Codeastro Codeastro

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in any Codeastro product.

RSS Feeds for Codeastro security vulnerabilities

Create a CVE RSS feed including security vulnerabilities found in Codeastro products with stack.watch. Just hit watch, then grab your custom RSS feed url.

Products by Codeastro Sorted by Most Security Vulnerabilities since 2018

Codeastro Ecommerce Website4 vulnerabilities

Codeastro Online Job Portal3 vulnerabilities

Codeastro Payroll System3 vulnerabilities

Codeastro Car Rental System2 vulnerabilities

By the Year

In 2026 there have been 72 vulnerabilities in Codeastro with an average score of 6.4 out of ten. Last year, in 2025 Codeastro had 48 security vulnerabilities published. That is, 24 more vulnerabilities have already been reported in 2026 as compared to last year. Last year, the average CVE base score was greater by 0.37




Year Vulnerabilities Average Score
2026 72 6.40
2025 48 6.77
2024 45 7.24
2023 7 6.91
2022 2 6.05

It may take a day or so for new Codeastro vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Codeastro Security Vulnerabilities

CVE Date Vulnerability Products
CVE-2026-77681 Aug 21, 2026
CodeAstro 1.0 Unrestricted File Upload via Name param in update-profile.php A vulnerability was identified in CodeAstro Online Job Portal 1.0. Affected by this vulnerability is an unknown functionality of the file /users/update-profile.php. The manipulation of the argument Name leads to unrestricted upload. The attack can be initiated remotely. The exploit is publicly available and might be used.
Online Job Portal
CVE-2026-77020 Aug 20, 2026
SQLi in CodeAstro A2MS 1.0 via 'password-recovery.php' email A vulnerability was identified in CodeAstro Apartment Visitor Management System 1.0. Affected by this vulnerability is an unknown functionality of the file password-recovery.php. The manipulation of the argument email leads to sql injection. Remote exploitation of the attack is possible. The exploit is publicly available and might be used.
Apartment Visitor Management System
CVE-2026-77019 Aug 20, 2026
CodeAstro Apartment Visitor Mgmt 1.0: SQLi via secode in forgotpw.php A vulnerability was determined in CodeAstro Apartment Visitor Management System 1.0. Affected is an unknown function of the file /apartment-visitor/forgotpw.php. Executing a manipulation of the argument secode can lead to sql injection. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized.
Apartment Visitor Management System
CVE-2025-69933 Jul 30, 2026
SQLi in CodeAstro Membership Management Sys 1.0 /memberProfile.php CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /memberProfile.php?id=1.
Membership Management System
CVE-2025-69934 Jul 30, 2026
CodeAstro Membership Management System 1.0: SQLI /delete_members.php id CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /delete_members.php?id=1.
Membership Management System
CVE-2025-69935 Jul 30, 2026
SQLi in report.php of CodeAstro Membership Management System 1.0 CodeAstro Membership Management System 1.0 is vulnerale to SQL Injection in the report.php and revenue_report.php via the fromDate parameter.
Membership Management System
CVE-2025-69936 Jul 30, 2026
CodeAstro Membership Sys 1.0 - SQLi in edit_member.php CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /edit_member.php?id=1.
Membership Management System
CVE-2025-69937 Jul 30, 2026
CodeAstro Membership Management Sys 1.0 SQLi via edit_type.php (id param) CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in the edit_type.php endpoint via the Parameter id.
Membership Management System
CVE-2026-16765 Jul 23, 2026
CodeAstro Online Classroom 1.0 SQLi via /OnlineClassroom/loginlinkadmin.php A vulnerability was determined in CodeAstro Online Classroom 1.0. Affected by this issue is some unknown functionality of the file /OnlineClassroom/loginlinkadmin.php. Executing a manipulation of the argument aid can lead to sql injection. The attack can be executed remotely. The exploit has been publicly disclosed and may be utilized.
Online Classroom
CVE-2026-15559 Jul 13, 2026
CodeAstro Simple Online Leave Mgmt 1.0 SQLi via POST Handler (appid) A vulnerability was detected in CodeAstro Simple Online Leave Management System 1.0. This affects an unknown part of the file /SimpleOnlineLeave/admin/accept.php of the component POST Handler. Performing a manipulation of the argument appid results in sql injection. The attack is possible to be carried out remotely. The exploit is now public and may be used.
Simple Online Leave Management System
CVE-2026-15558 Jul 13, 2026
