{"schema_version":1,"title":"CodeAstro vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 56 vulnerabilities in CodeAstro: 1 in the last 7 days and 28 in the last 90 days, 2 of them critical and 0 exploited in the wild. The most recent, CVE-2026-94048, was published on 20 September 2026. 8 technologies have a page of their own.","url":"https://junglewise.ai/threats/vendors/codeastro","json_url":"https://junglewise.ai/threats/vendors/codeastro.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/vendors/codeastro","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"vendor","counts":{"high":9,"all_time":56,"critical":2,"exploited":0,"last_7_days":1,"last_30_days":1,"last_90_days":28,"last_365_days":56},"latest":[{"cve":"CVE-2026-94048","cvss":6.6,"epss":0.004,"slug":"cve-2026-94048-a-vulnerability-was-detected-in-codeastro-qr-code-attendance","title":"CodeAstro QR Code Attendance Management System privilege escalation","severity":"medium","exploited":false,"published_at":"2026-09-20T20:16:54.51+00:00","url":"https://junglewise.ai/threats/cve-2026-94048-a-vulnerability-was-detected-in-codeastro-qr-code-attendance"},{"cve":"CVE-2026-77020","cvss":7.3,"epss":0.0043,"slug":"cve-2026-77020-codeastro-apartment-visitor-management-system-sql-injection-in","title":"CodeAstro Apartment Visitor Management System SQL injection in password-recovery.php","severity":"high","exploited":false,"published_at":"2026-08-20T17:19:49.237+00:00","url":"https://junglewise.ai/threats/cve-2026-77020-codeastro-apartment-visitor-management-system-sql-injection-in"},{"cve":"CVE-2026-77019","cvss":7.3,"epss":0.0043,"slug":"cve-2026-77019-codeastro-apartment-visitor-management-system-sql-injection-in","title":"CodeAstro Apartment Visitor Management System SQL injection in forgotpw.php","severity":"high","exploited":false,"published_at":"2026-08-20T17:19:49.063+00:00","url":"https://junglewise.ai/threats/cve-2026-77019-codeastro-apartment-visitor-management-system-sql-injection-in"},{"cve":"CVE-2025-69938","cvss":7.5,"slug":"cve-2025-69938-codeastro-membership-management-system-sql-injection-in-renew-php","title":"CodeAstro Membership Management System SQL injection in renew.php","severity":"info","exploited":false,"published_at":"2026-07-30T21:16:52.67+00:00","url":"https://junglewise.ai/threats/cve-2025-69938-codeastro-membership-management-system-sql-injection-in-renew-php"},{"cve":"CVE-2025-69937","slug":"cve-2025-69937-codeastro-membership-management-system-sql-injection-in-edit-type","title":"CodeAstro Membership Management System SQL injection in edit_type.php","severity":"info","exploited":false,"published_at":"2026-07-30T21:16:52.563+00:00","url":"https://junglewise.ai/threats/cve-2025-69937-codeastro-membership-management-system-sql-injection-in-edit-type"},{"cve":"CVE-2025-69936","cvss":7.5,"slug":"cve-2025-69936-codeastro-membership-management-system-sql-injection-in-edit","title":"CodeAstro Membership Management System SQL injection in edit_member.php","severity":"info","exploited":false,"published_at":"2026-07-30T21:16:52.453+00:00","url":"https://junglewise.ai/threats/cve-2025-69936-codeastro-membership-management-system-sql-injection-in-edit"},{"cve":"CVE-2025-69935","slug":"cve-2025-69935-codeastro-membership-management-system-sql-injection-in-reporting","title":"CodeAstro Membership Management System SQL injection in reporting modules","severity":"info","exploited":false,"published_at":"2026-07-30T21:16:52.333+00:00","url":"https://junglewise.ai/threats/cve-2025-69935-codeastro-membership-management-system-sql-injection-in-reporting"},{"cve":"CVE-2025-69934","slug":"cve-2025-69934-codeastro-membership-management-system-sql-injection-in-delete","title":"CodeAstro Membership Management System SQL injection in delete_members.php","severity":"info","exploited":false,"published_at":"2026-07-30T21:16:52.223+00:00","url":"https://junglewise.ai/threats/cve-2025-69934-codeastro-membership-management-system-sql-injection-in-delete"},{"cve":"CVE-2025-69933","slug":"cve-2025-69933-codeastro-membership-management-system-sql-injection-in","title":"CodeAstro Membership Management System SQL injection in