Skip to main content

Vendor/product archive

codeastro / membership_management_system CVEs

Beta · best-effort

19 CVEs tagged to codeastro / membership_management_system3 Critical, 5 High, 11 Medium, 0 Low, 0 Unrated.

CVE-2025-70150

Published Feb 18, 2026

CodeAstro Membership Management System 1.0 contains a missing authentication vulnerability in delete_members.php that allows unauthenticated attackers to delete arbitrary member r…

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2025-70148

Published Feb 18, 2026

Missing authentication and authorization in print_membership_card.php in CodeAstro Membership Management System 1.0 allows unauthenticated attackers to access membership card data…

CVSS 7.5 · High
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2025-3998

Published Apr 28, 2025

A vulnerability classified as critical was found in CodeAstro Membership Management System 1.0. This vulnerability affects unknown code of the file renew.php?id=6. The manipulatio…

CVSS 6.9 · Medium
evidence mentions
5
Buzz score
33.9
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2024-46471

Published Sep 27, 2024

The Directory Listing in /uploads/ Folder in CodeAstro Membership Management System 1.0 exposes the structure and contents of directories, potentially revealing sensitive informat…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-46470

Published Sep 27, 2024

Cross Site Scripting vulnerability in CodeAstro Membership Management System 1.0 allows attackers to run malicious JavaScript via the membership_type field in the edit-type.php co…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-2333

Published Mar 9, 2024

A vulnerability classified as critical has been found in CodeAstro Membership Management System 1.0. Affected is an unknown function of the file /add_members.php. The manipulation…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-2149

Published Mar 3, 2024

A vulnerability classified as critical was found in CodeAstro Membership Management System 1.0. This vulnerability affects unknown code of the file settings.php. The manipulation…

CVSS 4.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-25869

Published Feb 28, 2024

An Unrestricted File Upload vulnerability in CodeAstro Membership Management System in PHP v.1.0 allows a remote attacker to execute arbitrary code via upload of a crafted php fil…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-25868

Published Feb 28, 2024

A Cross Site Scripting (XSS) vulnerability in CodeAstro Membership Management System in PHP v.1.0 allows a remote attacker to execute arbitrary code via the membershipType paramet…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-25867

Published Feb 28, 2024

A SQL Injection vulnerability in CodeAstro Membership Management System in PHP v.1.0 allows a remote attacker to execute arbitrary SQL commands via the membershipType and membersh…

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-25866

Published Feb 28, 2024

A SQL Injection vulnerability in CodeAstro Membership Management System in PHP v.1.0 allows a remote attacker to execute arbitrary SQL commands via the email parameter in the inde…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-1924

Published Feb 27, 2024

A vulnerability was found in CodeAstro Membership Management System 1.0. It has been classified as critical. This affects an unknown part of the file /get_membership_amount.php. T…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-1819

Published Feb 23, 2024

A vulnerability was found in CodeAstro Membership Management System 1.0. It has been classified as critical. This affects an unknown part of the component Add Members Tab. The man…

CVSS 4.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-1818

Published Feb 23, 2024

A vulnerability was found in CodeAstro Membership Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /uploads/ of t…

CVSS 4.7 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-19 of 19 CVEsPage 1 of 1