CodeAstro Simple Online Leave Mgmt 1.0: SQLi via deletemp.php A security vulnerability has been detected in CodeAstro Simple Online Leave Management System 1.0. Affected by this issue is some unknown functionality of the file /SimpleOnlineLeave/admin/deletemp.php. Such manipulation of the argument ID leads to sql injection. The attack can be executed remotely. The exploit has been disclosed publicly and may be used.
Simple Online Leave Management System
CVE-2026-15523 Jul 13, 2026
Remote SQLi in CodeAstro Simple Online Leave Mgmt 1.0 admin/dashboard.php A weakness has been identified in CodeAstro Simple Online Leave Management System 1.0. Affected by this issue is some unknown functionality of the file /SimpleOnlineLeave/admin/dashboard.php. This manipulation of the argument Name causes sql injection. The attack can be initiated remotely. The exploit has been made available to the public and could be used for attacks.
Simple Online Leave Management System
CVE-2026-15134 Jul 08, 2026
SQLi in CodeAstro Simple Online Leave Mgt. Sys 1.0 (/index.php) via email A vulnerability was determined in CodeAstro Simple Online Leave Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /SimpleOnlineLeave/index.php. Executing a manipulation of the argument email can lead to sql injection. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized.
Simple Online Leave Management System
CVE-2026-14799 Jul 06, 2026
CodeAstro Ecommerce 1.0 Remote SQLi via my_wishlist delete_wishlist A security flaw has been discovered in CodeAstro Ecommerce Website 1.0. Impacted is an unknown function of the file /customer/my_account.php?my_wishlist. The manipulation of the argument delete_wishlist results in sql injection. The attack can be launched remotely. The exploit has been released to the public and may be used for attacks.
Ecommerce Website
CVE-2026-14798 Jul 06, 2026
SQL Injection in CodeAstro A/VMS 1.0 via visname in visitor-entry.php A vulnerability was identified in CodeAstro Apartment Visitor Management System 1.0. This issue affects some unknown processing of the file /apartment-visitor/visitor-entry.php. The manipulation of the argument visname leads to sql injection. The attack can be initiated remotely. The exploit is publicly available and might be used.
Apartment Visitor Management System
CVE-2026-14797 Jul 06, 2026
CodeAstro A/VMS 1.0: Remote SQLi via editid in edit-apartment.php A vulnerability was determined in CodeAstro Apartment Visitor Management System 1.0. This vulnerability affects unknown code of the file /apartment-visitor/edit-apartment.php. Executing a manipulation of the argument editid can lead to sql injection. It is possible to launch the attack remotely. The exploit has been publicly disclosed and may be utilized.
Apartment Visitor Management System
CVE-2026-14796 Jul 06, 2026
CodeAstro Apartment VisitMgmt 1.0 SQLi via /report.php fromdate A vulnerability was found in CodeAstro Apartment Visitor Management System 1.0. This affects an unknown part of the file /apartment-visitor/report.php. Performing a manipulation of the argument fromdate results in sql injection. It is possible to initiate the attack remotely. The exploit has been made public and could be used.
Apartment Visitor Management System
CVE-2026-14795 Jul 06, 2026
CodeAstro Apartment Visitor Mgmt 1.0 Remote SQLi via action-visitor.php A vulnerability has been found in CodeAstro Apartment Visitor Management System 1.0. Affected by this issue is some unknown functionality of the file /apartment-visitor/action-visitor.php. Such manipulation of the argument remark leads to sql injection. The attack may be performed from remote. The exploit has been disclosed to the public and may be used.
Apartment Visitor Management System
CVE-2026-14767 Jul 05, 2026
SQLi in CodeAstro Ecom Site 1.0 POST Param invoice_no A security flaw has been discovered in CodeAstro Ecommerce Website 1.0. This affects an unknown part of the file /ecommerce-website-php/customer/confirm.php of the component POST Parameter Handler. The manipulation of the argument invoice_no results in sql injection. The attack can be executed remotely. The exploit has been released to the public and may be used for attacks.
Ecommerce Website
CVE-2026-14766 Jul 05, 2026
SQLi via POST Parameter Handler in CodeAstro Apt Visitor Mgmt 1.0 A vulnerability was identified in CodeAstro Apartment Visitor Management System 1.0. Affected by this issue is some unknown functionality of the file /apartment-visitor/search-result.php of the component POST Parameter Handler. The manipulation of the argument searchdata leads to sql injection. Remote exploitation of the attack is possible. The exploit is publicly available and might be used.
Apartment Visitor Management System
CVE-2026-14689 Jul 05, 2026
