Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Collector

First CVE: May 29, 2009Active for: 17 yearsTotal CVEs: 6

Collector's vulnerability profile centers on a narrow product portfolio—notably MyColex and MyGesaud—that appears to be web-facing or web-integrated applications with a consistent pattern of application-layer input-handling and authentication weaknesses. While the vendor's disclosures carry a notable tendency to acquire public exploit code, the exposure recurs across classic web vulnerability classes including improper authentication, cross-site scripting, and SQL injection that are characteristic of web application development. Current severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
6
Total CVEs
More Total CVEs than 86% of tracked vendors
3.0
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 91% of tracked vendors
5.2
Avg CVSS Score
Higher Avg CVSS Score than 14% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Collector over time

Volume of CVEsAvg CVSS Base Score
First CVE
May 29, 2009
17 years ago
Most Recent CVE
May 29, 2009
6,265 days ago

Products(2 total)

Top CVEs

Signals from CVEs in this vendor scope (6 CVEs).

6 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2009-1826MEDIUM
modules/admuser.php in myGesuad 0.9.14 (aka 0.9) does not require administrative authentication, which allows remote authenticated users to list user accounts via a Find action.
May 29, 20096.526NOYES
CVE-2009-1812MEDIUM
Multiple SQL injection vulnerabilities in myGesuad 0.9.14 (aka 0.9) allow remote attackers to execute arbitrary SQL commands via (1) the formUser parameter (aka the Name field) to
May 29, 20096.024NOYES
CVE-2009-1810MEDIUM
Multiple SQL injection vulnerabilities in myColex 1.4.2 allow remote attackers to execute arbitrary SQL commands via (1) the formUser parameter (aka the Name field) to common/login
May 29, 20096.024NOYES
CVE-2009-1825MEDIUM
modules/admuser.php in myColex 1.4.2 does not require administrative authentication, which allows remote authenticated users to list user accounts via a Find action.
May 29, 20094.021NOYES
CVE-2009-1811MEDIUM
Multiple cross-site scripting (XSS) vulnerabilities in myGesuad 0.9.14 (aka 0.9) allow remote attackers to inject arbitrary web script or HTML via (1) the Page parameter in a List
May 29, 20094.321NOYES
CVE-2009-1809MEDIUM
Multiple cross-site scripting (XSS) vulnerabilities in myColex 1.4.2 allow remote attackers to inject arbitrary web script or HTML via (1) the year parameter to modules/kalender.ph
May 29, 20094.321NOYES
View all 6 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products6 CVEs
100%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
Medium
Attack Vector
Local0 (0.0%)
Network0 (0.0%)
Unknown6 (100.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low0 (0.0%)
High0 (0.0%)
Unknown6 (100.0%)
User Interaction
None0 (0.0%)
Unknown6 (100.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None0 (0.0%)
Unknown6 (100.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (6 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
6 CVEs
100.0% of CVEs· 85th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Collector.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Collector — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Collector's Products

View all 1 CNAs →

Top CWEs