Codeastro
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in any Codeastro product.
RSS Feeds for Codeastro security vulnerabilities
Create a CVE RSS feed including security vulnerabilities found in Codeastro products with stack.watch. Just hit watch, then grab your custom RSS feed url.
Products by Codeastro Sorted by Most Security Vulnerabilities since 2018
By the Year
In 2026 there have been 72 vulnerabilities in Codeastro with an average score of 6.4 out of ten. Last year, in 2025 Codeastro had 48 security vulnerabilities published. That is, 24 more vulnerabilities have already been reported in 2026 as compared to last year. Last year, the average CVE base score was greater by 0.37
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 72 | 6.40 |
| 2025 | 48 | 6.77 |
| 2024 | 45 | 7.24 |
| 2023 | 7 | 6.91 |
| 2022 | 2 | 6.05 |
It may take a day or so for new Codeastro vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent Codeastro Security Vulnerabilities
| CVE | Date | Vulnerability | Products |
|---|---|---|---|
| CVE-2026-77681 | Aug 21, 2026 |
CodeAstro 1.0 Unrestricted File Upload via Name param in update-profile.phpA vulnerability was identified in CodeAstro Online Job Portal 1.0. Affected by this vulnerability is an unknown functionality of the file /users/update-profile.php. The manipulation of the argument Name leads to unrestricted upload. The attack can be initiated remotely. The exploit is publicly available and might be used. |
|
| CVE-2026-77020 | Aug 20, 2026 |
SQLi in CodeAstro A2MS 1.0 via 'password-recovery.php' emailA vulnerability was identified in CodeAstro Apartment Visitor Management System 1.0. Affected by this vulnerability is an unknown functionality of the file password-recovery.php. The manipulation of the argument email leads to sql injection. Remote exploitation of the attack is possible. The exploit is publicly available and might be used. |
|
| CVE-2026-77019 | Aug 20, 2026 |
CodeAstro Apartment Visitor Mgmt 1.0: SQLi via secode in forgotpw.phpA vulnerability was determined in CodeAstro Apartment Visitor Management System 1.0. Affected is an unknown function of the file /apartment-visitor/forgotpw.php. Executing a manipulation of the argument secode can lead to sql injection. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized. |
|
| CVE-2025-69933 | Jul 30, 2026 |
SQLi in CodeAstro Membership Management Sys 1.0 /memberProfile.phpCodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /memberProfile.php?id=1. |
|
| CVE-2025-69934 | Jul 30, 2026 |
CodeAstro Membership Management System 1.0: SQLI /delete_members.php idCodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /delete_members.php?id=1. |
|
| CVE-2025-69935 | Jul 30, 2026 |
SQLi in report.php of CodeAstro Membership Management System 1.0CodeAstro Membership Management System 1.0 is vulnerale to SQL Injection in the report.php and revenue_report.php via the fromDate parameter. |
|
| CVE-2025-69936 | Jul 30, 2026 |
CodeAstro Membership Sys 1.0 - SQLi in edit_member.phpCodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /edit_member.php?id=1. |
|
| CVE-2025-69937 | Jul 30, 2026 |
CodeAstro Membership Management Sys 1.0 SQLi via edit_type.php (id param)CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in the edit_type.php endpoint via the Parameter id. |
|
| CVE-2026-16765 | Jul 23, 2026 |
CodeAstro Online Classroom 1.0 SQLi via /OnlineClassroom/loginlinkadmin.phpA vulnerability was determined in CodeAstro Online Classroom 1.0. Affected by this issue is some unknown functionality of the file /OnlineClassroom/loginlinkadmin.php. Executing a manipulation of the argument aid can lead to sql injection. The attack can be executed remotely. The exploit has been publicly disclosed and may be utilized. |
|
| CVE-2026-15559 | Jul 13, 2026 |
CodeAstro Simple Online Leave Mgmt 1.0 SQLi via POST Handler (appid)A vulnerability was detected in CodeAstro Simple Online Leave Management System 1.0. This affects an unknown part of the file /SimpleOnlineLeave/admin/accept.php of the component POST Handler. Performing a manipulation of the argument appid results in sql injection. The attack is possible to be carried out remotely. The exploit is now public and may be used. |
|
| CVE-2026-15558 | Jul 13, 2026 |