SQLi in CodeAstro Apartment Visitor Management 1.0 add-apartment.php via apartmentno A security flaw has been discovered in CodeAstro Apartment Visitor Management System 1.0. The impacted element is an unknown function of the file /apartment-visitor/add-apartment.php. The manipulation of the argument apartmentno results in sql injection. The attack may be launched remotely. The exploit has been released to the public and may be used for attacks.
Apartment Visitor Management System
CVE-2026-14640 Jul 04, 2026
CodeAstro Appt Visitor Mgmt Sys 1.0 Remote SQLi via Login Username A vulnerability was found in CodeAstro Apartment Visitor Management System 1.0. Affected is an unknown function of the file /index.php of the component Login. Performing a manipulation of the argument Username results in sql injection. Remote exploitation of the attack is possible. The exploit has been made public and could be used.
Apartment Visitor Management System
CVE-2026-14639 Jul 04, 2026
CodeAstro Ecommerce 1.0 my_account.php c_name SQLi A vulnerability has been found in CodeAstro Ecommerce Website 1.0. This impacts an unknown function of the file /ecommerce-website-php/customer/my_account.php?edit_account. Such manipulation of the argument c_name leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
Ecommerce Website
CVE-2026-13558 Jun 29, 2026
CodeAstro 1.0 - XSS in /report/addreport Report Title via Report Handler A security flaw has been discovered in CodeAstro Complaint Management System 1.0. This issue affects some unknown processing of the file /report/addreport of the component Report Handler. Performing a manipulation of the argument Report Title results in cross site scripting. Remote exploitation of the attack is possible. The exploit has been released to the public and may be used for attacks.
Complaint Management System
CVE-2026-13549 Jun 29, 2026
CodeAstro CMS v1.0 Auth Bypass in Report Endpoint via deletereport A security flaw has been discovered in CodeAstro Complaint Management System 1.0. The affected element is the function deletereport of the file application/controllers/Report.php of the component Report Endpoint. The manipulation results in authorization bypass. The attack can be executed remotely. The exploit has been released to the public and may be used for attacks.
Complaint Management System
CVE-2026-13537 Jun 29, 2026
CodeAstro HRMS 1.0 CSRF Vulnerability (Remote Exploit) A vulnerability was found in CodeAstro Human Resource Management System 1.0. Impacted is an unknown function. The manipulation results in cross-site request forgery. The attack may be launched remotely. The exploit has been made public and could be used.
Human Resource Management System
CVE-2026-13535 Jun 29, 2026
CodeAstro HRMS 1.0 ViewEndpoint SQLi via GetFileInfo(ID) A flaw has been found in CodeAstro Human Resource Management System 1.0. This vulnerability affects the function GetFileInfo of the file hrsystem/application/models/Employee_model.php of the component View Endpoint. Executing a manipulation of the argument ID can lead to sql injection. The attack can be launched remotely. The exploit has been published and may be used.
Human Resource Management System
CVE-2026-13525 Jun 29, 2026
CodeAstro HRMS 1.0 SQL Injection via Update_Earn_Leave Endpoint A vulnerability was detected in CodeAstro Human Resource Management System 1.0. This issue affects the function emselectByCode of the file application/models/Employee_model.php of the component Update_Earn_Leave Endpoint. The manipulation of the argument emid results in sql injection. The attack can be launched remotely. The exploit is now public and may be used.
Human Resource Management System
CVE-2026-12175 Jun 13, 2026
SQLi in CodeAstro Student Attendance Management System 1.0 createStudents.php A vulnerability was detected in CodeAstro Student Attendance Management System 1.0. Impacted is an unknown function of the file /attendance-php/Admin/createStudents.php. Performing a manipulation of the argument admissionNumber results in sql injection. Remote exploitation of the attack is possible. The exploit is now public and may be used.
Student Attendance Management System
CVE-2026-12131 Jun 12, 2026
CodeAstro HRMS 1.0: Payroll Invoice ID SQLi A weakness has been identified in CodeAstro Human Resource Management System 1.0. This vulnerability affects the function Invoice of the file \application\controllers\Payroll.php of the component Payroll Invoice Module. This manipulation of the argument ID causes sql injection. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be used for attacks.
Human Resource Management System
CVE-2026-12130 Jun 12, 2026
