Collector's vulnerability profile centers on a narrow product portfolio—notably MyColex and MyGesaud—that appears to be web-facing or web-integrated applications with a consistent pattern of application-layer input-handling and authentication weaknesses. While the vendor's disclosures carry a notable tendency to acquire public exploit code, the exposure recurs across classic web vulnerability classes including improper authentication, cross-site scripting, and SQL injection that are characteristic of web application development. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Collector over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2009-1826MEDIUM modules/admuser.php in myGesuad 0.9.14 (aka 0.9) does not require administrative authentication, which allows remote authenticated users to list user accounts via a Find action. | May 29, 2009 | 6.5 | 26 | NO | YES |
CVE-2009-1812MEDIUM Multiple SQL injection vulnerabilities in myGesuad 0.9.14 (aka 0.9) allow remote attackers to execute arbitrary SQL commands via (1) the formUser parameter (aka the Name field) to | May 29, 2009 | 6.0 | 24 | NO | YES |
CVE-2009-1810MEDIUM Multiple SQL injection vulnerabilities in myColex 1.4.2 allow remote attackers to execute arbitrary SQL commands via (1) the formUser parameter (aka the Name field) to common/login | May 29, 2009 | 6.0 | 24 | NO | YES |
CVE-2009-1825MEDIUM modules/admuser.php in myColex 1.4.2 does not require administrative authentication, which allows remote authenticated users to list user accounts via a Find action. | May 29, 2009 | 4.0 | 21 | NO | YES |
CVE-2009-1811MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in myGesuad 0.9.14 (aka 0.9) allow remote attackers to inject arbitrary web script or HTML via (1) the Page parameter in a List | May 29, 2009 | 4.3 | 21 | NO | YES |
CVE-2009-1809MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in myColex 1.4.2 allow remote attackers to inject arbitrary web script or HTML via (1) the year parameter to modules/kalender.ph | May 29, 2009 | 4.3 | 21 | NO | YES |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Collector.
Media articles that mention a CVE ID that affects a product developed by Collector — matched by CVE ID, not by vendor name.