Adobe Coldfusion vulnerabilities
240 known vulnerabilities affecting adobe/coldfusion.
Total CVEs
240
CISA KEV
17
actively exploited
Public exploits
23
Exploited in wild
27
Severity breakdown
CRITICAL76HIGH66MEDIUM89LOW9
Vulnerabilities
Page 1 of 12
CVE-2023-29300P1CRITICALCVSS 9.8KEVPoCRansomwarev2018v2021+2 more2023-07-12
CVE-2023-29300 [CRITICAL] CWE-502 CVE-2023-29300: Adobe ColdFusion versions 2018u16 (and earlier), 2021u6 (and earlier) and 2023.0.0.330468 (and earli
Adobe ColdFusion versions 2018u16 (and earlier), 2021u6 (and earlier) and 2023.0.0.330468 (and earlier) are affected by a Deserialization of Untrusted Data vulnerability that could result in Arbitrary code execution. Exploitation of this issue does not require user interaction.
nvd
CVE-2023-38203P1CRITICALCVSS 9.8KEVPoCRansomwarev2018v2021+2 more2023-07-20
CVE-2023-38203 [CRITICAL] CWE-502 CVE-2023-38203: Adobe ColdFusion versions 2018u17 (and earlier), 2021u7 (and earlier) and 2023u1 (and earlier) are a
Adobe ColdFusion versions 2018u17 (and earlier), 2021u7 (and earlier) and 2023u1 (and earlier) are affected by a Deserialization of Untrusted Data vulnerability that could result in Arbitrary code execution. Exploitation of this issue does not require user interaction.
nvd
CVE-2026-48282P1CRITICALCVSS 10.0KEVPoCv2023v2023-update1+30 more2026-06-30
CVE-2026-48282 [CRITICAL] CWE-22 CVE-2026-48282: ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Limitation of a Pathname
ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed.
nvd
CVE-2023-26360P1CRITICALCVSS 9.8KEVPoCv2018v2021+1 more2023-03-23
CVE-2023-26360 [CRITICAL] CWE-284 CVE-2023-26360: Adobe ColdFusion versions 2018 Update 15 (and earlier) and 2021 Update 5 (and earlier) are affected
Adobe ColdFusion versions 2018 Update 15 (and earlier) and 2021 Update 5 (and earlier) are affected by an Improper Access Control vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction.
nvd
CVE-2018-15961P1CRITICALCVSS 9.8KEVPoCv11.0v2016+2 more2018-09-25
CVE-2018-15961 [CRITICAL] CWE-434 CVE-2018-15961: Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and
Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have an unrestricted file upload vulnerability. Successful exploitation could lead to arbitrary code execution.
nvd
CVE-2017-3066P1CRITICALCVSS 9.8KEVPoCv10.0v11.0+1 more2017-04-27
CVE-2017-3066 [CRITICAL] CWE-502 CVE-2017-3066: Adobe ColdFusion 2016 Update 3 and earlier, ColdFusion 11 update 11 and earlier, ColdFusion 10 Updat
Adobe ColdFusion 2016 Update 3 and earlier, ColdFusion 11 update 11 and earlier, ColdFusion 10 Update 22 and earlier have a Java deserialization vulnerability in the Apache BlazeDS library. Successful exploitation could lead to arbitrary code execution.
nvd
CVE-2013-0625P1CRITICALCVSS 9.8KEVPoCv9.0v9.0.1+1 more2013-01-09
CVE-2013-0625 [CRITICAL] CWE-287 CVE-2013-0625: Adobe ColdFusion 9.0, 9.0.1, and 9.0.2, when a password is not configured, allows remote attackers t
Adobe ColdFusion 9.0, 9.0.1, and 9.0.2, when a password is not configured, allows remote attackers to bypass authentication and possibly execute arbitrary code via unspecified vectors, as exploited in the wild in January 2013.
nvd
CVE-2010-2861P1CRITICALCVSS 9.8KEVPoCRansomware≤ 9.0.12010-08-11
CVE-2010-2861 [CRITICAL] CWE-22 CVE-2010-2861: Multiple directory traversal vulnerabilities in the administrator console in Adobe ColdFusion 9.0.1
Multiple directory traversal vulnerabilities in the administrator console in Adobe ColdFusion 9.0.1 and earlier allow remote attackers to read arbitrary files via the locale parameter to (1) CFIDE/administrator/settings/mappings.cfm, (2) logging/settings.cfm, (3) datasources/index.cfm, (4) j2eepackaging/editarchive.cfm, and (5) enter.cfm in CFIDE/admi
nvd
CVE-2013-0632P1CRITICALCVSS 9.8KEVPoCv9.0v9.0.1+2 more2013-01-17
CVE-2013-0632 [CRITICAL] CWE-276 CVE-2013-0632: administrator.cfc in Adobe ColdFusion 9.0, 9.0.1, 9.0.2, and 10 allows remote attackers to bypass au
administrator.cfc in Adobe ColdFusion 9.0, 9.0.1, 9.0.2, and 10 allows remote attackers to bypass authentication and possibly execute arbitrary code by logging in to the RDS component using the default empty password and leveraging this session to access the administrative web interface, as exploited in the wild in January 2013.
nvd
CVE-2023-38205P1HIGHCVSS 7.5KEVPoCv2018v2021+1 more2023-09-14
CVE-2023-38205 [HIGH] CVE-2023-38205: Adobe ColdFusion versions 2018u18 (and earlier), 2021u8 (and earlier) and 2023u2 (and earlier) are a
Adobe ColdFusion versions 2018u18 (and earlier), 2021u8 (and earlier) and 2023u2 (and earlier) are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to access the administration CFM and CFC endpoints. Exploitation of this issue does not require user interaction.
