CodeAstro records
109 published records for vendor codeastro.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 3
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')44
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')25
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')13
- CWE-284 Improper Access Control7
- CWE-434 Unrestricted Upload of File with Dangerous Type6
- CWE-352 Cross-Site Request Forgery (CSRF)4
The weakness classes this vendor ships most often: where to look.
CWEAll records
109 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
41Plan | CVE-2024-25869No exploit | An Unrestricted File Upload vulnerability in CodeAstro Membership Management System in PHP v.1.0 allows a remote attacker to execute arbitracodeastro · membership management system · CWE-434 | High8.8 | — | 18.7% | Feb 28, 2024 |
39Monitor | CVE-2024-55509No exploit | SQL injection vulnerability in CodeAstro Complaint Management System v.1.0 allows a remote attacker to execute arbitrary code and escalate pcodeastro · complaint management system · CWE-89 | Critical9.8 | — | 0.8% | Dec 20, 2024 |
39Monitor | CVE-2024-0194No exploit | CodeAstro Internet Banking System Profile Picture pages_account.php unrestricted uploadcodeastro · internet banking system · CWE-434 | Critical9.8 | — | 0.7% | Jan 2, 2024 |
39Monitor | CVE-2024-2351No exploit | CodeAstro Ecommerce Site Search action.php sql injectioncodeastro · ecommerce website · CWE-89 | Critical9.8 | — | 0.7% | Mar 9, 2024 |
39Monitor | CVE-2025-70150No exploit | CodeAstro Membership Management System 1.0 contains a missing authentication vulnerability in delete_members.php that allows unauthenticatedcodeastro · membership management system · CWE-862 | Critical9.8 | — | 0.7% | Feb 18, 2026 |
39Monitor | CVE-2024-55507No exploit | An issue in CodeAstro Complaint Management System v.1.0 allows a remote attacker to escalate privileges via the delete_e.php component.codeastro · complaint management system · CWE-281 | Critical9.8 | — | 0.6% | Jan 3, 2025 |
39Monitor | CVE-2024-1824No exploit | CodeAstro House Rental Management System signing.php sql injectioncodeastro · house rental management system · CWE-89 | Critical9.8 | — | 0.6% | Feb 23, 2024 |
39Monitor | CVE-2025-25775No exploit | Codeastro Bus Ticket Booking System v1.0 is vulnerable to SQL injection via the kodetiket parameter in /BusTicket-CI/tiket/cekorder.codeastro · bus ticket booking system · CWE-89 | Critical9.8 | — | 0.5% | Apr 25, 2025 |
39Monitor | CVE-2025-70149Proof of concept | CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in print_membership_card.php via the ID parameter.codeastro · membership management system · CWE-89 | Critical9.8 | — | 0.4% | Feb 18, 2026 |
36Monitor | CVE-2024-25867No exploit | A SQL Injection vulnerability in CodeAstro Membership Management System in PHP v.1.0 allows a remote attacker to execute arbitrary SQL commacodeastro · membership management system · CWE-89 | Critical9.1 | — | 0.7% | Feb 28, 2024 |
35Monitor | CVE-2025-29017Proof of concept | A Remote Code Execution (RCE) vulnerability exists in Code Astro Internet Banking System 2.0.0 due to improper file upload validation in thecodeastro · internet banking system · CWE-434 | High8.8 | — | 0.9% | Apr 10, 2025 |
35Monitor | CVE-2024-25866No exploit | A SQL Injection vulnerability in CodeAstro Membership Management System in PHP v.1.0 allows a remote attacker to execute arbitrary SQL commacodeastro · membership management system · CWE-89 | High8.8 | — | 0.8% | Feb 28, 2024 |
35Monitor | CVE-2023-6773No exploit | CodeAstro POS and Inventory Management System User Creation register_account access controlcodeastro · pos and inventory management system · CWE-284 | High8.8 | — | 0.7% | Dec 13, 2023 |
35Monitor | CVE-2024-55506No exploit | An IDOR vulnerability in CodeAstro's Complaint Management System v1.0 (version with 0 updates) enables an attacker to execute arbitrary codecodeastro · complaint management system · CWE-639 | High8.8 | — | 0.7% | Dec 18, 2024 |
35Monitor | CVE-2024-55505No exploit | An issue in CodeAstro Complaint Management System v.1.0 allows a remote attacker to escalate privileges via the mess-view.php component.codeastro · complaint management system · CWE-94 | High8.8 | — | 0.7% | Dec 18, 2024 |