CodeAstro Simple Online Leave Mgmt 1.0: SQLi via deletemp.phpA security vulnerability has been detected in CodeAstro Simple Online Leave Management System 1.0. Affected by this issue is some unknown functionality of the file /SimpleOnlineLeave/admin/deletemp.php. Such manipulation of the argument ID leads to sql injection. The attack can be executed remotely. The exploit has been disclosed publicly and may be used. |
|
| CVE-2026-15523 | Jul 13, 2026 |
Remote SQLi in CodeAstro Simple Online Leave Mgmt 1.0 admin/dashboard.phpA weakness has been identified in CodeAstro Simple Online Leave Management System 1.0. Affected by this issue is some unknown functionality of the file /SimpleOnlineLeave/admin/dashboard.php. This manipulation of the argument Name causes sql injection. The attack can be initiated remotely. The exploit has been made available to the public and could be used for attacks. |
|
| CVE-2026-15134 | Jul 08, 2026 |
SQLi in CodeAstro Simple Online Leave Mgt. Sys 1.0 (/index.php) via emailA vulnerability was determined in CodeAstro Simple Online Leave Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /SimpleOnlineLeave/index.php. Executing a manipulation of the argument email can lead to sql injection. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized. |
|
| CVE-2026-14799 | Jul 06, 2026 |
CodeAstro Ecommerce 1.0 Remote SQLi via my_wishlist delete_wishlistA security flaw has been discovered in CodeAstro Ecommerce Website 1.0. Impacted is an unknown function of the file /customer/my_account.php?my_wishlist. The manipulation of the argument delete_wishlist results in sql injection. The attack can be launched remotely. The exploit has been released to the public and may be used for attacks. |
|
| CVE-2026-14798 | Jul 06, 2026 |
SQL Injection in CodeAstro A/VMS 1.0 via visname in visitor-entry.phpA vulnerability was identified in CodeAstro Apartment Visitor Management System 1.0. This issue affects some unknown processing of the file /apartment-visitor/visitor-entry.php. The manipulation of the argument visname leads to sql injection. The attack can be initiated remotely. The exploit is publicly available and might be used. |
|
| CVE-2026-14797 | Jul 06, 2026 |
CodeAstro A/VMS 1.0: Remote SQLi via editid in edit-apartment.phpA vulnerability was determined in CodeAstro Apartment Visitor Management System 1.0. This vulnerability affects unknown code of the file /apartment-visitor/edit-apartment.php. Executing a manipulation of the argument editid can lead to sql injection. It is possible to launch the attack remotely. The exploit has been publicly disclosed and may be utilized. |
|
| CVE-2026-14796 | Jul 06, 2026 |
CodeAstro Apartment VisitMgmt 1.0 SQLi via /report.php fromdateA vulnerability was found in CodeAstro Apartment Visitor Management System 1.0. This affects an unknown part of the file /apartment-visitor/report.php. Performing a manipulation of the argument fromdate results in sql injection. It is possible to initiate the attack remotely. The exploit has been made public and could be used. |
|
| CVE-2026-14795 | Jul 06, 2026 |
CodeAstro Apartment Visitor Mgmt 1.0 Remote SQLi via action-visitor.phpA vulnerability has been found in CodeAstro Apartment Visitor Management System 1.0. Affected by this issue is some unknown functionality of the file /apartment-visitor/action-visitor.php. Such manipulation of the argument remark leads to sql injection. The attack may be performed from remote. The exploit has been disclosed to the public and may be used. |
|
| CVE-2026-14767 | Jul 05, 2026 |
SQLi in CodeAstro Ecom Site 1.0 POST Param invoice_noA security flaw has been discovered in CodeAstro Ecommerce Website 1.0. This affects an unknown part of the file /ecommerce-website-php/customer/confirm.php of the component POST Parameter Handler. The manipulation of the argument invoice_no results in sql injection. The attack can be executed remotely. The exploit has been released to the public and may be used for attacks. |
|
| CVE-2026-14766 | Jul 05, 2026 |
SQLi via POST Parameter Handler in CodeAstro Apt Visitor Mgmt 1.0A vulnerability was identified in CodeAstro Apartment Visitor Management System 1.0. Affected by this issue is some unknown functionality of the file /apartment-visitor/search-result.php of the component POST Parameter Handler. The manipulation of the argument searchdata leads to sql injection. Remote exploitation of the attack is possible. The exploit is publicly available and might be used. |
