Codezips Gym Management System
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in Codezips Gym Management System.
By the Year
In 2026 there have been 0 vulnerabilities in Codezips Gym Management System. Last year, in 2025 Gym Management System had 16 security vulnerabilities published. Right now, Gym Management System is on track to have less security vulnerabilities in 2026 than it did last year.
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 0 | 0.00 |
| 2025 | 16 | 9.53 |
It may take a day or so for new Gym Management System vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent Codezips Gym Management System Security Vulnerabilities
CodeZips Gym Management Sys v1.0: SQLi in deleteroutine.php 'name'
CVE-2025-29208
- April 01, 2025
CodeZips Gym Management System v1.0 is vulnerable to SQL injection in the name parameter within /dashboard/admin/deleteroutine.php.
Critical SQLi in Codezips Gym Management System 1.0 via over_month.php mm
CVE-2025-2847
8.8 - High
- March 27, 2025
A vulnerability, which was classified as critical, has been found in Codezips Gym Management System 1.0. This issue affects some unknown processing of the file /dashboard/admin/over_month.php. The manipulation of the argument mm leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
SQL Injection
Codezips Gym Management System 1.0 - /change_s_pwd.php Arbitrary SQLi
CVE-2025-1959
9.8 - Critical
- March 04, 2025
A vulnerability, which was classified as critical, was found in Codezips Gym Management System 1.0. Affected is an unknown function of the file /change_s_pwd.php. The manipulation of the argument login_id/login_key leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
SQL Injection
Codezips Gym Mgmt Sys 1.0 SQLi in gen_invoice.php ID
CVE-2025-1856
9.8 - Critical
- March 03, 2025
A vulnerability was found in Codezips Gym Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /dashboard/admin/gen_invoice.php. The manipulation of the argument id leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
SQL Injection
Codezips GymMgmt 1.0 Remote SQLi via admin/del_member.php (CVE-2025-1854)
CVE-2025-1854
8.8 - High
- March 03, 2025
A vulnerability was found in Codezips Gym Management System 1.0. It has been classified as critical. Affected is an unknown function of the file /dashboard/admin/del_member.php. The manipulation of the argument name leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
SQL Injection
Codezips Gym Management System 1.0 - /dashboard/admin/del_plan.php SQLi Remote
CVE-2025-1380
9.8 - Critical
- February 17, 2025
A vulnerability was found in Codezips Gym Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /dashboard/admin/del_plan.php. The manipulation of the argument name leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
SQL Injection
Codezips Gym 1.0 Remote SQLi in /dashboard/admin/viewdetailroutine.php
CVE-2025-1206
8.8 - High
- February 12, 2025
A vulnerability was found in Codezips Gym Management System 1.0. It has been classified as critical. This affects an unknown part of the file /dashboard/admin/viewdetailroutine.php. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
SQL Injection
SQLi via tid in updateroutine.php of Codezips Gym Management System 1.0
CVE-2025-1188
9.8 - Critical
- February 12, 2025
A vulnerability, which was classified as critical, has been found in Codezips Gym Management System 1.0. Affected by this issue is some unknown functionality of the file /dashboard/admin/updateroutine.php. The manipulation of the argument tid leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
SQL Injection
CodeZips Gym Mgt Sys 1.0 - Remote SQLi via login_id in more-userprofile.php
CVE-2025-1183
9.8 - Critical
- February 12, 2025
A vulnerability has been found in CodeZips Gym Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /dashboard/admin/more-userprofile.php. The manipulation of the argument login_id leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
SQL Injection
Codezips Gym Mgt Sys 1.0: Critical SQLi in /dashboard/admin/updateplan.php
CVE-2025-0880
9.8 - Critical
- January 30, 2025
A vulnerability was found in Codezips Gym Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /dashboard/admin/updateplan.php. The manipulation of the argument planid leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
SQL Injection
Codezips Gym 1.0: SQLi via /dashboard/admin/saveroutine.php rname
CVE-2025-0881
9.8 - Critical
- January 30, 2025
A vulnerability was found in Codezips Gym Management System 1.0. It has been classified as critical. Affected is an unknown function of the file /dashboard/admin/saveroutine.php. The manipulation of the argument rname leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
SQL Injection
SQLi in Codezips GymMgmt 1.0 admin/health_status_entry.php (critical)
CVE-2025-0562
9.8 - Critical
- January 19, 2025
A vulnerability was found in Codezips Gym Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /dashboard/admin/health_status_entry.php. The manipulation of the argument usrid leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
SQL Injection
Codezips Gym Management System 1.0 SQLi in /dashboard/admin/edit_member.php
CVE-2025-0541
9.8 - Critical
- January 17, 2025
A vulnerability was found in Codezips Gym Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /dashboard/admin/edit_member.php. The manipulation of the argument name leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well.
SQL Injection
Codezips Gym Management 1.0 SQLi via uid in edit_mem_submit.php
CVE-2025-0535
9.8 - Critical
- January 17, 2025
A vulnerability classified as critical has been found in Codezips Gym Management System 1.0. This affects an unknown part of the file /dashboard/admin/edit_mem_submit.php. The manipulation of the argument uid leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
SQL Injection
Codezips Gym Management Sys 1.0 SQLi via m_id (admin/new_submit.php)
CVE-2025-0532
9.8 - Critical
- January 17, 2025
A vulnerability was found in Codezips Gym Management System 1.0. It has been classified as critical. Affected is an unknown function of the file /dashboard/admin/new_submit.php. The manipulation of the argument m_id leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
SQL Injection
Codezips Gym Management System 1.0 SQLi via m_id in submit_payments.php
CVE-2025-0231
8.8 - High
- January 05, 2025
A vulnerability has been found in Codezips Gym Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /dashboard/admin/submit_payments.php. The manipulation of the argument m_id leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
SQL Injection
Stay on top of Security Vulnerabilities
Want an email whenever new vulnerabilities are published for Codezips Gym Management System or by Codezips? Click the Watch button to subscribe.