CodeAstro has 4 CVEs on record. 1 was published in the last 90 days. The busiest recent month was February 2026 with 3. The median CVSS is 8.7 (high), with 2 rated critical. Most affected products: membership_management_system (3), QR Code Attendance Management System (1).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 8.7
- Publish → KEV
- —
- Last 90 days
- 1 prev 0
Products
- membership_management_system 3
- QR Code Attendance Management System 1
Worst active — by depth score
CVE-2025-70150Critical· 9.8CodeAstro Membership Management System 1.0 contains a missing authentication vulnerability in delete_members.php that allows unauthenticated attackers to delete arbitrary member records via the id parameter.66CVE-2025-70149Critical· 9.8CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in print_membership_card.php via the ID parameter.66CVE-2025-70148High· 7.5Missing authentication and authorization in print_membership_card.php in CodeAstro Membership Management System 1.0 allows unauthenticated attackers to access membership card data of arbitrary users via direct requests with a manipulated…53CVE-2026-94048Medium· 6.6A vulnerability was detected in CodeAstro QR Code Attendance Management System 1.048
CodeAstro vulnerabilities
CVEs affecting CodeAstro, newest first. Open any entry for full detail, references, and exploit status.
4 CVEsRSS
CVE-2026-94048Medium· 6.6PoCA vulnerability was detected in CodeAstro QR Code Attendance Management System 1.0
A vulnerability was detected in CodeAstro QR Code Attendance Management System 1.0. This affects the function Save of the file app/Controllers/UserController.php. The manipulation of the argument role_id results in improper privilege man…
CVE-2025-70150Critical· 9.8PoCCodeAstro Membership Management System 1.0 contains a missing authentication vulnerability in delete_members.php that allows unauthenticated attackers to delete arbitrary member records via the id parameter.
CodeAstro Membership Management System 1.0 contains a missing authentication vulnerability in delete_members.php that allows unauthenticated attackers to delete arbitrary member records via the id parameter.
CVE-2025-70149Critical· 9.8PoCCodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in print_membership_card.php via the ID parameter.
CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in print_membership_card.php via the ID parameter.
CVE-2025-70148High· 7.5PoCMissing authentication and authorization in print_membership_card.php in CodeAstro Membership Management System 1.0 allows unauthenticated attackers to access membership card data of arbitrary users via direct requests with a manipulated…
Missing authentication and authorization in print_membership_card.php in CodeAstro Membership Management System 1.0 allows unauthenticated attackers to access membership card data of arbitrary users via direct requests with a manipulated…