Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Codeastro

First CVE: Nov 1, 2022Active for: 4 yearsTotal CVEs: 109
38.4
VTI Score
Medium

Codeastro develops a focused portfolio of web-based management systems spanning membership, real estate, gym operations, complaint handling, and residential rental domains, each presenting a typical small-business or administrative deployment context. Despite its narrow product scope, the vendor's vulnerability footprint is moderately represented in the landscape and skews toward serious outcomes, with an elevated share of disclosures reaching critical severity. The recurring weakness classes—SQL injection, output injection, cross-site scripting, unrestricted file uploads, and improper access control—reflect consistent gaps in input validation, output encoding, and authorization logic across the product line, characteristic of web applications built without defense-in-depth input and access controls. These vulnerability patterns suggest that defenders deploying Codeastro systems should prioritize input sanitization, output encoding, and access-control reviews, as the same structural flaws tend to recur across the vendor's offerings. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.

FAUCET AI Generated
109
Total CVEs
More Total CVEs than 99% of tracked vendors
0.8
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 11% of tracked vendors
7.7
Avg CVSS Score
Higher Avg CVSS Score than 73% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Codeastro over time

Volume of CVEsAvg CVSS Base Score
First CVE
Nov 1, 2022
3 years ago
Most Recent CVE
Feb 25, 2026
149 days ago

Products(28 total)

Top CVEs

Signals from CVEs in this vendor scope (109 CVEs).

109 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2025-70150CRITICAL
CodeAstro Membership Management System 1.0 contains a missing authentication vulnerability in delete_members.php that allows unauthenticated attackers to delete arbitrary member re
Feb 18, 20269.834NONO
CVE-2025-70149CRITICAL
CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in print_membership_card.php via the ID parameter.
Feb 18, 20269.834NONO
CVE-2024-25869HIGH
An Unrestricted File Upload vulnerability in CodeAstro Membership Management System in PHP v.1.0 allows a remote attacker to execute arbitrary code via upload of a crafted php file
Feb 28, 20248.832NONO
CVE-2025-13280CRITICAL
A vulnerability was determined in CodeAstro Simple Inventory System 1.0. The impacted element is an unknown function of the file /index.php of the component Login. Executing a mani
Nov 17, 20259.831NONO
CVE-2025-11118CRITICAL
A vulnerability was identified in CodeAstro Student Grading System 1.0. This issue affects some unknown processing of the file /adminLogin.php. Such manipulation of the argument st
Sep 28, 20259.831NONO
CVE-2025-5581CRITICAL
A vulnerability was found in CodeAstro Real Estate Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /admin/index.php. Th
Jun 4, 20259.830NONO
CVE-2025-5580CRITICAL
A vulnerability was found in CodeAstro Real Estate Management System 1.0. It has been classified as critical. This affects an unknown part of the file /login.php. The manipulation
Jun 4, 20259.830NONO
CVE-2025-3998CRITICAL
A vulnerability classified as critical was found in CodeAstro Membership Management System 1.0. This vulnerability affects unknown code of the file renew.php?id=6. The manipulation
Apr 28, 20259.830NONO
CVE-2024-12943CRITICAL
A vulnerability was found in CodeAstro House Rental Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file
Dec 26, 20249.830NONO
CVE-2024-0194CRITICAL
A vulnerability, which was classified as critical, has been found in CodeAstro Internet Banking System up to 1.0. This issue affects some unknown processing of the file pages_accou
Jan 2, 20249.830NONO
View all 109 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products109 CVEs
29%
50%
21%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local3 (2.8%)
Network106 (97.2%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low109 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None80 (73.4%)
Unknown0 (0.0%)
Required29 (26.6%)
Privileges Required
Low47 (43.1%)
High18 (16.5%)
None44 (40.4%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (109 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Codeastro.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Codeastro — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Codeastro's Products

View all 2 CNAs →

Top CWEs