Adobe Coldfusion vulnerabilities
240 known vulnerabilities affecting adobe/coldfusion.
Total CVEs
240
CISA KEV
17
actively exploited
Public exploits
23
Exploited in wild
27
Severity breakdown
CRITICAL76HIGH66MEDIUM89LOW9
Vulnerabilities
Page 12 of 12
CVE-2025-49541P4MEDIUMCVSS 4.3v2021v2023+2 more2025-07-08
CVE-2025-49541 [MEDIUM] CWE-79 CVE-2025-49541: ColdFusion versions 2025.2, 2023.14, 2021.20 and earlier are affected by a stored Cross-Site Scripti
ColdFusion versions 2025.2, 2023.14, 2021.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a high-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field,
nvd
CVE-2006-5860P4MEDIUMCVSS 4.3v6.1v7.02007-02-14
CVE-2006-5860 [MEDIUM] CWE-79 CVE-2006-5860: Cross-site scripting (XSS) vulnerability in the administrator console for Adobe JRun 4.0, as used in
Cross-site scripting (XSS) vulnerability in the administrator console for Adobe JRun 4.0, as used in ColdFusion, allows remote attackers to inject arbitrary web script or HTML via unknown vectors.
nvd
CVE-2009-3467P4MEDIUMCVSS 4.3≤ 9.0v4.5+9 more2010-05-13
CVE-2009-3467 [MEDIUM] CWE-79 CVE-2009-3467: Cross-site scripting (XSS) vulnerability in an unspecified method in Adobe ColdFusion 8.0, 8.0.1, an
Cross-site scripting (XSS) vulnerability in an unspecified method in Adobe ColdFusion 8.0, 8.0.1, and 9.0 allows remote attackers to inject arbitrary web script or HTML via unknown vectors.
nvd
CVE-2011-2463P4MEDIUMCVSS 4.3v8.0v8.0.1+2 more2011-12-14
CVE-2011-2463 [MEDIUM] CWE-79 CVE-2011-2463: Cross-site scripting (XSS) vulnerability in Adobe ColdFusion 8.0 through 9.0.1 allows remote attacke
Cross-site scripting (XSS) vulnerability in Adobe ColdFusion 8.0 through 9.0.1 allows remote attackers to inject arbitrary web script or HTML via vectors involving the cfform tag.
nvd
CVE-2006-5859P4MEDIUMCVSS 4.3v7.0v7.0.12007-02-14
CVE-2006-5859 [MEDIUM] CWE-79 CVE-2006-5859: Cross-site scripting (XSS) vulnerability in Adobe ColdFusion MX 7 7.0 and 7.0.1, when Global Script
Cross-site scripting (XSS) vulnerability in Adobe ColdFusion MX 7 7.0 and 7.0.1, when Global Script Protection is not enabled, allows remote attackers to inject arbitrary HTML and web script via unknown vectors, possibly related to Linkdirect.cfm, Topnav.cfm, and Welcomedoc.cfm.
nvd
CVE-2008-0643P4MEDIUMCVSS 4.3v7.0v7.0.1+2 more2008-03-12
CVE-2008-0643 [MEDIUM] CWE-79 CVE-2008-0643: Cross-site scripting (XSS) vulnerability in Adobe ColdFusion MX 7 and ColdFusion 8 allows remote att
Cross-site scripting (XSS) vulnerability in Adobe ColdFusion MX 7 and ColdFusion 8 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
nvd
CVE-2009-1877P4MEDIUMCVSS 4.3≤ 8.0.1v6.0+7 more2009-08-18
CVE-2009-1877 [MEDIUM] CVE-2009-1877: Cross-site scripting (XSS) vulnerability in Adobe ColdFusion 8.0.1 and earlier allows remote attacke
Cross-site scripting (XSS) vulnerability in Adobe ColdFusion 8.0.1 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2009-1875.
nvd
CVE-2009-1875P4MEDIUMCVSS 4.3≤ 8.0.1v6.0+7 more2009-08-18
CVE-2009-1875 [MEDIUM] CWE-79 CVE-2009-1875: Multiple cross-site scripting (XSS) vulnerabilities in Adobe ColdFusion 8.0.1 and earlier allow remo
Multiple cross-site scripting (XSS) vulnerabilities in Adobe ColdFusion 8.0.1 and earlier allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2009-1877.
nvd
CVE-2006-6482P4MEDIUMCVSS 5.0v7.02006-12-12
CVE-2006-6482 [MEDIUM] CVE-2006-6482: Adobe ColdFusion MX7 allows remote attackers to obtain sensitive information via a URL request (1) f
Adobe ColdFusion MX7 allows remote attackers to obtain sensitive information via a URL request (1) for a non-existent (a) JWS, (b) CFM, (c) CFML, or (d) CFC file, which displays the installation path in the resulting error message; or (2) to /CFIDE/administrator/login.cfm without a host, which can reveal the server's internal IP address in an HREF tag.
nvd
CVE-2006-3978P4MEDIUMCVSS 4.6v7.0v7.0.1+1 more2006-10-10
CVE-2006-3978 [MEDIUM] CVE-2006-3978: Unspecified vulnerability in a Verity third party library, as used on Adobe ColdFusion MX 7 through
Unspecified vulnerability in a Verity third party library, as used on Adobe ColdFusion MX 7 through MX 7.0.2 and possibly other products, allows local users to execute arbitrary code via unknown attack vectors.
