CVE-2025-61823
published 2025-12-10CVE-2025-61823: ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that…
PriorityP434medium6.2CVSS 3.1
AVNACLPRHUIRSCCHINAN
EPSS
0.43%
35.2th percentile
ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could lead to arbitrary file system read. A high privileged attacker could exploit this vulnerability to access sensitive files and data on the server. Exploitation of this issue requires user interaction and scope is changed.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| adobe | coldfusion | <= 2021.22 | — |
| adobe | coldfusion | — | — |
| adobe | coldfusion | — | — |
| adobe | coldfusion | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
Wiz
CVE-2025-64897 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 6.8
CVE-2025-64897 [MEDIUM] CVE-2025-64897 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-64897 :
Adobe ColdFusion vulnerability analysis and mitigation
ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Improper Access Control vulnerability. A low privileged attacker could leverage this vulnerability to bypass security measures and gain limited unauthorized write access potentially resulting in denial of service. Exploitation of this issue requires user interaction.
Source : NVD
## 5.6
Score
Published December 10, 2025
Severity MEDIUM
CNA Score 5.6
Affected Technologies
Adobe ColdFusion
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 8.1
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a:adobe:coldfusion
S
Wiz
CVE-2025-61810 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.4
CVE-2025-61810 [HIGH] CVE-2025-61810 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-61810 :
Adobe ColdFusion vulnerability analysis and mitigation
ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could result in arbitrary code execution in the context of the current user. A high privileged attacker could exploit this vulnerability by providing maliciously crafted serialized data to the application. Exploitation of this issue requires user interaction and scope is changed.
Source : NVD
## 8.4
Score
Published December 10, 2025
Severity HIGH
CNA Score 8.4
Affected Technologies
Adobe ColdFusion
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 89
Exploitation Probability (EPSS) 4.4
Wiz
CVE-2025-64898 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 6.8
CVE-2025-64898 [MEDIUM] CVE-2025-64898 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-64898 :
Adobe ColdFusion vulnerability analysis and mitigation
ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Insufficiently Protected Credentials vulnerability that could result in limited unauthorized write access. An attacker could leverage this vulnerability to gain unauthorized access by exploiting improperly stored or transmitted credentials. Exploitation of this issue does not require user interaction.
Source : NVD
## 5.3
Score
Published December 10, 2025
Severity MEDIUM
CNA Score 4.3
Affected Technologies
Adobe ColdFusion
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 20.3
Exploitation Probability (EPSS) 0.1
Affected packages and libr
Wiz
CVE-2025-61811 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 9.1
CVE-2025-61811 [CRITICAL] CVE-2025-61811 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-61811 :
Adobe ColdFusion vulnerability analysis and mitigation
ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Improper Access Control vulnerability that could result in arbitrary code execution in the context of the current user. A high privileged attacker could leverage this vulnerability to bypass security measures and execute malicious code. Exploitation of this issue does not require user interaction and scope is changed.
Source : NVD
## 9.1
Score
Published December 10, 2025
Severity CRITICAL
CNA Score 9.1
Affected Technologies
Adobe ColdFusion
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 77.2
Exploitation Probability (EPSS) 1
Affected
Wiz
CVE-2025-61821 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 6.8
CVE-2025-61821 [MEDIUM] CVE-2025-61821 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-61821 :
Adobe ColdFusion vulnerability analysis and mitigation
ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to access sensitive files and data on the server. Exploitation of this issue does not require user interaction and scope is changed.
Source : NVD
## 8.6
Score
Published December 10, 2025
Severity HIGH
CNA Score 6.8
Affected Technologies
Adobe ColdFusion
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 28
Exploitation Probability (EPSS) 0.1
Affected packages and libraries
Wiz
CVE-2025-61808 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 9.1
CVE-2025-61808 [CRITICAL] CVE-2025-61808 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-61808 :
Adobe ColdFusion vulnerability analysis and mitigation
ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Unrestricted Upload of File with Dangerous Type vulnerability that could lead to arbitrary code execution by a high priviledged attacker. Exploitation of this issue does not require user interaction and scope is changed.
Source : NVD
## 9.1
Score
Published December 10, 2025
Severity CRITICAL
CNA Score 9.1
Affected Technologies
Adobe ColdFusion
Has Public Exploit Yes
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 73.3
Exploitation Probability (EPSS) 0.8
Affected packages and libraries
cpe:2.3:a:adobe:coldfusion
Sources
Linux Severity CRITICAL No Fix Adde
Wiz
CVE-2025-61812 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.4
CVE-2025-61812 [HIGH] CVE-2025-61812 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-61812 :
Adobe ColdFusion vulnerability analysis and mitigation
ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Improper Input Validation vulnerability that could allow a high privileged attacker to gain arbitrary code execution. Exploitation of this issue does not require user interaction.
Source : NVD
## 8.4
Score
Published December 10, 2025
Severity HIGH
CNA Score 8.4
Affected Technologies
Adobe ColdFusion
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 19.7
Exploitation Probability (EPSS) 0.1
Affected packages and libraries
cpe:2.3:a:adobe:coldfusion
Sources
Linux Severity HIGH No Fix Added at: Dec 11, 2025
Windows Severity HIGH No Fix A
Wiz
CVE-2025-61809 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 9.1
CVE-2025-61809 [CRITICAL] CVE-2025-61809 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-61809 :
Adobe ColdFusion vulnerability analysis and mitigation
ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized read and write access. Exploitation of this issue does not require user interaction and scope is unchanged.
Source : NVD
## 9.1
Score
Published December 10, 2025
Severity CRITICAL
CNA Score 9.1
Affected Technologies
Adobe ColdFusion
Has Public Exploit Yes
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 72.5
Exploitation Probability (EPSS) 0.7
Affected packages and libraries
c
Wiz
CVE-2025-61823 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 6.8
CVE-2025-61823 [MEDIUM] CVE-2025-61823 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-61823 :
Adobe ColdFusion vulnerability analysis and mitigation
ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could lead to arbitrary file system read. A high privileged attacker could exploit this vulnerability to access sensitive files and data on the server. Exploitation of this issue requires user interaction and scope is changed.
Source : NVD
## 6.2
Score
Published December 10, 2025
Severity MEDIUM
CNA Score 6.2
Affected Technologies
Adobe ColdFusion
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 26.7
Exploitation Probability (EPSS) 0.1
Affected packages and
Wiz
CVE-2025-61822 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 6.8
CVE-2025-61822 [MEDIUM] CVE-2025-61822 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-61822 :
Adobe ColdFusion vulnerability analysis and mitigation
ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Improper Input Validation vulnerability that could lead to arbitrary file system write. An attacker could exploit this vulnerability to write malicious files to arbitrary locations on the file system. Exploitation of this issue does not require user interaction and scope is changed.
Source : NVD
## 6.2
Score
Published December 10, 2025
Severity MEDIUM
CNA Score 6.2
Affected Technologies
Adobe ColdFusion
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 17.8
Exploitation Probability (EPSS) 0.1
Affected packages and libraries
cpe:2.3:a:ad
Wiz
CVE-2025-61813 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.2
CVE-2025-61813 [HIGH] CVE-2025-61813 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-61813 :
Adobe ColdFusion vulnerability analysis and mitigation
ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to access sensitive files on the server. Exploitation of this issue does not require user interaction and scope is changed.
Source : NVD
## 8.6
Score
Published December 10, 2025
Severity HIGH
CNA Score 8.2
Affected Technologies
Adobe ColdFusion
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 26
Exploitation Probability (EPSS) 0.1
Affected packages and libraries
cpe:2.3:
2025-12-10
Published