CodeAstro HRM 1.0 N: XSS via protitle on /Projects/Add_Projects A security flaw has been discovered in CodeAstro Human Resource Management System 1.0. This affects an unknown part of the file /Projects/Add_Projects of the component Projects Management Page. The manipulation of the argument protitle results in cross site scripting. The attack may be launched remotely. The exploit has been released to the public and may be used for attacks.
Human Resource Management System
CVE-2026-12129 Jun 12, 2026
XSS in Dashboard Interface of CodeAstro HRMS 1.0 (before 1.1) A vulnerability was identified in CodeAstro Human Resource Management System 1.0. Affected by this issue is some unknown functionality of the file /dashboard/add_tod of the component Dashboard Interface. The manipulation of the argument todo_data leads to cross site scripting. The attack may be initiated remotely. The exploit is publicly available and might be used.
Human Resource Management System
CVE-2026-11585 Jun 08, 2026
CVE-2026-11585 SQLi via classId in CodeAstro 1.0 Admin/createClassArms.php A vulnerability was determined in CodeAstro Student Attendance Management System 1.0. Affected is an unknown function of the file /attendance-php/Admin/createClassArms.php. This manipulation of the argument classId causes sql injection. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized.
Student Attendance Management System
CVE-2026-11584 Jun 08, 2026
SQLi in CodeAstro Student Att. System 1.0 (createClass.php ID) A vulnerability was found in CodeAstro Student Attendance Management System 1.0. This impacts an unknown function of the file /attendance-php/Admin/createClass.php?action=edit. The manipulation of the argument ID results in sql injection. It is possible to launch the attack remotely. The exploit has been made public and could be used.
Student Attendance Management System
CVE-2026-11583 Jun 08, 2026
CodeAstro Student Attendance 1.0 SQLi via className in createClass.php A vulnerability has been found in CodeAstro Student Attendance Management System 1.0. This affects an unknown function of the file /attendance-php/Admin/createClass.php. The manipulation of the argument className leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
Student Attendance Management System
CVE-2026-11582 Jun 08, 2026
CodeAstro Student Attendance MS 1.0 SQLi via Username (remote) A flaw has been found in CodeAstro Student Attendance Management System 1.0. The impacted element is an unknown function of the file /attendance-php/index.php. Executing a manipulation of the argument Username can lead to sql injection. The attack may be performed from remote. The exploit has been published and may be used.
Student Attendance Management System
CVE-2026-11559 Jun 08, 2026
CodeAstro Payroll System 1.0 SQLi via /view_account.php ID A vulnerability was detected in CodeAstro Payroll System 1.0. This affects an unknown function of the file /view_account.php. The manipulation of the argument ID results in sql injection. The attack may be performed from remote. The exploit is now public and may be used.
Payroll System
CVE-2026-11558 Jun 08, 2026
Remote SQLi via rate/salary_rate in CodeAstro Payroll 1.0 A security vulnerability has been detected in CodeAstro Payroll System 1.0. The impacted element is an unknown function of the file /home_salary.php. The manipulation of the argument rate/salary_rate leads to sql injection. The attack is possible to be carried out remotely. The exploit has been disclosed publicly and may be used.
Payroll System
CVE-2026-11510 Jun 08, 2026
Remote SQLi via admin/add_leave.php in CodeAstro LMT 1.0 A security flaw has been discovered in CodeAstro Leave Management System 1.0. This affects an unknown part of the file /admin/add_leave.php. Performing a manipulation of the argument type_of_leave results in sql injection. It is possible to initiate the attack remotely. The exploit has been released to the public and may be used for attacks.
Leave Management System
CVE-2026-11509 Jun 08, 2026
CodeAstro LSM 1.0 SQLi in search_staff_for_updation.php A vulnerability was identified in CodeAstro Leave Management System 1.0. Affected by this issue is some unknown functionality of the file /admin/search_staff_for_updation.php. Such manipulation of the argument Name leads to sql injection. The attack may be performed from remote.
Leave Management System
CVE-2026-11508 Jun 08, 2026
CodeAstro LMS 1.0 Remote SQLi via /admin/search_staff_to_assign_pc.php A vulnerability was determined in CodeAstro Leave Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/search_staff_to_assign_pc.php. This manipulation of the argument Name causes sql injection. The attack is possible to be carried out remotely. The exploit has been publicly disclosed and may be utilized.
