cbcvebase.

Adobe Coldfusion vulnerabilities

240 known vulnerabilities affecting adobe/coldfusion.

Total CVEs
240
CISA KEV
17
actively exploited
Public exploits
23
Exploited in wild
27
Severity breakdown
CRITICAL76HIGH66MEDIUM89LOW9

Vulnerabilities

Page 12 of 12
CVE-2025-49541P4MEDIUMCVSS 4.3v2021v2023+2 more2025-07-08
CVE-2025-49541 [MEDIUM] CWE-79 CVE-2025-49541: ColdFusion versions 2025.2, 2023.14, 2021.20 and earlier are affected by a stored Cross-Site Scripti ColdFusion versions 2025.2, 2023.14, 2021.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a high-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field,
nvd
CVE-2006-5860P4MEDIUMCVSS 4.3v6.1v7.02007-02-14
CVE-2006-5860 [MEDIUM] CWE-79 CVE-2006-5860: Cross-site scripting (XSS) vulnerability in the administrator console for Adobe JRun 4.0, as used in Cross-site scripting (XSS) vulnerability in the administrator console for Adobe JRun 4.0, as used in ColdFusion, allows remote attackers to inject arbitrary web script or HTML via unknown vectors.
nvd
CVE-2009-3467P4MEDIUMCVSS 4.3≤ 9.0v4.5+9 more2010-05-13
CVE-2009-3467 [MEDIUM] CWE-79 CVE-2009-3467: Cross-site scripting (XSS) vulnerability in an unspecified method in Adobe ColdFusion 8.0, 8.0.1, an Cross-site scripting (XSS) vulnerability in an unspecified method in Adobe ColdFusion 8.0, 8.0.1, and 9.0 allows remote attackers to inject arbitrary web script or HTML via unknown vectors.
nvd
CVE-2011-2463P4MEDIUMCVSS 4.3v8.0v8.0.1+2 more2011-12-14
CVE-2011-2463 [MEDIUM] CWE-79 CVE-2011-2463: Cross-site scripting (XSS) vulnerability in Adobe ColdFusion 8.0 through 9.0.1 allows remote attacke Cross-site scripting (XSS) vulnerability in Adobe ColdFusion 8.0 through 9.0.1 allows remote attackers to inject arbitrary web script or HTML via vectors involving the cfform tag.
nvd
CVE-2006-5859P4MEDIUMCVSS 4.3v7.0v7.0.12007-02-14
CVE-2006-5859 [MEDIUM] CWE-79 CVE-2006-5859: Cross-site scripting (XSS) vulnerability in Adobe ColdFusion MX 7 7.0 and 7.0.1, when Global Script Cross-site scripting (XSS) vulnerability in Adobe ColdFusion MX 7 7.0 and 7.0.1, when Global Script Protection is not enabled, allows remote attackers to inject arbitrary HTML and web script via unknown vectors, possibly related to Linkdirect.cfm, Topnav.cfm, and Welcomedoc.cfm.
nvd
CVE-2008-0643P4MEDIUMCVSS 4.3v7.0v7.0.1+2 more2008-03-12
CVE-2008-0643 [MEDIUM] CWE-79 CVE-2008-0643: Cross-site scripting (XSS) vulnerability in Adobe ColdFusion MX 7 and ColdFusion 8 allows remote att Cross-site scripting (XSS) vulnerability in Adobe ColdFusion MX 7 and ColdFusion 8 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
nvd
CVE-2009-1877P4MEDIUMCVSS 4.3≤ 8.0.1v6.0+7 more2009-08-18
CVE-2009-1877 [MEDIUM] CVE-2009-1877: Cross-site scripting (XSS) vulnerability in Adobe ColdFusion 8.0.1 and earlier allows remote attacke Cross-site scripting (XSS) vulnerability in Adobe ColdFusion 8.0.1 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2009-1875.
nvd
CVE-2009-1875P4MEDIUMCVSS 4.3≤ 8.0.1v6.0+7 more2009-08-18
CVE-2009-1875 [MEDIUM] CWE-79 CVE-2009-1875: Multiple cross-site scripting (XSS) vulnerabilities in Adobe ColdFusion 8.0.1 and earlier allow remo Multiple cross-site scripting (XSS) vulnerabilities in Adobe ColdFusion 8.0.1 and earlier allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2009-1877.
nvd
CVE-2006-6482P4MEDIUMCVSS 5.0v7.02006-12-12
CVE-2006-6482 [MEDIUM] CVE-2006-6482: Adobe ColdFusion MX7 allows remote attackers to obtain sensitive information via a URL request (1) f Adobe ColdFusion MX7 allows remote attackers to obtain sensitive information via a URL request (1) for a non-existent (a) JWS, (b) CFM, (c) CFML, or (d) CFC file, which displays the installation path in the resulting error message; or (2) to /CFIDE/administrator/login.cfm without a host, which can reveal the server's internal IP address in an HREF tag.
nvd
CVE-2006-3978P4MEDIUMCVSS 4.6v7.0v7.0.1+1 more2006-10-10
CVE-2006-3978 [MEDIUM] CVE-2006-3978: Unspecified vulnerability in a Verity third party library, as used on Adobe ColdFusion MX 7 through Unspecified vulnerability in a Verity third party library, as used on Adobe ColdFusion MX 7 through MX 7.0.2 and possibly other products, allows local users to execute arbitrary code via unknown attack vectors.
nvd
CVE-2026-27307P4LOWCVSS 2.4v2023v2023-update1+25 more2026-04-14