|
| CVE-2026-14689 | Jul 05, 2026 |
SQLi in CodeAstro Apartment Visitor Management 1.0 add-apartment.php via apartmentnoA security flaw has been discovered in CodeAstro Apartment Visitor Management System 1.0. The impacted element is an unknown function of the file /apartment-visitor/add-apartment.php. The manipulation of the argument apartmentno results in sql injection. The attack may be launched remotely. The exploit has been released to the public and may be used for attacks. |
|
| CVE-2026-14640 | Jul 04, 2026 |
CodeAstro Appt Visitor Mgmt Sys 1.0 Remote SQLi via Login UsernameA vulnerability was found in CodeAstro Apartment Visitor Management System 1.0. Affected is an unknown function of the file /index.php of the component Login. Performing a manipulation of the argument Username results in sql injection. Remote exploitation of the attack is possible. The exploit has been made public and could be used. |
|
| CVE-2026-14639 | Jul 04, 2026 |
CodeAstro Ecommerce 1.0 my_account.php c_name SQLiA vulnerability has been found in CodeAstro Ecommerce Website 1.0. This impacts an unknown function of the file /ecommerce-website-php/customer/my_account.php?edit_account. Such manipulation of the argument c_name leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. |
|
| CVE-2026-13558 | Jun 29, 2026 |
CodeAstro 1.0 - XSS in /report/addreport Report Title via Report HandlerA security flaw has been discovered in CodeAstro Complaint Management System 1.0. This issue affects some unknown processing of the file /report/addreport of the component Report Handler. Performing a manipulation of the argument Report Title results in cross site scripting. Remote exploitation of the attack is possible. The exploit has been released to the public and may be used for attacks. |
|
| CVE-2026-13549 | Jun 29, 2026 |
CodeAstro CMS v1.0 Auth Bypass in Report Endpoint via deletereportA security flaw has been discovered in CodeAstro Complaint Management System 1.0. The affected element is the function deletereport of the file application/controllers/Report.php of the component Report Endpoint. The manipulation results in authorization bypass. The attack can be executed remotely. The exploit has been released to the public and may be used for attacks. |
|
| CVE-2026-13537 | Jun 29, 2026 |
CodeAstro HRMS 1.0 CSRF Vulnerability (Remote Exploit)A vulnerability was found in CodeAstro Human Resource Management System 1.0. Impacted is an unknown function. The manipulation results in cross-site request forgery. The attack may be launched remotely. The exploit has been made public and could be used. |
|
| CVE-2026-13535 | Jun 29, 2026 |
CodeAstro HRMS 1.0 ViewEndpoint SQLi via GetFileInfo(ID)A flaw has been found in CodeAstro Human Resource Management System 1.0. This vulnerability affects the function GetFileInfo of the file hrsystem/application/models/Employee_model.php of the component View Endpoint. Executing a manipulation of the argument ID can lead to sql injection. The attack can be launched remotely. The exploit has been published and may be used. |
|
| CVE-2026-13525 | Jun 29, 2026 |
CodeAstro HRMS 1.0 SQL Injection via Update_Earn_Leave EndpointA vulnerability was detected in CodeAstro Human Resource Management System 1.0. This issue affects the function emselectByCode of the file application/models/Employee_model.php of the component Update_Earn_Leave Endpoint. The manipulation of the argument emid results in sql injection. The attack can be launched remotely. The exploit is now public and may be used. |
|
| CVE-2026-12175 | Jun 13, 2026 |
SQLi in CodeAstro Student Attendance Management System 1.0 createStudents.phpA vulnerability was detected in CodeAstro Student Attendance Management System 1.0. Impacted is an unknown function of the file /attendance-php/Admin/createStudents.php. Performing a manipulation of the argument admissionNumber results in sql injection. Remote exploitation of the attack is possible. The exploit is now public and may be used. |
|
| CVE-2026-12131 | Jun 12, 2026 |
CodeAstro HRMS 1.0: Payroll Invoice ID SQLiA weakness has been identified in CodeAstro Human Resource Management System 1.0. This vulnerability affects the function Invoice of the file \application\controllers\Payroll.php of the component Payroll Invoice Module. This manipulation of the argument ID causes sql injection. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be used for attacks. |
