PatchSiren

PHP Scripts Online CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH PHP Scripts Online CVE published 2026-02-18

CVE-2025-70148

CVE-2025-70148 is a high-severity vulnerability in CodeAstro Membership Management System 1.0, allowing unauthenticated attackers to access membership card data of arbitrary users via direct requests with a manipulated id parameter, resulting in insecure direct object reference (IDOR). The vulnerability exists in the print_membership_card.php file, and defenders should assess exposure and prioritize remed [truncated]