CVE-2026-36387
A Remote Code Execution vulnerability was found in CODEASTRO Membership Management System v1.0 in /add_members.php. This vulnerability affec
CVSS
6.5
Medium
EPSS
0.3%
p17
KEV
—
Exploit Today
5
0-100
Published: May 7, 2026 · Last modified: Jul 5, 2026 · CWE-434
0.3%EPSS · 30 days0.3%
2026-06-302026-07-20
A Remote Code Execution vulnerability was found in CODEASTRO Membership Management System v1.0 in /add_members.php. This vulnerability affects the file upload functionality, where improper file sanitization allows attackers to inject malicious files which leads RCE.
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-562919.8 CRI94.5%
KEV—78Balbooa Forms Unrestricted Upload of File with Dangerous Type Vulnerability10dCVE-2026-562909.8 CRI85.5%
KEV—76Joomlack Page Builder Improper Access Control Vulnerability13dCVE-2026-489089.8 CRI72.6%
KEV—72JoomShaper SP Page Builder Unrestricted Upload of File with Dangerous Type Vulnerability13dCVE-2026-489399.8 CRI71.5%
KEV—71iCagenda Unrestricted Upload of File with Dangerous Type Vulnerability10dCVE-2023-388368.8 HIG99.3%
——30File Upload vulnerability in BoidCMS v.2.0.0 allows a remote attacker to execute arbitrary code by adding a GIF header to bypass MIME type checks.12dCVE-2023-464747.2 HIG97.3%
——29File Upload vulnerability PMB v.7.4.8 allows a remote attacker to execute arbitrary code and escalate privileges via a crafted PHP file uploaded to the start_import.php file.12d