34Monitor | CVE-2024-46472No exploit | CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection via the parameter 'email' in the Login Page.codeastro · membership management system · CWE-89 | High8.6 | — | 0.4% | Sep 27, 2024 |
32Monitor | CVE-2025-25777No exploit | Insecure Direct Object Reference (IDOR) in Codeastro Bus Ticket Booking System v1.0 allows unauthorized access to user profiles.codeastro · bus ticket booking system · CWE-639 | High8.0 | — | 0.3% | Apr 24, 2025 |
30Monitor | CVE-2024-2076No exploit | CodeAstro House Rental Management System tenant.php missing authenticationcodeastro · house rental management system · CWE-306 | High7.5 | — | 0.9% | Mar 1, 2024 |
30Monitor | CVE-2024-56889Proof of concept | Incorrect access control in the endpoint /admin/m_delete.php of CodeAstro Complaint Management System v1.0 allows unauthorized attackers to codeastro · complaint management system · CWE-284 | High7.5 | — | 0.7% | Feb 6, 2025 |
30Monitor | CVE-2024-46471No exploit | The Directory Listing in /uploads/ Folder in CodeAstro Membership Management System 1.0 exposes the structure and contents of directories, pcodeastro · membership management system · CWE-200 | High7.5 | — | 0.5% | Sep 27, 2024 |
30Monitor | CVE-2024-0543No exploit | CodeAstro Real Estate Management System propertydetail.php sql injectioncodeastro · real estate management system · CWE-89 | High7.5 | — | 0.5% | Jan 15, 2024 |
30Monitor | CVE-2025-70148No exploit | Missing authentication and authorization in print_membership_card.php in CodeAstro Membership Management System 1.0 allows unauthenticated acodeastro · membership management system · CWE-862 | High7.5 | — | 0.4% | Feb 18, 2026 |
29Monitor | CVE-2024-56924Proof of concept | A Cross Site Request Forgery (CSRF) vulnerability in Code Astro Internet banking system 2.0.0 allows remote attackers to execute arbitrary Jcodeastro · internet banking system · CWE-352 | High7.3 | — | 0.5% | Jan 22, 2025 |
28Monitor | CVE-2022-43085No exploit | An arbitrary file upload vulnerability in add_product.php of Restaurant POS System v1.0 allows attackers to execute arbitrary code via a cracodeastro · restaurant pos system · CWE-434 | High7.2 | — | 1.1% | Nov 1, 2022 |
28Monitor | CVE-2024-2333No exploit | CodeAstro Membership Management System add_members.php sql injectioncodeastro · membership management system · CWE-89 | High7.2 | — | 0.7% | Mar 9, 2024 |
- CVE-2024-2586941Plan
An Unrestricted File Upload vulnerability in CodeAstro Membership Management System in PHP v.1.0 allows a remote attacker to execute arbitra
HighCVSS 8.8No exploitEPSS 19%codeastro · membership management systemFeb 28, 2024
- CVE-2024-5550939Monitor
SQL injection vulnerability in CodeAstro Complaint Management System v.1.0 allows a remote attacker to execute arbitrary code and escalate p
CriticalCVSS 9.8No exploitEPSS 1%codeastro · complaint management systemDec 20, 2024
- CVE-2024-019439Monitor
CodeAstro Internet Banking System Profile Picture pages_account.php unrestricted upload
CriticalCVSS 9.8No exploitEPSS 1%codeastro · internet banking systemJan 2, 2024
- CVE-2024-235139Monitor
CodeAstro Ecommerce Site Search action.php sql injection
CriticalCVSS 9.8No exploitEPSS 1%codeastro · ecommerce websiteMar 9, 2024
- CVE-2025-7015039Monitor
CodeAstro Membership Management System 1.0 contains a missing authentication vulnerability in delete_members.php that allows unauthenticated
CriticalCVSS 9.8No exploitEPSS 1%codeastro · membership management systemFeb 18, 2026
- CVE-2024-5550739Monitor
An issue in CodeAstro Complaint Management System v.1.0 allows a remote attacker to escalate privileges via the delete_e.php component.
CriticalCVSS 9.8No exploitEPSS 1%codeastro · complaint management systemJan 3, 2025
- CVE-2024-182439Monitor
CodeAstro House Rental Management System signing.php sql injection
CriticalCVSS 9.8No exploitEPSS 1%codeastro · house rental management systemFeb 23, 2024
- CVE-2025-2577539Monitor
Codeastro Bus Ticket Booking System v1.0 is vulnerable to SQL injection via the kodetiket parameter in /BusTicket-CI/tiket/cekorder.