CVE-2026-27307 [LOW] CWE-400 CVE-2026-27307: ColdFusion versions 2023.18, 2025.6 and earlier are affected by an Uncontrolled Resource Consumption ColdFusion versions 2023.18, 2025.6 and earlier are affected by an Uncontrolled Resource Consumption vulnerability that could lead to application denial-of-service. A high-privileged attacker could exploit this vulnerability and exhaust system resources, reducing application speed. Exploitation of this issue does not require user interaction.
nvd
CVE-2026-27308P4LOWCVSS 2.4v2023v2023-update1+25 more2026-04-14
CVE-2026-27308 [LOW] CWE-400 CVE-2026-27308: ColdFusion versions 2023.18, 2025.6 and earlier are affected by an Uncontrolled Resource Consumption ColdFusion versions 2023.18, 2025.6 and earlier are affected by an Uncontrolled Resource Consumption vulnerability that could lead to application denial-of-service. A high-privileged attacker could exploit this vulnerability and exhaust system resources, reducing application speed. Exploitation of this issue does not require user interaction.
nvd
CVE-2025-54234P4LOWCVSS 2.7v2021v2023+2 more2025-08-18
CVE-2025-54234 [LOW] CWE-918 CVE-2025-54234: ColdFusion versions 2025.1, 2023.13, 2021.19 and earlier are affected by a Server-Side Request Forge ColdFusion versions 2025.1, 2023.13, 2021.19 and earlier are affected by a Server-Side Request Forgery (SSRF) vulnerability that could lead to limited file system read. A high-privilege authenticated attacker can force the application to make arbitrary requests via injection of arbitrary URLs. Exploitation of this issue does not require user interactio
nvd
CVE-2026-48329P4LOWCVSS 2.7v2023v2023-update1+31 more2026-07-14
CVE-2026-48329 [LOW] CWE-613 CVE-2026-48329: ColdFusion is affected by an Insufficient Session Expiration vulnerability that could result in a Se ColdFusion is affected by an Insufficient Session Expiration vulnerability that could result in a Security feature bypass. A high-privileged attacker could leverage this vulnerability to bypass security measures and gain unauthorized write access. Exploitation of this issue does not require user interaction.
nvd
CVE-2012-5675P4MEDIUMCVSS 4.4v9.0v9.0.1+2 more2012-12-12
CVE-2012-5675 [MEDIUM] CWE-264 CVE-2012-5675: Adobe ColdFusion 9.0 through 9.0.2, and 10, allows local users to bypass intended shared-hosting san Adobe ColdFusion 9.0 through 9.0.2, and 10, allows local users to bypass intended shared-hosting sandbox permissions via unspecified vectors.
nvd
CVE-2006-6483P4LOWCVSS 2.6v7.0v7.0.12006-12-12
CVE-2006-6483 [LOW] CVE-2006-6483: Adobe ColdFusion MX 7.x before 7.0.2 does not properly filter HTML tags when protecting against cros Adobe ColdFusion MX 7.x before 7.0.2 does not properly filter HTML tags when protecting against cross-site scripting (XSS) attacks, which allows remote attackers to inject arbitrary web script or HTML via a NULL byte (%00) in certain HTML tags, as demonstrated using "%00script" in a tag.
nvd
CVE-2006-4725P4MEDIUMCVSS 4.6v7.0v7.0.12006-09-14
CVE-2006-4725 [MEDIUM] CVE-2006-4725: Adobe ColdFusion MX 7 and 7.01 allows local users to bypass security restrictions and call component Adobe ColdFusion MX 7 and 7.01 allows local users to bypass security restrictions and call components (CFC) within a sandbox from CFML templates that are located outside of the sandbox.
nvd
CVE-2006-4726P4LOWCVSS 2.6v6.1v7.0+1 more2006-09-14
CVE-2006-4726 [LOW] CVE-2006-4726: Cross-site scripting (XSS) vulnerability in Adobe ColdFusion MX 6.1 through 7.02 allows remote attac Cross-site scripting (XSS) vulnerability in Adobe ColdFusion MX 6.1 through 7.02 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors involving a ColdFusion error page.
nvd
CVE-2025-49546P4LOWCVSS 2.4v2021v2023+2 more2025-07-08
CVE-2025-49546 [LOW] CWE-284 CVE-2025-49546: ColdFusion versions 2025.2, 2023.14, 2021.20 and earlier are affected by an Improper Access Control ColdFusion versions 2025.2, 2023.14, 2021.20 and earlier are affected by an Improper Access Control vulnerability that could lead to a partial application denial-of-service. A high-privileged attacker could exploit this vulnerability to partially disrupt the availability of the application. Exploitation of this issue does not require user interaction an
nvd
CVE-2010-1294P4LOWCVSS 2.1≤ 9.0v4.5+9 more2010-05-13
CVE-2010-1294 [LOW] CWE-200 CVE-2010-1294: Unspecified vulnerability in Adobe ColdFusion 8.0, 8.0.1, and 9.0 allows local users to obtain sensi Unspecified vulnerability in Adobe ColdFusion 8.0, 8.0.1, and 9.0 allows local users to obtain sensitive information via unknown vectors.
nvd
Adobe Coldfusion vulnerabilities | cvebase