📦 Membership Management System

by Codeastro

🔍 What is Membership Management System?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-70150

CRITICAL CVSS 9.8 Feb 18, 2026

CVE-2025-70150 is a critical missing authentication vulnerability in CodeAstro Membership Management System 1.0 that allows unauthenticated attackers to delete arbitrary member records via the delete_...

CVE-2025-70149

CRITICAL CVSS 9.8 Feb 18, 2026

CodeAstro Membership Management System 1.0 contains a SQL injection vulnerability in the print_membership_card.php file via the ID parameter. This allows attackers to execute arbitrary SQL commands on...

CVE-2024-25867

CRITICAL CVSS 9.1 Feb 28, 2024

This SQL injection vulnerability in CodeAstro Membership Management System v1.0 allows remote attackers to execute arbitrary SQL commands through the membershipType and membershipAmount parameters in ...

CVE-2025-3998

HIGH CVSS 7.3 Apr 28, 2025

A critical SQL injection vulnerability in CodeAstro Membership Management System 1.0 allows remote attackers to execute arbitrary SQL commands via the ID parameter in renew.php. This can lead to unaut...

CVE-2024-46471

HIGH CVSS 7.5 Sep 27, 2024

This vulnerability allows unauthenticated directory listing of the /uploads/ folder in CodeAstro Membership Management System 1.0, exposing file structure and potentially sensitive uploaded content. A...

CVE-2024-25866

HIGH CVSS 8.8 Feb 28, 2024

This SQL injection vulnerability in CodeAstro Membership Management System v1.0 allows remote attackers to execute arbitrary SQL commands through the email parameter in index.php. Attackers can potent...

CVE-2024-25869

HIGH CVSS 8.8 Feb 28, 2024

An unrestricted file upload vulnerability in CodeAstro Membership Management System v1.0 allows remote attackers to upload malicious PHP files through the settings.php component. This enables arbitrar...

CVE-2024-45528

MEDIUM CVSS 5.4 Sep 2, 2024

This vulnerability allows attackers to inject malicious scripts into the 'fullname' field during member creation in CodeAstro MembershipM-PHP 1.0. When administrators view the member list, the scripts...