nvd
CVE-2026-27307P4LOWCVSS 2.4v2023v2023-update1+25 more2026-04-14
CVE-2026-27307 [LOW] CWE-400 CVE-2026-27307: ColdFusion versions 2023.18, 2025.6 and earlier are affected by an Uncontrolled Resource Consumption
ColdFusion versions 2023.18, 2025.6 and earlier are affected by an Uncontrolled Resource Consumption vulnerability that could lead to application denial-of-service. A high-privileged attacker could exploit this vulnerability and exhaust system resources, reducing application speed. Exploitation of this issue does not require user interaction.
nvd
CVE-2026-27308P4LOWCVSS 2.4v2023v2023-update1+25 more2026-04-14
CVE-2026-27308 [LOW] CWE-400 CVE-2026-27308: ColdFusion versions 2023.18, 2025.6 and earlier are affected by an Uncontrolled Resource Consumption
ColdFusion versions 2023.18, 2025.6 and earlier are affected by an Uncontrolled Resource Consumption vulnerability that could lead to application denial-of-service. A high-privileged attacker could exploit this vulnerability and exhaust system resources, reducing application speed. Exploitation of this issue does not require user interaction.
nvd
CVE-2025-54234P4LOWCVSS 2.7v2021v2023+2 more2025-08-18
CVE-2025-54234 [LOW] CWE-918 CVE-2025-54234: ColdFusion versions 2025.1, 2023.13, 2021.19 and earlier are affected by a Server-Side Request Forge
ColdFusion versions 2025.1, 2023.13, 2021.19 and earlier are affected by a Server-Side Request Forgery (SSRF) vulnerability that could lead to limited file system read. A high-privilege authenticated attacker can force the application to make arbitrary requests via injection of arbitrary URLs. Exploitation of this issue does not require user interactio
nvd
CVE-2026-48329P4LOWCVSS 2.7v2023v2023-update1+31 more2026-07-14
CVE-2026-48329 [LOW] CWE-613 CVE-2026-48329: ColdFusion is affected by an Insufficient Session Expiration vulnerability that could result in a Se
ColdFusion is affected by an Insufficient Session Expiration vulnerability that could result in a Security feature bypass. A high-privileged attacker could leverage this vulnerability to bypass security measures and gain unauthorized write access. Exploitation of this issue does not require user interaction.
nvd
CVE-2012-5675P4MEDIUMCVSS 4.4v9.0v9.0.1+2 more2012-12-12
CVE-2012-5675 [MEDIUM] CWE-264 CVE-2012-5675: Adobe ColdFusion 9.0 through 9.0.2, and 10, allows local users to bypass intended shared-hosting san
Adobe ColdFusion 9.0 through 9.0.2, and 10, allows local users to bypass intended shared-hosting sandbox permissions via unspecified vectors.
nvd
CVE-2006-6483P4LOWCVSS 2.6v7.0v7.0.12006-12-12
CVE-2006-6483 [LOW] CVE-2006-6483: Adobe ColdFusion MX 7.x before 7.0.2 does not properly filter HTML tags when protecting against cros
Adobe ColdFusion MX 7.x before 7.0.2 does not properly filter HTML tags when protecting against cross-site scripting (XSS) attacks, which allows remote attackers to inject arbitrary web script or HTML via a NULL byte (%00) in certain HTML tags, as demonstrated using "%00script" in a tag.
nvd
CVE-2006-4725P4MEDIUMCVSS 4.6v7.0v7.0.12006-09-14
CVE-2006-4725 [MEDIUM] CVE-2006-4725: Adobe ColdFusion MX 7 and 7.01 allows local users to bypass security restrictions and call component
Adobe ColdFusion MX 7 and 7.01 allows local users to bypass security restrictions and call components (CFC) within a sandbox from CFML templates that are located outside of the sandbox.
nvd
CVE-2006-4726P4LOWCVSS 2.6v6.1v7.0+1 more2006-09-14
CVE-2006-4726 [LOW] CVE-2006-4726: Cross-site scripting (XSS) vulnerability in Adobe ColdFusion MX 6.1 through 7.02 allows remote attac
Cross-site scripting (XSS) vulnerability in Adobe ColdFusion MX 6.1 through 7.02 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors involving a ColdFusion error page.
nvd
CVE-2025-49546P4LOWCVSS 2.4v2021v2023+2 more2025-07-08
CVE-2025-49546 [LOW] CWE-284 CVE-2025-49546: ColdFusion versions 2025.2, 2023.14, 2021.20 and earlier are affected by an Improper Access Control
ColdFusion versions 2025.2, 2023.14, 2021.20 and earlier are affected by an Improper Access Control vulnerability that could lead to a partial application denial-of-service. A high-privileged attacker could exploit this vulnerability to partially disrupt the availability of the application. Exploitation of this issue does not require user interaction an
nvd
CVE-2010-1294P4LOWCVSS 2.1≤ 9.0v4.5+9 more2010-05-13
CVE-2010-1294 [LOW] CWE-200 CVE-2010-1294: Unspecified vulnerability in Adobe ColdFusion 8.0, 8.0.1, and 9.0 allows local users to obtain sensi
Unspecified vulnerability in Adobe ColdFusion 8.0, 8.0.1, and 9.0 allows local users to obtain sensitive information via unknown vectors.
nvd
← Previous12 / 12