Vendor
CodeAstro vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 56 vulnerabilities in CodeAstro: 1 in the last 7 days and 28 in the last 90 days, 2 of them critical and 0 exploited in the wild. The most recent, CVE-2026-94048, was published on 20 September 2026. 8 technologies have a page of their own.
- Last 7 days
- 1
- Last 90 days
- 28
- Critical, all time
- 2
- Exploited in the wild
- 0
About CodeAstro
CodeAstro is an organization that develops and provides open-source web application projects for educational and development purposes.
CodeAstro technologies
Latest CodeAstro vulnerabilities
- CVE-2026-94048: CodeAstro QR Code Attendance Management System privilege escalationmediumCVSS 6.6EPSS 0.4%
- CVE-2026-77020: CodeAstro Apartment Visitor Management System SQL injection in password-recovery.phphighCVSS 7.3EPSS 0.4%
- CVE-2026-77019: CodeAstro Apartment Visitor Management System SQL injection in forgotpw.phphighCVSS 7.3EPSS 0.4%
- CVE-2025-69938: CodeAstro Membership Management System SQL injection in renew.phpinfoCVSS 7.5
- CVE-2025-69937: CodeAstro Membership Management System SQL injection in edit_type.phpinfo
- CVE-2025-69936: CodeAstro Membership Management System SQL injection in edit_member.phpinfoCVSS 7.5
- CVE-2025-69935: CodeAstro Membership Management System SQL injection in reporting modulesinfo
- CVE-2025-69934: CodeAstro Membership Management System SQL injection in delete_members.phpinfo
- CVE-2025-69933: CodeAstro Membership Management System SQL injection in memberProfile.phpinfo
- CVE-2025-69931: CodeAstro Membership Management System SQL injection in delete_membership.phpinfoCVSS 7.5
- CVE-2025-69930: CodeAstro Membership Management System SQL injection in print_membership_card.phpinfoCVSS 7.5
- CVE-2026-16765: CodeAstro Online Classroom SQL injection in loginlinkadmin.phphighCVSS 7.3
- CVE-2026-15559: CodeAstro Simple Online Leave Management System SQL injection in accept.phpmediumCVSS 6.3
- CVE-2026-15558: CodeAstro Simple Online Leave Management System SQL injection in deletemp.phpmediumCVSS 6.3
- CVE-2026-15523: CodeAstro Simple Online Leave Management System SQL injection in dashboard.phpmediumCVSS 6.3
- CVE-2026-15134: CodeAstro Simple Online Leave Management System SQL injection in index.phphighCVSS 7.3
- CVE-2026-14799: CodeAstro Ecommerce Website SQL injection in my_account.phpmediumCVSS 6.3
- CVE-2026-14798: CodeAstro Apartment Visitor Management System SQL injection in visitor-entry.phpmediumCVSS 6.3
- CVE-2026-14797: CodeAstro Apartment Visitor Management System SQL injection in edit-apartment.phpmediumCVSS 6.3
- CVE-2026-14796: CodeAstro Apartment Visitor Management System SQL injection in report.phpmediumCVSS 6.3
- CVE-2026-14795: CodeAstro Apartment Visitor Management System SQL injection in action-visitor.phpmediumCVSS 6.3
- CVE-2026-14767: CodeAstro Ecommerce Website SQL injection in confirm.phpmediumCVSS 6.3
- CVE-2026-14766: CodeAstro Apartment Visitor Management System SQL injection in search-result.phpmediumCVSS 6.3
- CVE-2026-14689: CodeAstro Apartment Visitor Management System SQL injection in add-apartment.phpmediumCVSS 6.3
- CVE-2026-14640: CodeAstro Apartment Visitor Management System SQL injection in LoginhighCVSS 7.3
Most severe CodeAstro vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2025-70150: CodeAstro Membership Management System missing authentication and SQL injection in delete_members.phpcriticalCVSS 9.8EPSS 0.7%
- CVE-2025-70149: CodeAstro Membership Management System SQL injection in print_membership_card.phpcriticalCVSS 9.8EPSS 0.4%
- CVE-2025-70148: CodeAstro Membership Management System insecure direct object reference in print_membership_card.phphighCVSS 7.5EPSS 0.4%
- CVE-2026-77020: CodeAstro Apartment Visitor Management System SQL injection in password-recovery.phphighCVSS 7.3EPSS 0.4%
- CVE-2026-77019: CodeAstro Apartment Visitor Management System SQL injection in forgotpw.phphighCVSS 7.3EPSS 0.4%
- CVE-2026-16765: CodeAstro Online Classroom SQL injection in loginlinkadmin.phphighCVSS 7.3
- CVE-2026-15134: CodeAstro Simple Online Leave Management System SQL injection in index.phphighCVSS 7.3
- CVE-2026-14640: CodeAstro Apartment Visitor Management System SQL injection in LoginhighCVSS 7.3
- CVE-2026-11582: CodeAstro Student Attendance Management System SQL injection in index.phphighCVSS 7.3
- CVE-2026-10261: CodeAstro Online Job Portal SQL injection in application_status.phphighCVSS 7.3
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 7 | 0 | |
| 6 Jul 2026 | 6 | 0 | |
| 13 Jul 2026 | 3 | 0 | |
| 20 Jul 2026 | 1 | 0 | |
| 27 Jul 2026 | 8 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 2 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 1 | 0 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/vendors/codeastro.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "CodeAstro vulnerabilities", https://junglewise.ai/threats/vendors/codeastro, 26 September 2026.