Adobe Coldfusion vulnerabilities
240 known vulnerabilities affecting adobe/coldfusion.
Total CVEs
240
CISA KEV
17
actively exploited
Public exploits
23
Exploited in wild
27
Severity breakdown
CRITICAL76HIGH66MEDIUM89LOW9
Vulnerabilities
Page 11 of 12
CVE-2015-0345P4MEDIUMCVSS 4.3≤ 10.0≤ 11.02015-04-15
CVE-2015-0345 [MEDIUM] CWE-79 CVE-2015-0345: Cross-site scripting (XSS) vulnerability in Adobe ColdFusion 10 before Update 16 and 11 before Updat
Cross-site scripting (XSS) vulnerability in Adobe ColdFusion 10 before Update 16 and 11 before Update 5 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
nvd
CVE-2015-8052P4MEDIUMCVSS 4.3≤ 10.0≤ 11.02015-11-18
CVE-2015-8052 [MEDIUM] CWE-79 CVE-2015-8052: Cross-site scripting (XSS) vulnerability in Adobe ColdFusion 10 before Update 18 and 11 before Updat
Cross-site scripting (XSS) vulnerability in Adobe ColdFusion 10 before Update 18 and 11 before Update 7 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2015-8053.
nvd
CVE-2015-8053P4MEDIUMCVSS 4.3≤ 10.0≤ 11.02015-11-18
CVE-2015-8053 [MEDIUM] CVE-2015-8053: Cross-site scripting (XSS) vulnerability in Adobe ColdFusion 10 before Update 18 and 11 before Updat
Cross-site scripting (XSS) vulnerability in Adobe ColdFusion 10 before Update 18 and 11 before Update 7 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2015-8052.
nvd
CVE-2009-1876P4MEDIUMCVSS 5.0≤ 8.0.1v6.0+6 more2009-08-18
CVE-2009-1876 [MEDIUM] CVE-2009-1876: Adobe ColdFusion 8.0.1 and earlier might allow attackers to obtain sensitive information via unspeci
Adobe ColdFusion 8.0.1 and earlier might allow attackers to obtain sensitive information via unspecified vectors, related to a "double-encoded null character vulnerability."
nvd
CVE-2014-0571P4MEDIUMCVSS 4.3v9.0v9.0.1+3 more2014-10-15
CVE-2014-0571 [MEDIUM] CWE-79 CVE-2014-0571: Cross-site scripting (XSS) vulnerability in Adobe ColdFusion 9.0 before Update 13, 9.0.1 before Upda
Cross-site scripting (XSS) vulnerability in Adobe ColdFusion 9.0 before Update 13, 9.0.1 before Update 12, 9.0.2 before Update 7, 10 before Update 14, and 11 before Update 2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
nvd
CVE-2025-49539P4MEDIUMCVSS 4.5v2021v2023+2 more2025-07-08
CVE-2025-49539 [MEDIUM] CWE-611 CVE-2025-49539: ColdFusion versions 2025.2, 2023.14, 2021.20 and earlier are affected by an Improper Restriction of
ColdFusion versions 2025.2, 2023.14, 2021.20 and earlier are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could result in a security feature bypass. A high-privileged attacker could leverage this vulnerability to access sensitive information. Exploitation of this issue does not require user interacti
nvd
CVE-2012-2048P4MEDIUMCVSS 5.0≤ 10.0v8.0+4 more2012-09-12
CVE-2012-2048 [MEDIUM] CVE-2012-2048: Unspecified vulnerability in Adobe ColdFusion 10 and earlier allows attackers to cause a denial of s
Unspecified vulnerability in Adobe ColdFusion 10 and earlier allows attackers to cause a denial of service via unknown vectors.
nvd
CVE-2011-0734P4MEDIUMCVSS 4.3≤ 9.0.1v4.5+11 more2011-02-01
CVE-2011-0734 [MEDIUM] CWE-79 CVE-2011-0734: Cross-site scripting (XSS) vulnerability in Adobe ColdFusion before 9.0.1 CHF1 allows remote attacke
Cross-site scripting (XSS) vulnerability in Adobe ColdFusion before 9.0.1 CHF1 allows remote attackers to inject arbitrary web script or HTML via an id parameter containing a JavaScript onLoad event handler for a BODY element, related to a "tag body" attack. NOTE: this was originally reported as affecting 9.0.1 CHF1 and earlier.
nvd
CVE-2011-0581P4MEDIUMCVSS 4.3v8.0v8.0.1+2 more2011-02-10
CVE-2011-0581 [MEDIUM] CWE-20 CVE-2011-0581: Multiple CRLF injection vulnerabilities in Adobe ColdFusion 8.0 through 9.0.1 allow remote attackers
Multiple CRLF injection vulnerabilities in Adobe ColdFusion 8.0 through 9.0.1 allow remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified tags.