nvd
CVE-2023-29298P1HIGHCVSS 7.5KEVPoCv2018v2021+2 more2023-07-12
CVE-2023-29298 [HIGH] CWE-284 CVE-2023-29298: Adobe ColdFusion versions 2018u16 (and earlier), 2021u6 (and earlier) and 2023.0.0.330468 (and earli
Adobe ColdFusion versions 2018u16 (and earlier), 2021u6 (and earlier) and 2023.0.0.330468 (and earlier) are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to access the administration CFM and CFC endpoints. Exploitation of this issue does not require us
nvd
CVE-2024-20767P1HIGHCVSS 7.4KEVPoCv2021v2023+1 more2024-03-18
CVE-2024-20767 [HIGH] CWE-284 CVE-2024-20767: ColdFusion versions 2023.6, 2021.12 and earlier are affected by an Improper Access Control vulnerabi
ColdFusion versions 2023.6, 2021.12 and earlier are affected by an Improper Access Control vulnerability that could result in arbitrary file system read. An attacker could leverage this vulnerability to access or modify restricted files. Exploitation of this issue does not require user interaction. Exploitation of this issue requires the admin panel b
nvd
CVE-2009-3960P1MEDIUMCVSS 6.5KEVPoCRansomwarev7.0.2v8.0+2 more2010-02-15
CVE-2009-3960 [MEDIUM] CVE-2009-3960: Unspecified vulnerability in BlazeDS 3.2 and earlier, as used in LiveCycle 8.0.1, 8.2.1, and 9.0, Li
Unspecified vulnerability in BlazeDS 3.2 and earlier, as used in LiveCycle 8.0.1, 8.2.1, and 9.0, LiveCycle Data Services 2.5.1, 2.6.1, and 3.0, Flex Data Services 2.0.1, and ColdFusion 7.0.2, 8.0, 8.0.1, and 9.0, allows remote attackers to obtain sensitive information via vectors that are associated with a request, and related to injected tags and external e
nvd
CVE-2013-0629P1HIGHCVSS 7.5KEVPoCv9.0v9.0.1+2 more2013-01-09
CVE-2013-0629 [HIGH] CVE-2013-0629: Adobe ColdFusion 9.0, 9.0.1, 9.0.2, and 10, when a password is not configured, allows attackers to a
Adobe ColdFusion 9.0, 9.0.1, 9.0.2, and 10, when a password is not configured, allows attackers to access restricted directories via unspecified vectors, as exploited in the wild in January 2013.
nvd
CVE-2018-4939P1CRITICALCVSS 9.8KEVv11.0v20162018-05-19
CVE-2018-4939 [CRITICAL] CWE-502 CVE-2018-4939: Adobe ColdFusion Update 5 and earlier versions, ColdFusion 11 Update 13 and earlier versions have an
Adobe ColdFusion Update 5 and earlier versions, ColdFusion 11 Update 13 and earlier versions have an exploitable Deserialization of Untrusted Data vulnerability. Successful exploitation could lead to arbitrary code execution.
nvd
CVE-2023-26359P1CRITICALCVSS 9.8KEVv2018v2021+1 more2023-03-23
CVE-2023-26359 [CRITICAL] CWE-502 CVE-2023-26359: Adobe ColdFusion versions 2018 Update 15 (and earlier) and 2021 Update 5 (and earlier) are affected
Adobe ColdFusion versions 2018 Update 15 (and earlier) and 2021 Update 5 (and earlier) are affected by a Deserialization of Untrusted Data vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction.
nvd
CVE-2013-0631P2HIGHCVSS 7.5KEVv9.0v9.0.1+1 more2013-01-09
CVE-2013-0631 [HIGH] CVE-2013-0631: Adobe ColdFusion 9.0, 9.0.1, and 9.0.2 allows attackers to obtain sensitive information via unspecif
Adobe ColdFusion 9.0, 9.0.1, and 9.0.2 allows attackers to obtain sensitive information via unspecified vectors, as exploited in the wild in January 2013.
nvd
CVE-2023-44353P1CRITICALCVSS 9.8ExploitedPoCfixed in 2021v2021+2 more2023-11-17
CVE-2023-44353 [CRITICAL] CWE-502 CVE-2023-44353: Adobe ColdFusion versions 2023.5 (and earlier) and 2021.11 (and earlier) are affected by an Deserial
Adobe ColdFusion versions 2023.5 (and earlier) and 2021.11 (and earlier) are affected by an Deserialization of Untrusted Data vulnerability that could result in Arbitrary code execution. Exploitation of this issue does not require user interaction.
nvd
CVE-2023-44352P2MEDIUMCVSS 6.1ExploitedPoCfixed in 2021v2021+2 more2023-11-17
CVE-2023-44352 [MEDIUM] CWE-79 CVE-2023-44352: Adobe ColdFusion versions 2023.5 (and earlier) and 2021.11 (and earlier) are affected by a reflected
Adobe ColdFusion versions 2023.5 (and earlier) and 2021.11 (and earlier) are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an unauthenticated attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser.
nvd
CVE-2013-3336P2MEDIUMCVSS 5.0ExploitedPoCv9.0v9.0.1+2 more2013-05-09
CVE-2013-3336 [MEDIUM] CVE-2013-3336: Unspecified vulnerability in Adobe ColdFusion 9.0, 9.0.1, 9.0.2, and 10 allows remote attackers to r
Unspecified vulnerability in Adobe ColdFusion 9.0, 9.0.1, 9.0.2, and 10 allows remote attackers to read arbitrary files via unknown vectors.
nvd
1 / 12Next →