|
| CVE-2026-12130 | Jun 12, 2026 |
CodeAstro HRM 1.0 N: XSS via protitle on /Projects/Add_ProjectsA security flaw has been discovered in CodeAstro Human Resource Management System 1.0. This affects an unknown part of the file /Projects/Add_Projects of the component Projects Management Page. The manipulation of the argument protitle results in cross site scripting. The attack may be launched remotely. The exploit has been released to the public and may be used for attacks. |
|
| CVE-2026-12129 | Jun 12, 2026 |
XSS in Dashboard Interface of CodeAstro HRMS 1.0 (before 1.1)A vulnerability was identified in CodeAstro Human Resource Management System 1.0. Affected by this issue is some unknown functionality of the file /dashboard/add_tod of the component Dashboard Interface. The manipulation of the argument todo_data leads to cross site scripting. The attack may be initiated remotely. The exploit is publicly available and might be used. |
|
| CVE-2026-11585 | Jun 08, 2026 |
CVE-2026-11585 SQLi via classId in CodeAstro 1.0 Admin/createClassArms.phpA vulnerability was determined in CodeAstro Student Attendance Management System 1.0. Affected is an unknown function of the file /attendance-php/Admin/createClassArms.php. This manipulation of the argument classId causes sql injection. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. |
|
| CVE-2026-11584 | Jun 08, 2026 |
SQLi in CodeAstro Student Att. System 1.0 (createClass.php ID)A vulnerability was found in CodeAstro Student Attendance Management System 1.0. This impacts an unknown function of the file /attendance-php/Admin/createClass.php?action=edit. The manipulation of the argument ID results in sql injection. It is possible to launch the attack remotely. The exploit has been made public and could be used. |
|
| CVE-2026-11583 | Jun 08, 2026 |
CodeAstro Student Attendance 1.0 SQLi via className in createClass.phpA vulnerability has been found in CodeAstro Student Attendance Management System 1.0. This affects an unknown function of the file /attendance-php/Admin/createClass.php. The manipulation of the argument className leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. |
|
| CVE-2026-11582 | Jun 08, 2026 |
CodeAstro Student Attendance MS 1.0 SQLi via Username (remote)A flaw has been found in CodeAstro Student Attendance Management System 1.0. The impacted element is an unknown function of the file /attendance-php/index.php. Executing a manipulation of the argument Username can lead to sql injection. The attack may be performed from remote. The exploit has been published and may be used. |
|
| CVE-2026-11559 | Jun 08, 2026 |
CodeAstro Payroll System 1.0 SQLi via /view_account.php IDA vulnerability was detected in CodeAstro Payroll System 1.0. This affects an unknown function of the file /view_account.php. The manipulation of the argument ID results in sql injection. The attack may be performed from remote. The exploit is now public and may be used. |
|
| CVE-2026-11558 | Jun 08, 2026 |
Remote SQLi via rate/salary_rate in CodeAstro Payroll 1.0A security vulnerability has been detected in CodeAstro Payroll System 1.0. The impacted element is an unknown function of the file /home_salary.php. The manipulation of the argument rate/salary_rate leads to sql injection. The attack is possible to be carried out remotely. The exploit has been disclosed publicly and may be used. |
|
| CVE-2026-11510 | Jun 08, 2026 |
Remote SQLi via admin/add_leave.php in CodeAstro LMT 1.0A security flaw has been discovered in CodeAstro Leave Management System 1.0. This affects an unknown part of the file /admin/add_leave.php. Performing a manipulation of the argument type_of_leave results in sql injection. It is possible to initiate the attack remotely. The exploit has been released to the public and may be used for attacks. |
|
| CVE-2026-11509 | Jun 08, 2026 |
CodeAstro LSM 1.0 SQLi in search_staff_for_updation.phpA vulnerability was identified in CodeAstro Leave Management System 1.0. Affected by this issue is some unknown functionality of the file /admin/search_staff_for_updation.php. Such manipulation of the argument Name leads to sql injection. The attack may be performed from remote. |
