Coinsoft Technologies maintains a narrowly scoped cryptocurrency payment platform, PHPCoin, that sits at the intersection of financial transaction processing and web application deployment. The recurring exposure centers on information-disclosure vulnerabilities and issues classified under broader categories, reflecting the sensitivity of financial data and authentication credentials in payment systems. Public exploit code has frequently been made available for vulnerabilities affecting this vendor, making live severity and exploitation counts shown alongside this summary essential for patch prioritization.
The number and severity of CVEs published that impact products developed by Coinsoft Technologies over time
Signals from CVEs in this vendor scope (16 CVEs).
16 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2005-4211HIGH PHP remote file inclusion vulnerability in coin_includes/db.php in phpCOIN 1.2.2 allows remote attackers to execute arbitrary PHP code via a URL in the $_CCFG[_PKG_PATH_DBSE] varia | Dec 14, 2005 | 7.5 | 32 | NO | YES |
CVE-2005-4213HIGH SQL injection vulnerability in mod.php in phpCOIN 1.2.2 allows remote attackers to execute arbitrary SQL commands via the phpcoinsessid cookie. | Dec 14, 2005 | 7.5 | 29 | NO | YES |
CVE-2005-1384HIGH Multiple SQL injection vulnerabilities in phpCoin 1.2.2 allow remote attackers to execute arbitrary SQL commands via the (1) search parameter to index.php, (2) phpcoinsessid parame | May 3, 2005 | 7.5 | 29 | NO | YES |
CVE-2006-4424MEDIUM PHP remote file inclusion vulnerability in coin_includes/constants.php in phpCOIN 1.2.3 allows remote attackers to execute arbitrary PHP code via the _CCFG[_PKG_PATH_INCL] paramete | Aug 29, 2006 | 5.1 | 25 | NO | YES |
CVE-2005-4212MEDIUM Directory traversal vulnerability in coin_includes/db.php in phpCOIN 1.2.2 allows remote attackers to read arbitrary local files via ".." (dot dot) sequences in the $_CCFG[_PKG_PAT | Dec 14, 2005 | 5.0 | 25 | NO | YES |
CVE-2006-4425MEDIUM Multiple PHP remote file inclusion vulnerabilities in phpCOIN 1.2.3 allow remote attackers to execute arbitrary PHP code via the _CCFG[_PKG_PATH_INCL] parameter in coin_includes sc | Aug 29, 2006 | 5.1 | 24 | NO | YES |
CVE-2005-0670MEDIUM Cross-site scripting (XSS) vulnerability in phpCOIN 1.2.0 through 1.2.1b allows remote attackers to inject arbitrary web script or HTML via (1) the new parameter to mod.php, (2) th | May 2, 2005 | 4.3 | 22 | NO | YES |
CVE-2006-1428MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in phpCOIN 1.2.2 and earlier allow remote attackers to inject arbitrary web script or HTML via the fs parameter to (1) mod.php o | Mar 28, 2006 | 4.3 | 21 | NO | YES |
CVE-2005-4447HIGH SQL injection vulnerability in articles\articles_funcs.php in phpCOIN 1.2.2 allows remote attackers to modify SQL syntax and possibly execute SQL in limited circumstances via the r | Dec 21, 2005 | 7.5 | 19 | NO | NO |
CVE-2005-0669HIGH Multiple SQL injection vulnerabilities in mod.php for phpCOIN 1.2.0 through 1.2.1b allow remote attackers to execute arbitrary SQL commands via the (1) the faq_id in the faq mod, ( | May 2, 2005 | 7.5 | 19 | NO | NO |
Signals from CVEs in this vendor scope (16 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Coinsoft Technologies.
Media articles that mention a CVE ID that affects a product developed by Coinsoft Technologies — matched by CVE ID, not by vendor name.