cbcvebase.

Adobe Coldfusion vulnerabilities

240 known vulnerabilities affecting adobe/coldfusion.

Total CVEs
240
CISA KEV
17
actively exploited
Public exploits
23
Exploited in wild
27
Severity breakdown
CRITICAL76HIGH66MEDIUM89LOW9

Vulnerabilities

Page 2 of 12
CVE-2023-26347P1HIGHCVSS 7.5ExploitedPoCfixed in 2021v2021+2 more2023-11-17
CVE-2023-26347 [HIGH] CWE-284 CVE-2023-26347: Adobe ColdFusion versions 2023.5 (and earlier) and 2021.11 (and earlier) are affected by an Improper Adobe ColdFusion versions 2023.5 (and earlier) and 2021.11 (and earlier) are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. An unauthenticated attacker could leverage this vulnerability to access the administration CFM and CFC endpoints. Exploitation of this issue does not require user interaction.
nvd
CVE-2021-21087P2MEDIUMCVSS 5.4ExploitedPoCv2016v2018+2 more2021-04-15
CVE-2021-21087 [MEDIUM] CWE-79 CVE-2021-21087: Adobe Coldfusion versions 2016 (update 16 and earlier), 2018 (update 10 and earlier) and 2021.0.0.32 Adobe Coldfusion versions 2016 (update 16 and earlier), 2018 (update 10 and earlier) and 2021.0.0.323925 are affected by an Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability. An attacker could abuse this vulnerability to execute arbitrary JavaScript code in context of the current user. Exploitation of
nvd
CVE-2023-38204P1CRITICALCVSS 9.8Exploitedv2018v2021+1 more2023-09-14
CVE-2023-38204 [CRITICAL] CVE-2023-38204: Adobe ColdFusion versions 2018u18 (and earlier), 2021u8 (and earlier) and 2023u2 (and earlier) are a Adobe ColdFusion versions 2018u18 (and earlier), 2021u8 (and earlier) and 2023u2 (and earlier) are affected by a Deserialization of Untrusted Data vulnerability that could result in Arbitrary code execution. Exploitation of this issue does not require user interaction.
nvd
CVE-2009-1872P2MEDIUMCVSS 4.3ExploitedPoC≤ 8.0.1v6.0+7 more2009-08-18
CVE-2009-1872 [MEDIUM] CWE-79 CVE-2009-1872: Multiple cross-site scripting (XSS) vulnerabilities in Adobe ColdFusion Server 8.0.1, 8, and earlier Multiple cross-site scripting (XSS) vulnerabilities in Adobe ColdFusion Server 8.0.1, 8, and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the startRow parameter to administrator/logviewer/searchlog.cfm, or the query string to (2) wizards/common/_logintowizard.cfm, (3) wizards/common/_authenticatewizarduser.cfm, or (4) a
nvd
CVE-2019-7816P1CRITICALCVSS 9.8Exploitedv11.0v2016+2 more2019-05-24
CVE-2019-7816 [CRITICAL] CWE-434 CVE-2019-7816: ColdFusion versions Update 2 and earlier, Update 9 and earlier, and Update 17 and earlier have a fil ColdFusion versions Update 2 and earlier, Update 9 and earlier, and Update 17 and earlier have a file upload restriction bypass vulnerability. Successful exploitation could lead to arbitrary code execution.
nvd
CVE-2013-1389P2CRITICALCVSS 10.0Exploitedv9.0v9.0.1+2 more2013-05-16
CVE-2013-1389 [CRITICAL] CVE-2013-1389: Unspecified vulnerability in Adobe ColdFusion 9.0 before Update 11, 9.0.1 before Update 10, 9.0.2 be Unspecified vulnerability in Adobe ColdFusion 9.0 before Update 11, 9.0.1 before Update 10, 9.0.2 before Update 5, and 10 before Update 10 allows remote attackers to execute arbitrary code via unknown vectors.
nvd
CVE-2013-5326P2LOWCVSS 3.5Exploitedv9.0v9.0.1+3 more2013-11-13
CVE-2013-5326 [LOW] CWE-79 CVE-2013-5326: Cross-site scripting (XSS) vulnerability in Adobe ColdFusion 9.0 before Update 12, 9.0.1 before Upda Cross-site scripting (XSS) vulnerability in Adobe ColdFusion 9.0 before Update 12, 9.0.1 before Update 11, 9.0.2 before Update 6, and 10 before Update 12, when the CFIDE directory is available, allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors related to the logviewer directory.
nvd
CVE-2016-4264P2HIGHCVSS 8.6PoC≤ 10.0≤ 11.02016-09-01
CVE-2016-4264 [HIGH] CWE-611 CVE-2016-4264: The Office Open XML (OOXML) feature in Adobe ColdFusion 10 before Update 21 and 11 before Update 10 The Office Open XML (OOXML) feature in Adobe ColdFusion 10 before Update 21 and 11 before Update 10 allows remote attackers to read arbitrary files or send TCP requests to intranet servers via a crafted OOXML spreadsheet containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.
nvd
CVE-2026-48313P2CRITICALCVSS 9.3PoCv2023v2023-update1+30 more2026-06-30
