Coins Global maintains a narrowly scoped product portfolio centered on its construction cloud platform. The vendor's vulnerability disclosures, while modest in volume, reflect the application-layer exposure of web-facing construction management software. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Coins Global over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-45222HIGH An issue was discovered in COINS Construction Cloud 11.12. Due to logical flaws in the human ressources interface, it is vulnerable to privilege escalation by HR personnel. | Jan 24, 2022 | 8.8 | 27 | NO | NO |
CVE-2021-45226MEDIUM An issue was discovered in COINS Construction Cloud 11.12. Due to improper validation of user-controlled HTTP headers, attackers can cause it to send password-reset e-mails pointin | Jan 24, 2022 | 6.5 | 22 | NO | NO |
CVE-2021-45223MEDIUM An issue was discovered in COINS Construction Cloud 11.12. Due to insufficient input neutralization, it is vulnerable to denial of service attacks via forced server crashes. | Jan 24, 2022 | 6.5 | 22 | NO | NO |
CVE-2021-45228MEDIUM An XSS issue was discovered in COINS Construction Cloud 11.12. Due to insufficient neutralization of user input in the description of a task, it is possible to store malicious Java | Apr 14, 2022 | 5.4 | 20 | NO | NO |
CVE-2021-45225MEDIUM An issue was discovered in COINS Construction Cloud 11.12. Due to improper input neutralization, it is vulnerable to reflected cross-site scripting (XSS) via malicious links (affec | Jan 24, 2022 | 6.1 | 17 | NO | NO |
CVE-2021-45224MEDIUM An issue was discovered in COINS Construction Cloud 11.12. In several locations throughout the application, JavaScript code is passed as a URL parameter. Attackers can trivially al | Jan 24, 2022 | 6.1 | 17 | NO | NO |
CVE-2021-45227MEDIUM An issue was discovered in COINS Construction Cloud 11.12. Due to an inappropriate use of HTML IFRAME elements, the file upload functionality is vulnerable to a persistent Cross-Si | Apr 14, 2022 | 5.4 | 15 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Coins Global.
Media articles that mention a CVE ID that affects a product developed by Coins Global — matched by CVE ID, not by vendor name.