|
| CVE-2026-11508 | Jun 08, 2026 |
CodeAstro LMS 1.0 Remote SQLi via /admin/search_staff_to_assign_pc.phpA vulnerability was determined in CodeAstro Leave Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/search_staff_to_assign_pc.php. This manipulation of the argument Name causes sql injection. The attack is possible to be carried out remotely. The exploit has been publicly disclosed and may be utilized. |
|
| CVE-2026-11507 | Jun 08, 2026 |
CodeAstro Leave Management System 1.0 - SQLi via /admin/delete_leave_type.phpA vulnerability was found in CodeAstro Leave Management System 1.0. Affected is an unknown function of the file /admin/delete_leave_type.php. The manipulation of the argument leave_type results in sql injection. The attack can be executed remotely. The exploit has been made public and could be used. |
|
| CVE-2026-11506 | Jun 08, 2026 |
CVE-2026-11506: SQLi in CodeAstro LeaveMgmt 1.0/admin/search_staff_for_deletion.phpA vulnerability has been found in CodeAstro Leave Management System 1.0. This impacts an unknown function of the file /admin/search_staff_for_deletion.php. The manipulation of the argument Name leads to sql injection. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used. |
|
| CVE-2026-11495 | Jun 08, 2026 |
SQLi in CodeAstro Ingredients Stock Mgmt Sys 1.0 via ID in add_stock.phpA vulnerability was detected in CodeAstro Ingredients Stock Management System 1.0. This impacts an unknown function of the file /Ingredients-Stock/add_stock.php. The manipulation of the argument ID results in sql injection. The attack may be launched remotely. The exploit is now public and may be used. |
|
| CVE-2026-11491 | Jun 08, 2026 |
CodeAstro HRMS 1.0 XSS Vulnerability in Notice Board ManagementA vulnerability was identified in CodeAstro Human Resource Management System 1.0. Impacted is an unknown function of the file /notice/All_notice of the component Notice Board Management. Such manipulation of the argument Notice Title with the input <svg onload="alert('Stored XSS Triggered by Ashik Mohamed')"> as part of POST leads to cross site scripting. It is possible to launch the attack remotely. The exploit is publicly available and might be used. |
|
| CVE-2026-10286 | Jun 01, 2026 |
CodeAstro Payroll System 1.0 SQLi via emp_id in /home_employee.phpA vulnerability was found in CodeAstro Payroll System 1.0. This affects an unknown part of the file /home_employee.php. The manipulation of the argument emp_id results in sql injection. The attack may be performed from remote. The exploit has been made public and could be used. |
|
| CVE-2026-10261 | Jun 01, 2026 |
SQL Injection in CodeAstro Online Job Portal 1.0 /users/application_status.phpA flaw has been found in CodeAstro Online Job Portal 1.0. This affects an unknown function of the file /users/application_status.php. Executing a manipulation of the argument ID can lead to sql injection. It is possible to launch the attack remotely. The exploit has been published and may be used. |
|
| CVE-2026-10260 | Jun 01, 2026 |
CodeAstro Online Job Portal 1.0 /admin/jobs-admins/delete-jobs.php ID SQLiA vulnerability was detected in CodeAstro Online Job Portal 1.0. The impacted element is an unknown function of the file /admin/jobs-admins/delete-jobs.php. Performing a manipulation of the argument ID results in sql injection. It is possible to initiate the attack remotely. The exploit is now public and may be used. |
|
| CVE-2026-10235 | Jun 01, 2026 |
CodeAstro Ingredients Stock Mgmt Sys 1.0 SQLi via stock_manager.phpA flaw has been found in CodeAstro Ingredients Stock Management System 1.0. This vulnerability affects unknown code of the file /Ingredients-Stock/stock_manager.php. This manipulation of the argument txt_search_category causes sql injection. The attack may be initiated remotely. The exploit has been published and may be used. |
|
| CVE-2026-9542 | May 26, 2026 |
CodeAstro LMS 1.0 SQL Injection in /admin/add_staff.php via email_idA weakness has been identified in CodeAstro Leave Management System 1.0. The affected element is an unknown function of the file /admin/add_staff.php. Executing a manipulation of the argument email_id can lead to sql injection. The attack can be launched remotely. The exploit has been made available to the public and could be used for attacks. |
|