cbcvebase.

Adobe Coldfusion vulnerabilities

240 known vulnerabilities affecting adobe/coldfusion.

Total CVEs
240
CISA KEV
17
actively exploited
Public exploits
23
Exploited in wild
27
Severity breakdown
CRITICAL76HIGH66MEDIUM89LOW9

Vulnerabilities

Page 10 of 12
CVE-2011-0629P4MEDIUMCVSS 6.8v8.0v8.0.1+2 more2011-06-16
CVE-2011-0629 [MEDIUM] CWE-352 CVE-2011-0629: Cross-site request forgery (CSRF) vulnerability in Adobe ColdFusion 8.0, 8.0.1, 9.0, and 9.0.1 allow Cross-site request forgery (CSRF) vulnerability in Adobe ColdFusion 8.0, 8.0.1, 9.0, and 9.0.1 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.
nvd
CVE-2016-4159P4MEDIUMCVSS 6.1v10.0v11.0+1 more2016-06-16
CVE-2016-4159 [MEDIUM] CWE-79 CVE-2016-4159: Cross-site scripting (XSS) vulnerability in Adobe ColdFusion 10 before Update 20, 11 before Update 9 Cross-site scripting (XSS) vulnerability in Adobe ColdFusion 10 before Update 20, 11 before Update 9, and 2016 before Update 2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
nvd
CVE-2009-1878P4MEDIUMCVSS 5.8≤ 8.0.1v6.0+7 more2009-08-18
CVE-2009-1878 [MEDIUM] CWE-287 CVE-2009-1878: Session fixation vulnerability in Adobe ColdFusion 8.0.1 and earlier allows remote attackers to hija Session fixation vulnerability in Adobe ColdFusion 8.0.1 and earlier allows remote attackers to hijack web sessions via unspecified vectors.
nvd
CVE-2007-1874P4HIGHCVSS 7.2v7.02007-04-11
CVE-2007-1874 [HIGH] CVE-2007-1874: Adobe ColdFusion MX 7 for Linux and Solaris uses insecure permissions for certain scripts and direct Adobe ColdFusion MX 7 for Linux and Solaris uses insecure permissions for certain scripts and directories, which allows local users to execute arbitrary code or obtain sensitive information via the (1) CFMX7DreamWeaverExtensions.mxp, (2) CFReportBuilderInstaller.exe, (3) .com.zerog.registry.xml, (4) uninstall.lax, (5) license.txt, (6) Readme.htm, (7) .com.zerog
nvd
CVE-2019-7092P4MEDIUMCVSS 6.1v11.0v2016+2 more2019-05-24
CVE-2019-7092 [MEDIUM] CWE-79 CVE-2019-7092: ColdFusion versions Update 1 and earlier, Update 7 and earlier, and Update 15 and earlier have a cro ColdFusion versions Update 1 and earlier, Update 7 and earlier, and Update 15 and earlier have a cross site scripting vulnerability. Successful exploitation could lead to information disclosure .
nvd
CVE-2018-4940P4MEDIUMCVSS 6.1v11.0v20162018-05-19
CVE-2018-4940 [MEDIUM] CWE-79 CVE-2018-4940: Adobe ColdFusion Update 5 and earlier versions, ColdFusion 11 Update 13 and earlier versions have an Adobe ColdFusion Update 5 and earlier versions, ColdFusion 11 Update 13 and earlier versions have an exploitable Cross-Site Scripting vulnerability. Successful exploitation could lead to information disclosure.
nvd
CVE-2018-4941P4MEDIUMCVSS 6.1v11.0v20162018-05-19
CVE-2018-4941 [MEDIUM] CWE-79 CVE-2018-4941: Adobe ColdFusion Update 5 and earlier versions, ColdFusion 11 Update 13 and earlier versions have an Adobe ColdFusion Update 5 and earlier versions, ColdFusion 11 Update 13 and earlier versions have an exploitable Cross-Site Scripting vulnerability. Successful exploitation could lead to information disclosure.
nvd
CVE-2025-64897P4MEDIUMCVSS 5.6v2021v2023+2 more2025-12-10
CVE-2025-64897 [MEDIUM] CWE-284 CVE-2025-64897: ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Improper Access Control ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Improper Access Control vulnerability. A low privileged attacker could leverage this vulnerability to bypass security measures and gain limited unauthorized write access potentially resulting in denial of service. Exploitation of this issue requires user interaction.
nvd
CVE-2025-30291P4MEDIUMCVSS 5.5v2021v2023+2 more2025-04-08
CVE-2025-30291 [MEDIUM] CWE-200 CVE-2025-30291: ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by an Information Exposure vul ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by an Information Exposure vulnerability that could result in a security feature bypass. A low privileged attacker with local access could leverage this vulnerability to gain access to sensitive information which could be used to further compromise the system or bypass security me
nvd
CVE-2008-4831P4HIGHCVSS 7.2v7.2v8.0+1 more2008-11-10