CriticalCVSS 9.8No exploitEPSS 1%codeastro · bus ticket booking systemApr 25, 2025
- CVE-2025-7014939Monitor
CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in print_membership_card.php via the ID parameter.
CriticalCVSS 9.8Proof of conceptEPSS 0%codeastro · membership management systemFeb 18, 2026
- CVE-2024-2586736Monitor
A SQL Injection vulnerability in CodeAstro Membership Management System in PHP v.1.0 allows a remote attacker to execute arbitrary SQL comma
CriticalCVSS 9.1No exploitEPSS 1%codeastro · membership management systemFeb 28, 2024
- CVE-2025-2901735Monitor
A Remote Code Execution (RCE) vulnerability exists in Code Astro Internet Banking System 2.0.0 due to improper file upload validation in the
HighCVSS 8.8Proof of conceptEPSS 1%codeastro · internet banking systemApr 10, 2025
- CVE-2024-2586635Monitor
A SQL Injection vulnerability in CodeAstro Membership Management System in PHP v.1.0 allows a remote attacker to execute arbitrary SQL comma
HighCVSS 8.8No exploitEPSS 1%codeastro · membership management systemFeb 28, 2024
- CVE-2023-677335Monitor
CodeAstro POS and Inventory Management System User Creation register_account access control
HighCVSS 8.8No exploitEPSS 1%codeastro · pos and inventory management systemDec 13, 2023
- CVE-2024-5550635Monitor
An IDOR vulnerability in CodeAstro's Complaint Management System v1.0 (version with 0 updates) enables an attacker to execute arbitrary code
HighCVSS 8.8No exploitEPSS 1%codeastro · complaint management systemDec 18, 2024
- CVE-2024-5550535Monitor
An issue in CodeAstro Complaint Management System v.1.0 allows a remote attacker to escalate privileges via the mess-view.php component.
HighCVSS 8.8No exploitEPSS 1%codeastro · complaint management systemDec 18, 2024
- CVE-2024-4647234Monitor
CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection via the parameter 'email' in the Login Page.
HighCVSS 8.6No exploitEPSS 0%codeastro · membership management systemSep 27, 2024
- CVE-2025-2577732Monitor
Insecure Direct Object Reference (IDOR) in Codeastro Bus Ticket Booking System v1.0 allows unauthorized access to user profiles.
HighCVSS 8.0No exploitEPSS 0%codeastro · bus ticket booking systemApr 24, 2025
- CVE-2024-207630Monitor
CodeAstro House Rental Management System tenant.php missing authentication
HighCVSS 7.5No exploitEPSS 1%codeastro · house rental management systemMar 1, 2024
- CVE-2024-5688930Monitor
Incorrect access control in the endpoint /admin/m_delete.php of CodeAstro Complaint Management System v1.0 allows unauthorized attackers to
HighCVSS 7.5Proof of conceptEPSS 1%codeastro · complaint management systemFeb 6, 2025
- CVE-2024-4647130Monitor
The Directory Listing in /uploads/ Folder in CodeAstro Membership Management System 1.0 exposes the structure and contents of directories, p
HighCVSS 7.5No exploitEPSS 1%codeastro · membership management systemSep 27, 2024
- CVE-2024-054330Monitor
CodeAstro Real Estate Management System propertydetail.php sql injection
HighCVSS 7.5No exploitEPSS 0%codeastro · real estate management systemJan 15, 2024
- CVE-2025-7014830Monitor
Missing authentication and authorization in print_membership_card.php in CodeAstro Membership Management System 1.0 allows unauthenticated a
HighCVSS 7.5No exploitEPSS 0%codeastro · membership management systemFeb 18, 2026
- CVE-2024-5692429Monitor
A Cross Site Request Forgery (CSRF) vulnerability in Code Astro Internet banking system 2.0.0 allows remote attackers to execute arbitrary J
HighCVSS 7.3Proof of conceptEPSS 0%codeastro · internet banking systemJan 22, 2025
- CVE-2022-4308528Monitor
An arbitrary file upload vulnerability in add_product.php of Restaurant POS System v1.0 allows attackers to execute arbitrary code via a cra
HighCVSS 7.2No exploitEPSS 1%codeastro · restaurant pos systemNov 1, 2022
- CVE-2024-233328Monitor
CodeAstro Membership Management System add_members.php sql injection
HighCVSS 7.2No exploitEPSS 1%codeastro · membership management systemMar 9, 2024