← Back

Coldgen

coldgen

4 CVEs • 3 products

Products (3)

Click to collapse
Toggle
Coldusergroup
coldusergroup
Coldcalendar
coldcalendar
Coldbookmarks
coldbookmarks

CVEs (4)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Coldgen
1Coldusergroup
Apr 29, 2026
Oct 8, 2011
N/A· v4
N/A· v3
7.5 HIGH· v2
Multiple SQL injection vulnerabilities in index.cfm in ColdGen ColdUserGroup 1.06 allow remote attackers to execute arbitrary SQL commands via the (1) ArticleID or (2) LibraryID parameter.
1Coldgen
1Coldbookmarks
Apr 29, 2026
Oct 8, 2011
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in index.cfm in ColdGen ColdBookmarks 1.22 allows remote attackers to execute arbitrary SQL commands via the BookmarkID parameter in an EditBookmark action.
1Coldgen
1Coldusergroup
Apr 29, 2026
Oct 8, 2011
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in the search feature in ColdGen ColdUserGroup 1.06 allows remote attackers to inject arbitrary web script or HTML via the Keywords parameter. NOTE: some of these details are obt...Show more
Cross-site scripting (XSS) vulnerability in the search feature in ColdGen ColdUserGroup 1.06 allows remote attackers to inject arbitrary web script or HTML via the Keywords parameter. NOTE: some of these details are obtained from third party information.Show less
1Coldgen
1Coldcalendar
Apr 29, 2026
Oct 8, 2011
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in index.cfm in ColdGen ColdCalendar 2.06 allows remote attackers to execute arbitrary SQL commands via the EventID parameter in a ViewEventDetails action.