memberProfile.php","severity":"info","exploited":false,"published_at":"2026-07-30T21:16:52.12+00:00","url":"https://junglewise.ai/threats/cve-2025-69933-codeastro-membership-management-system-sql-injection-in"},{"cve":"CVE-2025-69931","cvss":7.5,"slug":"cve-2025-69931-codeastro-membership-management-system-sql-injection-in-delete","title":"CodeAstro Membership Management System SQL injection in delete_membership.php","severity":"info","exploited":false,"published_at":"2026-07-30T21:16:52.007+00:00","url":"https://junglewise.ai/threats/cve-2025-69931-codeastro-membership-management-system-sql-injection-in-delete"},{"cve":"CVE-2025-69930","cvss":7.5,"slug":"cve-2025-69930-codeastro-membership-management-system-sql-injection-in-print","title":"CodeAstro Membership Management System SQL injection in print_membership_card.php","severity":"info","exploited":false,"published_at":"2026-07-30T21:16:51.893+00:00","url":"https://junglewise.ai/threats/cve-2025-69930-codeastro-membership-management-system-sql-injection-in-print"},{"cve":"CVE-2026-16765","cvss":7.3,"slug":"cve-2026-16765-codeastro-online-classroom-sql-injection-in-loginlinkadmin-php","title":"CodeAstro Online Classroom SQL injection in loginlinkadmin.php","severity":"high","exploited":false,"published_at":"2026-07-23T22:16:52.25+00:00","url":"https://junglewise.ai/threats/cve-2026-16765-codeastro-online-classroom-sql-injection-in-loginlinkadmin-php"},{"cve":"CVE-2026-15559","cvss":6.3,"slug":"cve-2026-15559-codeastro-simple-online-leave-management-system-sql-injection-in","title":"CodeAstro Simple Online Leave Management System SQL injection in accept.php","severity":"medium","exploited":false,"published_at":"2026-07-13T13:16:30.41+00:00","url":"https://junglewise.ai/threats/cve-2026-15559-codeastro-simple-online-leave-management-system-sql-injection-in"},{"cve":"CVE-2026-15558","cvss":6.3,"slug":"cve-2026-15558-codeastro-simple-online-leave-management-system-sql-injection-in","title":"CodeAstro Simple Online Leave Management System SQL injection in deletemp.php","severity":"medium","exploited":false,"published_at":"2026-07-13T12:16:30.59+00:00","url":"https://junglewise.ai/threats/cve-2026-15558-codeastro-simple-online-leave-management-system-sql-injection-in"},{"cve":"CVE-2026-15523","cvss":6.3,"slug":"cve-2026-15523-codeastro-simple-online-leave-management-system-sql-injection-in","title":"CodeAstro Simple Online Leave Management System SQL injection in dashboard.php","severity":"medium","exploited":false,"published_at":"2026-07-13T03:16:16.36+00:00","url":"https://junglewise.ai/threats/cve-2026-15523-codeastro-simple-online-leave-management-system-sql-injection-in"},{"cve":"CVE-2026-15134","cvss":7.3,"slug":"cve-2026-15134-codeastro-simple-online-leave-management-system-sql-injection-in","title":"CodeAstro Simple Online Leave Management System SQL injection in index.php","severity":"high","exploited":false,"published_at":"2026-07-09T00:17:03.9+00:00","url":"https://junglewise.ai/threats/cve-2026-15134-codeastro-simple-online-leave-management-system-sql-injection-in"},{"cve":"CVE-2026-14799","cvss":6.3,"slug":"cve-2026-14799-codeastro-ecommerce-website-sql-injection-in-my-account-php","title":"CodeAstro Ecommerce Website SQL injection in my_account.php","severity":"medium","exploited":false,"published_at":"2026-07-06T06:16:27.71+00:00","url":"https://junglewise.ai/threats/cve-2026-14799-codeastro-ecommerce-website-sql-injection-in-my-account-php"},{"cve":"CVE-2026-14798","cvss":6.3,"slug":"cve-2026-14798-codeastro-apartment-visitor-management-system-sql-injection-in","title":"CodeAstro Apartment Visitor Management System SQL injection in visitor-entry.php","severity":"medium","exploited":false,"published_at":"2026-07-06T06:16:27.513+00:00","url":"https://junglewise.ai/threats/cve-2026-14798-codeastro-apartment-visitor-management-system-sql-injection-in"},{"cve":"CVE-2026-14797","cvss":6.3,"slug":"cve-2026-14797-codeastro-apartment-visitor-management-system-sql-injection-in","title":"CodeAstro Apartment Visitor Management System SQL injection in edit-apartment.php","severity":"medium","exploited":false,"published_at":"2026-07-06T06:16:27.153+00:00","url":"https://junglewise.ai/threats/cve-2026-14797-codeastro-apartment-visitor-management-system-sql-injection-in"},{"cve":"CVE-2026-14796","cvss":6.3,"slug":"cve-2026-14796-codeastro-apartment-visitor-management-system-sql-injection-in","title":"CodeAstro Apartment Visitor Management System