Leave Management System
CVE-2026-11507 Jun 08, 2026
CodeAstro Leave Management System 1.0 - SQLi via /admin/delete_leave_type.php A vulnerability was found in CodeAstro Leave Management System 1.0. Affected is an unknown function of the file /admin/delete_leave_type.php. The manipulation of the argument leave_type results in sql injection. The attack can be executed remotely. The exploit has been made public and could be used.
Leave Management System
CVE-2026-11506 Jun 08, 2026
CVE-2026-11506: SQLi in CodeAstro LeaveMgmt 1.0/admin/search_staff_for_deletion.php A vulnerability has been found in CodeAstro Leave Management System 1.0. This impacts an unknown function of the file /admin/search_staff_for_deletion.php. The manipulation of the argument Name leads to sql injection. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used.
Leave Management System
CVE-2026-11495 Jun 08, 2026
SQLi in CodeAstro Ingredients Stock Mgmt Sys 1.0 via ID in add_stock.php A vulnerability was detected in CodeAstro Ingredients Stock Management System 1.0. This impacts an unknown function of the file /Ingredients-Stock/add_stock.php. The manipulation of the argument ID results in sql injection. The attack may be launched remotely. The exploit is now public and may be used.
Ingredients Stock Management System
CVE-2026-11491 Jun 08, 2026
CodeAstro HRMS 1.0 XSS Vulnerability in Notice Board Management A vulnerability was identified in CodeAstro Human Resource Management System 1.0. Impacted is an unknown function of the file /notice/All_notice of the component Notice Board Management. Such manipulation of the argument Notice Title with the input <svg onload="alert('Stored XSS Triggered by Ashik Mohamed')"> as part of POST leads to cross site scripting. It is possible to launch the attack remotely. The exploit is publicly available and might be used.
Human Resource Management System
CVE-2026-10286 Jun 01, 2026
CodeAstro Payroll System 1.0 SQLi via emp_id in /home_employee.php A vulnerability was found in CodeAstro Payroll System 1.0. This affects an unknown part of the file /home_employee.php. The manipulation of the argument emp_id results in sql injection. The attack may be performed from remote. The exploit has been made public and could be used.
Payroll System
CVE-2026-10261 Jun 01, 2026
SQL Injection in CodeAstro Online Job Portal 1.0 /users/application_status.php A flaw has been found in CodeAstro Online Job Portal 1.0. This affects an unknown function of the file /users/application_status.php. Executing a manipulation of the argument ID can lead to sql injection. It is possible to launch the attack remotely. The exploit has been published and may be used.
Online Job Portal
CVE-2026-10260 Jun 01, 2026
CodeAstro Online Job Portal 1.0 /admin/jobs-admins/delete-jobs.php ID SQLi A vulnerability was detected in CodeAstro Online Job Portal 1.0. The impacted element is an unknown function of the file /admin/jobs-admins/delete-jobs.php. Performing a manipulation of the argument ID results in sql injection. It is possible to initiate the attack remotely. The exploit is now public and may be used.
Online Job Portal
CVE-2026-10235 Jun 01, 2026
CodeAstro Ingredients Stock Mgmt Sys 1.0 SQLi via stock_manager.php A flaw has been found in CodeAstro Ingredients Stock Management System 1.0. This vulnerability affects unknown code of the file /Ingredients-Stock/stock_manager.php. This manipulation of the argument txt_search_category causes sql injection. The attack may be initiated remotely. The exploit has been published and may be used.
Ingredients Stock Management System
CVE-2026-9542 May 26, 2026
CodeAstro LMS 1.0 SQL Injection in /admin/add_staff.php via email_id A weakness has been identified in CodeAstro Leave Management System 1.0. The affected element is an unknown function of the file /admin/add_staff.php. Executing a manipulation of the argument email_id can lead to sql injection. The attack can be launched remotely. The exploit has been made available to the public and could be used for attacks.
Leave Management System
Built by Foundeo Inc., with data from the National Vulnerability Database (NVD). Privacy Policy. Use of this site is governed by the Legal Terms
Disclaimer
CONTENT ON THIS WEBSITE IS PROVIDED ON AN "AS IS" BASIS AND DOES NOT IMPLY ANY KIND OF GUARANTEE OR WARRANTY, INCLUDING THE WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR USE. YOUR USE OF THE INFORMATION ON THE DOCUMENT OR MATERIALS LINKED FROM THE DOCUMENT IS AT YOUR OWN RISK. Always check with your vendor for the most up to date, and accurate information.