PatchSiren

CodeAstro CVE debriefs · Page 2

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

LOW CodeAstro CVE published 2026-04-28

CVE-2026-7196

A security vulnerability has been detected in CodeAstro Online Classroom 1.0, specifically in an unknown function of the file /guestdetails. Manipulation of the argument deleteid leads to SQL injection. The attack may be performed remotely, and the exploit has been publicly disclosed. This vulnerability affects CodeAstro Online Classroom 1.0, and users of this software should be aware of the potential for [truncated]

CRITICAL CodeAstro CVE published 2026-02-18

CVE-2025-70150

A critical vulnerability exists in CodeAstro Membership Management System 1.0, specifically in the delete_members.php file, which allows unauthenticated attackers to delete arbitrary member records via the id parameter. This issue has a CVSS score of 9.8 and is considered critical. System administrators and security teams should prioritize patching or mitigating this vulnerability to prevent potential una [truncated]

CRITICAL CodeAstro CVE published 2026-02-18

CVE-2025-70149

A critical SQL injection vulnerability exists in CodeAstro Membership Management System 1.0, specifically in the print_membership_card.php file via the ID parameter. This issue, tracked as CVE-2025-70149, has a CVSS score of 9.8 and is considered critical. The vulnerability allows for high impact on confidentiality, integrity, and availability. Defenders should assess exposure and prioritize remediation d [truncated]