SQL injection in report.php","severity":"medium","exploited":false,"published_at":"2026-07-06T05:16:35.223+00:00","url":"https://junglewise.ai/threats/cve-2026-14796-codeastro-apartment-visitor-management-system-sql-injection-in"},{"cve":"CVE-2026-14795","cvss":6.3,"slug":"cve-2026-14795-codeastro-apartment-visitor-management-system-sql-injection-in","title":"CodeAstro Apartment Visitor Management System SQL injection in action-visitor.php","severity":"medium","exploited":false,"published_at":"2026-07-06T05:16:35.01+00:00","url":"https://junglewise.ai/threats/cve-2026-14795-codeastro-apartment-visitor-management-system-sql-injection-in"},{"cve":"CVE-2026-14767","cvss":6.3,"slug":"cve-2026-14767-codeastro-ecommerce-website-sql-injection-in-confirm-php","title":"CodeAstro Ecommerce Website SQL injection in confirm.php","severity":"medium","exploited":false,"published_at":"2026-07-05T20:16:31.293+00:00","url":"https://junglewise.ai/threats/cve-2026-14767-codeastro-ecommerce-website-sql-injection-in-confirm-php"},{"cve":"CVE-2026-14766","cvss":6.3,"slug":"cve-2026-14766-codeastro-apartment-visitor-management-system-sql-injection-in","title":"CodeAstro Apartment Visitor Management System SQL injection in search-result.php","severity":"medium","exploited":false,"published_at":"2026-07-05T19:16:28.563+00:00","url":"https://junglewise.ai/threats/cve-2026-14766-codeastro-apartment-visitor-management-system-sql-injection-in"},{"cve":"CVE-2026-14689","cvss":6.3,"slug":"cve-2026-14689-codeastro-apartment-visitor-management-system-sql-injection-in","title":"CodeAstro Apartment Visitor Management System SQL injection in add-apartment.php","severity":"medium","exploited":false,"published_at":"2026-07-05T02:17:40.47+00:00","url":"https://junglewise.ai/threats/cve-2026-14689-codeastro-apartment-visitor-management-system-sql-injection-in"},{"cve":"CVE-2026-14640","cvss":7.3,"slug":"cve-2026-14640-codeastro-apartment-visitor-management-system-sql-injection-in","title":"CodeAstro Apartment Visitor Management System SQL injection in Login","severity":"high","exploited":false,"published_at":"2026-07-04T19:16:53.18+00:00","url":"https://junglewise.ai/threats/cve-2026-14640-codeastro-apartment-visitor-management-system-sql-injection-in"}],"vendor":{"hub":true,"name":"CodeAstro","slug":"codeastro","homepage":"https://codeastro.com/","description":"CodeAstro is an organization that develops and provides open-source web application projects for educational and development purposes.","url":"https://junglewise.ai/threats/vendors/codeastro"},"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":7},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":6},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":3},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":8},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":2},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0}],"most_severe":[{"cve":"CVE-2025-70150","cvss":9.8,"epss":0.0066,"slug":"cve-2025-70150-codeastro-membership-management-system-missing-authentication-and","title":"CodeAstro Membership Management System missing authentication and SQL injection in delete_members.php","severity":"critical","exploited":false,"published_at":"2026-02-18T18:24:20.04+00:00","url":"https://junglewise.ai/threats/cve-2025-70150-codeastro-membership-management-system-missing-authentication-and"},{"cve":"CVE-2025-70149","cvss":9.8,"epss":0.0039,"slug":"cve-2025-70149-codeastro-membership-management-system-sql-injection-in-print","title":"CodeAstro Membership Management System SQL injection in print_membership_card.php","severity":"critical","exploited":false,"published_at":"2026-02-18T17:21:36.16+00:00","url":"https://junglewise.ai/threats/cve-2025-70149-codeastro-membership-management-system-sql-injection-in-print"},{"cve":"CVE-2025-70148","cvss":7.5,"epss":0.0044,"slug":"cve-2025-70148-codeastro-membership-management-system-insecure-direct-object","title":"CodeAstro Membership Management System insecure direct object reference in print_membership_card.php","severity":"high","exploited":false,"published_at":"2026-02-18T18:24:19.79+00:00","url":"https://junglewise.ai/threats/cve-2025-70148-codeastro-membership-management-system-insecure-direct-object"},{"cve":"CVE-2026-77020","cvss":7.3,"epss":0.0043,"slug":"cve-2026-77020-codeastro-apartment-visitor-management-system-sql-injection-in","title":"CodeAstro