nvd
CVE-2011-0737P4MEDIUMCVSS 5.3≤ 9.0.1v4.5+11 more2011-02-01
CVE-2011-0737 [MEDIUM] CWE-200 CVE-2011-0737: Adobe ColdFusion 9.0.1 CHF1 and earlier allows remote attackers to obtain sensitive information via
Adobe ColdFusion 9.0.1 CHF1 and earlier allows remote attackers to obtain sensitive information via an id=- query to a .cfm file, which reveals the installation path in an error message. NOTE: the vendor disputes the significance of this issue because the Site-wide Error Handler and Debug Output Settings sections of the ColdFusion Lockdown guide explai
nvd
CVE-2006-4724P4MEDIUMCVSS 5.0v7.0v7.0.12006-09-14
CVE-2006-4724 [MEDIUM] CVE-2006-4724: Unspecified vulnerability in the ColdFusion Flash Remoting Gateway in Adobe ColdFusion MX 7 and 7.01
Unspecified vulnerability in the ColdFusion Flash Remoting Gateway in Adobe ColdFusion MX 7 and 7.01 allows remote attackers to cause a denial of service (infinite loop) via unspecified vectors involving a crafted command.
nvd
CVE-2011-0735P4MEDIUMCVSS 4.3≤ 9.0.1v4.5+11 more2011-02-01
CVE-2011-0735 [MEDIUM] CWE-79 CVE-2011-0735: Cross-site scripting (XSS) vulnerability in Adobe ColdFusion before 9.0.1 CHF1 allows remote attacke
Cross-site scripting (XSS) vulnerability in Adobe ColdFusion before 9.0.1 CHF1 allows remote attackers to inject arbitrary web script or HTML via vectors involving a "tag script."
nvd
CVE-2011-0583P4MEDIUMCVSS 4.3v8.0v8.0.1+2 more2011-02-10
CVE-2011-0583 [MEDIUM] CWE-79 CVE-2011-0583: Cross-site scripting (XSS) vulnerability in Adobe ColdFusion 8.0 through 9.0.1 allows remote attacke
Cross-site scripting (XSS) vulnerability in Adobe ColdFusion 8.0 through 9.0.1 allows remote attackers to inject arbitrary web script or HTML via the cfform tag.
nvd
CVE-2011-0580P4MEDIUMCVSS 4.3v8.0v8.0.1+2 more2011-02-10
CVE-2011-0580 [MEDIUM] CWE-79 CVE-2011-0580: Multiple cross-site scripting (XSS) vulnerabilities in the administrator console in Adobe ColdFusion
Multiple cross-site scripting (XSS) vulnerabilities in the administrator console in Adobe ColdFusion 8.0 through 9.0.1 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
nvd
CVE-2014-5315P4MEDIUMCVSS 4.3≤ 8.0.1v8.02014-09-26
CVE-2014-5315 [MEDIUM] CWE-79 CVE-2014-5315: Cross-site scripting (XSS) vulnerability in the Help page in Adobe Acrobat 9.5.2 and earlier and Col
Cross-site scripting (XSS) vulnerability in the Help page in Adobe Acrobat 9.5.2 and earlier and ColdFusion 8.0.1 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
nvd
CVE-2010-1293P4MEDIUMCVSS 4.3≤ 9.0v4.5+9 more2010-05-13
CVE-2010-1293 [MEDIUM] CWE-79 CVE-2010-1293: Cross-site scripting (XSS) vulnerability in the Administrator page in Adobe ColdFusion 8.0, 8.0.1, a
Cross-site scripting (XSS) vulnerability in the Administrator page in Adobe ColdFusion 8.0, 8.0.1, and 9.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
nvd
CVE-2011-4368P4MEDIUMCVSS 4.3v8.0v8.0.1+2 more2011-12-14
CVE-2011-4368 [MEDIUM] CWE-79 CVE-2011-4368: Cross-site scripting (XSS) vulnerability in Remote Development Services (RDS) in Adobe ColdFusion 8.
Cross-site scripting (XSS) vulnerability in Remote Development Services (RDS) in Adobe ColdFusion 8.0 through 9.0.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
nvd
CVE-2014-0572P4MEDIUMCVSS 4.6v9.0v9.0.1+3 more2014-10-15
CVE-2014-0572 [MEDIUM] CWE-264 CVE-2014-0572: Adobe ColdFusion 9.0 before Update 13, 9.0.1 before Update 12, 9.0.2 before Update 7, 10 before Upda
Adobe ColdFusion 9.0 before Update 13, 9.0.1 before Update 12, 9.0.2 before Update 7, 10 before Update 14, and 11 before Update 2 allows local users to bypass intended IP-based access restrictions via unspecified vectors.
nvd
CVE-2025-49540P4MEDIUMCVSS 4.3v2021v2023+2 more2025-07-08
CVE-2025-49540 [MEDIUM] CWE-79 CVE-2025-49540: ColdFusion versions 2025.2, 2023.14, 2021.20 and earlier are affected by a stored Cross-Site Scripti
ColdFusion versions 2025.2, 2023.14, 2021.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a high-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field,
nvd
CVE-2025-49543P4MEDIUMCVSS 4.3v2021v2023+2 more2025-07-08
CVE-2025-49543 [MEDIUM] CWE-79 CVE-2025-49543: ColdFusion versions 2025.2, 2023.14, 2021.20 and earlier are affected by a stored Cross-Site Scripti
ColdFusion versions 2025.2, 2023.14, 2021.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a high-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field,
nvd