CodeAstro vulnerabilities
9 CVEs tracked
CodeAstro appears in recent reports primarily due to multiple SQL Injection vulnerabilities. The 'Membership Management System 1.0' is heavily affected, with CVEs from CVE-2025-69933 to CVE-2025-69938 and CVE-2025-69930 targeting various endpoints like 'edit_type.php', 'edit_member.php', and 'renew.php'. Additionally, 'Online Classroom 1.0' is affected by CVE-2026-16765 via the 'loginlinkadmin.php' file. Defenders should focus on monitoring database queries and restricting access for products running these versions, paying close attention to parameters such as 'id', 'membershipType', and 'fromDate'.
Azərbaycanca: CodeAstro son hesabatlarda ciddi SQL injection zəiflikləri ilə diqqət çəkir. 'Membership Management System 1.0' məhsulu üçün bir çox endpoint-də ('edit_type.php', 'edit_member.php', 'renew.php' daxil olmaqla) CVE-2025-69933-dən CVE-2025-69938-ə qədər və CVE-2025-69930 zəiflikləri müəyyən edilib. 'Online Classroom 1.0' məhsulunda isə 'loginlinkadmin.php' faylında CVE-2026-16765 SQL injection aşkarlanıb. Müdafiəçilər bu versiyaları istifadə edən sistemlərdə məlumat bazası əməliyyatlarına nəzarət etməli, xüsusilə 'id', 'membershipType' və 'fromDate' kimi parametrlər üzərindən gələn şübhəli SQL sorğularını nəzarətdə saxlamalıdır.
This vendor's CVEs9
This hub is built from skopnix's own reporting on CodeAstro: the overview is AI-written from that coverage and every CVE links to its grounded explainer. KEV status comes from CISA's Known Exploited Vulnerabilities catalog and EPSS from FIRST — vendor, version and score details are never invented.