Apartment Visitor Management System SQL injection in password-recovery.php","severity":"high","exploited":false,"published_at":"2026-08-20T17:19:49.237+00:00","url":"https://junglewise.ai/threats/cve-2026-77020-codeastro-apartment-visitor-management-system-sql-injection-in"},{"cve":"CVE-2026-77019","cvss":7.3,"epss":0.0043,"slug":"cve-2026-77019-codeastro-apartment-visitor-management-system-sql-injection-in","title":"CodeAstro Apartment Visitor Management System SQL injection in forgotpw.php","severity":"high","exploited":false,"published_at":"2026-08-20T17:19:49.063+00:00","url":"https://junglewise.ai/threats/cve-2026-77019-codeastro-apartment-visitor-management-system-sql-injection-in"},{"cve":"CVE-2026-16765","cvss":7.3,"slug":"cve-2026-16765-codeastro-online-classroom-sql-injection-in-loginlinkadmin-php","title":"CodeAstro Online Classroom SQL injection in loginlinkadmin.php","severity":"high","exploited":false,"published_at":"2026-07-23T22:16:52.25+00:00","url":"https://junglewise.ai/threats/cve-2026-16765-codeastro-online-classroom-sql-injection-in-loginlinkadmin-php"},{"cve":"CVE-2026-15134","cvss":7.3,"slug":"cve-2026-15134-codeastro-simple-online-leave-management-system-sql-injection-in","title":"CodeAstro Simple Online Leave Management System SQL injection in index.php","severity":"high","exploited":false,"published_at":"2026-07-09T00:17:03.9+00:00","url":"https://junglewise.ai/threats/cve-2026-15134-codeastro-simple-online-leave-management-system-sql-injection-in"},{"cve":"CVE-2026-14640","cvss":7.3,"slug":"cve-2026-14640-codeastro-apartment-visitor-management-system-sql-injection-in","title":"CodeAstro Apartment Visitor Management System SQL injection in Login","severity":"high","exploited":false,"published_at":"2026-07-04T19:16:53.18+00:00","url":"https://junglewise.ai/threats/cve-2026-14640-codeastro-apartment-visitor-management-system-sql-injection-in"},{"cve":"CVE-2026-11582","cvss":7.3,"slug":"cve-2026-11582-codeastro-student-attendance-management-system-sql-injection-in","title":"CodeAstro Student Attendance Management System SQL injection in index.php","severity":"high","exploited":false,"published_at":"2026-06-08T20:16:59.78+00:00","url":"https://junglewise.ai/threats/cve-2026-11582-codeastro-student-attendance-management-system-sql-injection-in"},{"cve":"CVE-2026-10261","cvss":7.3,"slug":"cve-2026-10261-codeastro-online-job-portal-sql-injection-in-application-status","title":"CodeAstro Online Job Portal SQL injection in application_status.php","severity":"high","exploited":false,"published_at":"2026-06-01T15:16:32.35+00:00","url":"https://junglewise.ai/threats/cve-2026-10261-codeastro-online-job-portal-sql-injection-in-application-status"}],"generated_at":"2026-09-26T12:07:00.15149+00:00","technologies":[{"name":"CodeAstro Membership Management System","slug":"membership-management-system","vulnerabilities":12,"url":"https://junglewise.ai/threats/technologies/membership-management-system"},{"name":"CodeAstro Apartment Visitor Management System","slug":"apartment-visitor-management-system","vulnerabilities":9,"url":"https://junglewise.ai/threats/technologies/apartment-visitor-management-system"},{"name":"CodeAstro Leave Management System","slug":"leave-management-system","vulnerabilities":6,"url":"https://junglewise.ai/threats/technologies/leave-management-system"},{"name":"CodeAstro Online Classroom","slug":"online-classroom","vulnerabilities":6,"url":"https://junglewise.ai/threats/technologies/online-classroom"},{"name":"CodeAstro Student-Attendance-Management-System","slug":"student-attendance-management-system","vulnerabilities":5,"url":"https://junglewise.ai/threats/technologies/student-attendance-management-system"},{"name":"CodeAstro Ecommerce Website","slug":"ecommerce-website","vulnerabilities":4,"url":"https://junglewise.ai/threats/technologies/ecommerce-website"},{"name":"CodeAstro Simple Online Leave Management System","slug":"simple-online-leave-management-system","vulnerabilities":4,"url":"https://junglewise.ai/threats/technologies/simple-online-leave-management-system"},{"name":"CodeAstro Payroll System","slug":"payroll-system","vulnerabilities":3,"url":"https://junglewise.ai/threats/technologies/payroll-system"}]}