffentlicht 28.04.2025 03:00:05
- Zuletzt bearbeitet 14.05.2025 19:49:55
A vulnerability classified as critical was found in CodeAstro Membership Management System 1.0. This vulnerability affects unknown code of the file renew.php?id=6. The manipulation of the argument ID leads to sql injection. The attack can be initiate...
CVE-2024-48709
- EPSS 0.3%
- Veröffentlicht 21.10.2024 19:15:03
- Zuletzt bearbeitet 31.03.2025 17:58:22
CodeAstro Membership Management System v1.0 is vulnerable to Cross Site Scripting (XSS) via the membershipType parameter in edit_type.php
CVE-2024-46236
- EPSS 0.27%
- Veröffentlicht 21.10.2024 19:15:03
- Zuletzt bearbeitet 31.03.2025 17:49:13
CodeAstro Membership Management System v1.0 is vulnerable to Cross Site Scripting (XSS) via the address parameter in add_members.php and edit_member.php.
CVE-2024-46470
- EPSS 0.32%
- Veröffentlicht 27.09.2024 15:15:15
- Zuletzt bearbeitet 31.03.2025 19:19:17
Cross Site Scripting vulnerability in CodeAstro Membership Management System 1.0 allows attackers to run malicious JavaScript via the membership_type field in the edit-type.php component.
CVE-2024-46472
- EPSS 0.43%
- Veröffentlicht 27.09.2024 15:15:15
- Zuletzt bearbeitet 31.03.2025 19:02:48
CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection via the parameter 'email' in the Login Page.
CVE-2024-46471
- EPSS 0.5%
- Veröffentlicht 27.09.2024 15:15:15
- Zuletzt bearbeitet 31.03.2025 19:07:09
The Directory Listing in /uploads/ Folder in CodeAstro Membership Management System 1.0 exposes the structure and contents of directories, potentially revealing sensitive information.