Codeastro develops a focused portfolio of web-based management systems spanning membership, real estate, gym operations, complaint handling, and residential rental domains, each presenting a typical small-business or administrative deployment context. Despite its narrow product scope, the vendor's vulnerability footprint is moderately represented in the landscape and skews toward serious outcomes, with an elevated share of disclosures reaching critical severity. The recurring weakness classes—SQL injection, output injection, cross-site scripting, unrestricted file uploads, and improper access control—reflect consistent gaps in input validation, output encoding, and authorization logic across the product line, characteristic of web applications built without defense-in-depth input and access controls. These vulnerability patterns suggest that defenders deploying Codeastro systems should prioritize input sanitization, output encoding, and access-control reviews, as the same structural flaws tend to recur across the vendor's offerings. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Codeastro over time
Signals from CVEs in this vendor scope (109 CVEs).
109 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-70150CRITICAL CodeAstro Membership Management System 1.0 contains a missing authentication vulnerability in delete_members.php that allows unauthenticated attackers to delete arbitrary member re | Feb 18, 2026 | 9.8 | 34 | NO | NO |
CVE-2025-70149CRITICAL CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in print_membership_card.php via the ID parameter. | Feb 18, 2026 | 9.8 | 34 | NO | NO |
CVE-2024-25869HIGH An Unrestricted File Upload vulnerability in CodeAstro Membership Management System in PHP v.1.0 allows a remote attacker to execute arbitrary code via upload of a crafted php file | Feb 28, 2024 | 8.8 | 32 | NO | NO |
CVE-2025-13280CRITICAL A vulnerability was determined in CodeAstro Simple Inventory System 1.0. The impacted element is an unknown function of the file /index.php of the component Login. Executing a mani | Nov 17, 2025 | 9.8 | 31 | NO | NO |
CVE-2025-11118CRITICAL A vulnerability was identified in CodeAstro Student Grading System 1.0. This issue affects some unknown processing of the file /adminLogin.php. Such manipulation of the argument st | Sep 28, 2025 | 9.8 | 31 | NO | NO |
CVE-2025-5581CRITICAL A vulnerability was found in CodeAstro Real Estate Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /admin/index.php. Th | Jun 4, 2025 | 9.8 | 30 | NO | NO |
CVE-2025-5580CRITICAL A vulnerability was found in CodeAstro Real Estate Management System 1.0. It has been classified as critical. This affects an unknown part of the file /login.php. The manipulation | Jun 4, 2025 | 9.8 | 30 | NO | NO |
CVE-2025-3998CRITICAL A vulnerability classified as critical was found in CodeAstro Membership Management System 1.0. This vulnerability affects unknown code of the file renew.php?id=6. The manipulation | Apr 28, 2025 | 9.8 | 30 | NO | NO |
CVE-2024-12943CRITICAL A vulnerability was found in CodeAstro House Rental Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file | Dec 26, 2024 | 9.8 | 30 | NO | NO |
CVE-2024-0194CRITICAL A vulnerability, which was classified as critical, has been found in CodeAstro Internet Banking System up to 1.0. This issue affects some unknown processing of the file pages_accou | Jan 2, 2024 | 9.8 | 30 | NO | NO |
Signals from CVEs in this vendor scope (109 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Codeastro.
Media articles that mention a CVE ID that affects a product developed by Codeastro — matched by CVE ID, not by vendor name.