Membership Management System

CodeAstro · 19 CVEs

CVE-2025-70150
CRITICAL

CodeAstro Membership Management System 1.0 contains a missing authentication vulnerability in delete_members.php that a…

Feb 18, 2026

CVE-2025-70149
CRITICAL

CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in print_membership_card.php via the ID param…

Feb 18, 2026

CVE-2025-70148
HIGH

Missing authentication and authorization in print_membership_card.php in CodeAstro Membership Management System 1.0 all…

Feb 18, 2026

CVE-2025-3998
MEDIUM

CodeAstro Membership Management System renew.php sql injection

Apr 28, 2025

CVE-2024-48709
MEDIUM

CodeAstro Membership Management System v1.0 is vulnerable to Cross Site Scripting (XSS) via the membershipType paramete…

Oct 21, 2024

CVE-2024-46236
MEDIUM

CodeAstro Membership Management System v1.0 is vulnerable to Cross Site Scripting (XSS) via the address parameter in ad…

Oct 21, 2024

CVE-2024-46472
HIGH

CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection via the parameter 'email' in the Login Page.

Sep 27, 2024

CVE-2024-46471
HIGH

The Directory Listing in /uploads/ Folder in CodeAstro Membership Management System 1.0 exposes the structure and conte…

Sep 27, 2024

CVE-2024-46470
MEDIUM

Cross Site Scripting vulnerability in CodeAstro Membership Management System 1.0 allows attackers to run malicious Java…

Sep 27, 2024

CVE-2024-45528
MEDIUM

CodeAstro MembershipM-PHP (aka Membership Management System in PHP) 1.0 allows add_members.php fullname stored XSS.

Sep 2, 2024

CVE-2024-2333
HIGH

CodeAstro Membership Management System add_members.php sql injection

Mar 9, 2024

CVE-2024-2149
HIGH

CodeAstro Membership Management System settings.php sql injection

Mar 3, 2024

CVE-2024-25869
HIGH

An Unrestricted File Upload vulnerability in CodeAstro Membership Management System in PHP v.1.0 allows a remote attack…

Feb 28, 2024

CVE-2024-25868
MEDIUM

A Cross Site Scripting (XSS) vulnerability in CodeAstro Membership Management System in PHP v.1.0 allows a remote attac…

Feb 28, 2024

CVE-2024-25867
CRITICAL

A SQL Injection vulnerability in CodeAstro Membership Management System in PHP v.1.0 allows a remote attacker to execut…

Feb 28, 2024

CVE-2024-25866
HIGH

A SQL Injection vulnerability in CodeAstro Membership Management System in PHP v.1.0 allows a remote attacker to execut…

Feb 28, 2024

CVE-2024-1924
MEDIUM

CodeAstro Membership Management System get_membership_amount.php sql injection

Feb 27, 2024

CVE-2024-1819
HIGH

CodeAstro Membership Management System Add Members Tab unrestricted upload

Feb 23, 2024

CVE-2024-1818
HIGH

CodeAstro Membership Management System Logo unrestricted upload

Feb 23, 2024

Showing 1 to 19 of 19 CVEs