CVE-2008-4831 [HIGH] CWE-264 CVE-2008-4831: Unspecified vulnerability in Adobe ColdFusion 8 and 8.0.1 and ColdFusion MX 7.0.2 allows local users Unspecified vulnerability in Adobe ColdFusion 8 and 8.0.1 and ColdFusion MX 7.0.2 allows local users to bypass sandbox restrictions, and obtain sensitive information or possibly gain privileges, via unknown vectors.
nvd
CVE-2011-0582P4MEDIUMCVSS 5.0v8.0v8.0.1+2 more2011-02-10
CVE-2011-0582 [MEDIUM] CVE-2011-0582: Unspecified vulnerability in the administrator console in Adobe ColdFusion 8.0 through 9.0.1 allows Unspecified vulnerability in the administrator console in Adobe ColdFusion 8.0 through 9.0.1 allows attackers to obtain sensitive information via unknown vectors.
nvd
CVE-2011-0584P4MEDIUMCVSS 4.3v8.0v8.0.1+2 more2011-02-10
CVE-2011-0584 [MEDIUM] CVE-2011-0584: Session fixation vulnerability in Adobe ColdFusion 8.0 through 9.0.1 allows remote attackers to hija Session fixation vulnerability in Adobe ColdFusion 8.0 through 9.0.1 allows remote attackers to hijack web sessions via unspecified vectors.
nvd
CVE-2012-2041P4MEDIUMCVSS 4.3v8.0v8.0.1+1 more2012-06-13
CVE-2012-2041 [MEDIUM] CWE-94 CVE-2012-2041: CRLF injection vulnerability in the Component Browser in Adobe ColdFusion 8.0 through 9.0.1 allows r CRLF injection vulnerability in the Component Browser in Adobe ColdFusion 8.0 through 9.0.1 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified vectors.
nvd
CVE-2011-0736P4MEDIUMCVSS 5.3≤ 9.0.1v4.5+11 more2011-02-01
CVE-2011-0736 [MEDIUM] CWE-200 CVE-2011-0736: Adobe ColdFusion 9.0.1 CHF1 and earlier, when a web application is configured to use a DBMS, allows Adobe ColdFusion 9.0.1 CHF1 and earlier, when a web application is configured to use a DBMS, allows remote attackers to obtain potentially sensitive information about the database structure via an id=- query to a .cfm file. NOTE: the vendor disputes the significance of this issue because the Site-wide Error Handler and Debug Output Settings sections of
nvd
CVE-2012-0770P4MEDIUMCVSS 5.0v8.0v8.0.1+2 more2012-03-13
CVE-2012-0770 [MEDIUM] CVE-2012-0770: Adobe ColdFusion 8.0, 8.0.1, 9.0, and 9.0.1 computes hash values for form parameters without restric Adobe ColdFusion 8.0, 8.0.1, 9.0, and 9.0.1 computes hash values for form parameters without restricting the ability to trigger hash collisions predictably, which allows remote attackers to cause a denial of service (CPU consumption) by sending many crafted parameters.
nvd
CVE-2025-49542P4MEDIUMCVSS 5.2v2021v2023+2 more2025-07-08
CVE-2025-49542 [MEDIUM] CWE-79 CVE-2025-49542: ColdFusion versions 2025.2, 2023.14, 2021.20 and earlier are affected by a reflected Cross-Site Scri ColdFusion versions 2025.2, 2023.14, 2021.20 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an unauthenticated attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser, scope is changed. The vulnerab
nvd
CVE-2011-2091P4MEDIUMCVSS 5.0v8.0v8.0.1+2 more2011-06-16
CVE-2011-2091 [MEDIUM] CVE-2011-2091: Unspecified vulnerability in Adobe ColdFusion 8.0, 8.0.1, 9.0, and 9.0.1 allows remote attackers to Unspecified vulnerability in Adobe ColdFusion 8.0, 8.0.1, 9.0, and 9.0.1 allows remote attackers to cause a denial of service via unknown vectors.
nvd
CVE-2008-0644P4MEDIUMCVSS 5.0v7.0v7.0.1+2 more2008-03-12
CVE-2008-0644 [MEDIUM] CVE-2008-0644: Adobe ColdFusion MX 7 and ColdFusion 8 allows remote attackers to bypass the cross-site scripting (X Adobe ColdFusion MX 7 and ColdFusion 8 allows remote attackers to bypass the cross-site scripting (XSS) protection mechanism for applications via unspecified vectors related to the setEncoding function.
nvd
CVE-2014-9166P4MEDIUMCVSS 5.0v10.0v11.02014-12-10
CVE-2014-9166 [MEDIUM] CVE-2014-9166: Adobe ColdFusion 10 before Update 15 and 11 before Update 3 allows attackers to cause a denial of se Adobe ColdFusion 10 before Update 15 and 11 before Update 3 allows attackers to cause a denial of service (resource consumption) via unspecified vectors.
nvd
CVE-2013-3349P4MEDIUMCVSS 5.0v9.0v9.0.1+1 more2013-07-10
CVE-2013-3349 [MEDIUM] CVE-2013-3349: Unspecified vulnerability in Adobe ColdFusion 9.0 through 9.0.2, when the JRun application server is Unspecified vulnerability in Adobe ColdFusion 9.0 through 9.0.2, when the JRun application server is used, allows remote attackers to cause a denial of service via unknown vectors.
nvd
Adobe Coldfusion vulnerabilities | cvebase