CVE-2026-48313 [CRITICAL] CWE-22 CVE-2026-48313: ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Limitation of a Pathname ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary file system read and limited write access. An attacker could exploit this vulnerability to access sensitive files and directories outside the intended access sco
nvd
CVE-2022-35711P2CRITICALCVSS 9.8v2018v2021+1 more2022-10-14
CVE-2022-35711 [CRITICAL] CWE-122 CVE-2022-35711: Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are affected by a Heap- Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction, the vulnerability is triggered when a crafted network packet is sent
nvd
CVE-2022-35690P2CRITICALCVSS 9.8v2018v2021+1 more2022-10-14
CVE-2022-35690 [CRITICAL] CWE-121 CVE-2022-35690: Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are affected by a Stack Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction, the vulnerability is triggered when a crafted network packet is sent
nvd
CVE-2023-44350P2CRITICALCVSS 9.8fixed in 2021v2021+2 more2023-11-17
CVE-2023-44350 [CRITICAL] CWE-502 CVE-2023-44350: Adobe ColdFusion versions 2023.5 (and earlier) and 2021.11 (and earlier) are affected by an Deserial Adobe ColdFusion versions 2023.5 (and earlier) and 2021.11 (and earlier) are affected by an Deserialization of Untrusted Data vulnerability that could result in Arbitrary code execution. Exploitation of this issue does not require user interaction.
nvd
CVE-2022-38418P2CRITICALCVSS 9.8v2018v2021+1 more2022-10-14
CVE-2022-38418 [CRITICAL] CWE-22 CVE-2022-38418: Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are affected by an Impr Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction.
nvd
CVE-2023-44351P2CRITICALCVSS 9.8fixed in 2021v2021+2 more2023-11-17
CVE-2023-44351 [CRITICAL] CWE-502 CVE-2023-44351: Adobe ColdFusion versions 2023.5 (and earlier) and 2021.11 (and earlier) are affected by an Deserial Adobe ColdFusion versions 2023.5 (and earlier) and 2021.11 (and earlier) are affected by an Deserialization of Untrusted Data vulnerability that could result in Arbitrary code execution. Exploitation of this issue does not require user interaction.
nvd
CVE-2026-48284P2CRITICALCVSS 9.9v2023v2023-update1+31 more2026-07-14
CVE-2026-48284 [CRITICAL] CWE-20 CVE-2026-48284: ColdFusion is affected by an Improper Input Validation vulnerability that could result in arbitrary ColdFusion is affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed.
nvd
CVE-2026-48319P2CRITICALCVSS 9.9v2023v2023-update1+31 more2026-07-14
CVE-2026-48319 [CRITICAL] CWE-22 CVE-2026-48319: ColdFusion is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Trav ColdFusion is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker with high privileges could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user inte
nvd
CVE-2025-54261P2CRITICALCVSS 10.0v2021v2023+2 more2025-09-09
CVE-2025-54261 [CRITICAL] CWE-22 CVE-2025-54261: ColdFusion versions 2025.3, 2023.15, 2021.21 and earlier are affected by an Improper Limitation of a ColdFusion versions 2025.3, 2023.15, 2021.21 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary code execution by an attacker. The victim must have optional configurations enabled. Scope is changed.
nvd
CVE-2026-48318P2CRITICALCVSS 9.9v2023v2023-update1+31 more2026-07-14
CVE-2026-48318 [CRITICAL] CWE-22 CVE-2026-48318: ColdFusion is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Trav ColdFusion is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to access sensitive files and directories outside the intended access scope. Exploitation of this issue does not require user interactio
nvd
CVE-2022-35710P2CRITICALCVSS 9.8v2018v2021+1 more2022-10-14
CVE-2022-35710 [CRITICAL] CWE-121 CVE-2022-35710: Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are affected by a Stack Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction, the vulnerability is triggered when a crafted network packet is sent
nvd
CVE-2024-41874P2CRITICALCVSS 9.8v2023v2021+1 more2024-09-13
CVE-2024-41874 [CRITICAL] CWE-502 CVE-2024-41874: ColdFusion versions 2023.9, 2021.15 and earlier are affected by a Deserialization of Untrusted Data ColdFusion versions 2023.9, 2021.15 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability by providing crafted input to the application, which when deserialized, leads to execution of malicious code.
nvd
Adobe Coldfusion vulnerabilities | cvebase