Adobe Coldfusion vulnerabilities
240 known vulnerabilities affecting adobe/coldfusion.
Total CVEs
240
CISA KEV
17
actively exploited
Public exploits
23
Exploited in wild
27
Severity breakdown
CRITICAL76HIGH66MEDIUM89LOW9
Vulnerabilities
Page 5 of 12
CVE-2025-43560P2CRITICALCVSS 9.1v2021v2023+2 more2025-05-13
CVE-2025-43560 [CRITICAL] CWE-20 CVE-2025-43560: ColdFusion versions 2025.1, 2023.13, 2021.19 and earlier are affected by an Improper Input Validatio
ColdFusion versions 2025.1, 2023.13, 2021.19 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. A high-privileged attacker could leverage this vulnerability to bypass security mechanisms and execute code. Exploitation of this issue does not require
nvd
CVE-2022-42340P3HIGHCVSS 7.5v2018v2021+1 more2022-10-14
CVE-2022-42340 [HIGH] CWE-20 CVE-2022-42340: Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are affected by an Impr
Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are affected by an Improper Input Validation vulnerability that could result in arbitrary file system read. Exploitation of this issue does not require user interaction.
nvd
CVE-2025-24447P2CRITICALCVSS 9.1v2021v2023+2 more2025-04-08
CVE-2025-24447 [CRITICAL] CWE-502 CVE-2025-24447: ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by a Deserialization of Untrus
ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could result in arbitrary code execution in the context of the current user resulting in a High impact to Confidentiality and Integrity. Exploitation of this issue does not require user interaction.
nvd
CVE-2019-7838P2CRITICALCVSS 9.8v11.0v2016+2 more2019-06-12
CVE-2019-7838 [CRITICAL] CWE-434 CVE-2019-7838: ColdFusion versions Update 3 and earlier, Update 10 and earlier, and Update 18 and earlier have a fi
ColdFusion versions Update 3 and earlier, Update 10 and earlier, and Update 18 and earlier have a file extension blacklist bypass vulnerability. Successful exploitation could lead to arbitrary code execution.
nvd
CVE-2025-30285P3HIGHCVSS 8.4v2021v2023+2 more2025-04-08
CVE-2025-30285 [HIGH] CWE-502 CVE-2025-30285: ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by a Deserialization of Untrus
ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could result in arbitrary code execution in the context of the current user. A high-privileged attacker could leverage this vulnerability to bypass security protections and execute code. Exploitation of this issue requires us
nvd
CVE-2026-27304P2CRITICALCVSS 9.3v2023v2023-update1+25 more2026-04-14
CVE-2026-27304 [CRITICAL] CWE-20 CVE-2026-27304: ColdFusion versions 2023.18, 2025.6 and earlier are affected by an Improper Input Validation vulnera
ColdFusion versions 2023.18, 2025.6 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction.
nvd
CVE-2026-48315P2CRITICALCVSS 9.3v2023v2023-update1+30 more2026-06-30
CVE-2026-48315 [CRITICAL] CWE-20 CVE-2026-48315: ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Input Validation vulnera
ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to inject malicious scripts into a web page, potentially gaining elevated access or control over the victim's accoun
nvd
CVE-2025-61809P2CRITICALCVSS 9.1v2021v2023+2 more2025-12-10
CVE-2025-61809 [CRITICAL] CWE-20 CVE-2025-61809: ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Improper Input Validatio
ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized read and write access. Exploitation of this issue does not require user interaction and sc
nvd
CVE-2026-48285P3HIGHCVSS 8.6v2023v2023-update1+30 more2026-06-30
CVE-2026-48285 [HIGH] CWE-918 CVE-2026-48285: ColdFusion versions 2025.9, 2023.20 and earlier are affected by a Server-Side Request Forgery (SSRF)
ColdFusion versions 2025.9, 2023.20 and earlier are affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized read access. Exploitation of this issue does not require user interaction. Scope is changed.
nvd
CVE-2024-53961P3HIGHCVSS 8.1v2021v2023+1 more2024-12-23
CVE-2024-53961 [HIGH] CWE-22 CVE-2024-53961: ColdFusion versions 2023.11, 2021.17 and earlier are affected by an Improper Limitation of a Pathnam
ColdFusion versions 2023.11, 2021.17 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to access files or directories that are outside of the restricted directory set by the application. T
nvd
CVE-2025-61811P2CRITICALCVSS 9.1v2021v2023+2 more2025-12-10
CVE-2025-61811 [CRITICAL] CWE-22 CVE-2025-61811: ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Improper Access Control
ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Improper Access Control vulnerability that could result in arbitrary code execution in the context of the current user. A high privileged attacker could leverage this vulnerability to bypass security measures and execute malicious code. Exploitation of this issue does not re
nvd
CVE-2025-30282P3CRITICALCVSS 9.1v2021v2023+2 more2025-04-08
CVE-2025-30282 [CRITICAL] CWE-287 CVE-2025-30282: ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by an Improper Authentication
ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by an Improper Authentication vulnerability that could result in arbitrary code execution in the context of the current user. A high-privileged attacker could leverage this vulnerability to bypass authentication mechanisms and execute code. Exploitation of this issue does not req
nvd
CVE-2026-48320P3CRITICALCVSS 9.6v2023v2023-update1+31 more2026-07-14
CVE-2026-48320 [CRITICAL] CWE-79 CVE-2026-48320: ColdFusion is affected by a reflected Cross-Site Scripting (XSS) vulnerability. An attacker could ex
ColdFusion is affected by a reflected Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this vulnerability to inject malicious scripts into a web page, potentially gaining elevated access or control over the victim's account or session. Exploitation of this issue requires user interaction in that a victim must open a malicious fil
nvd
CVE-2026-48325P3CRITICALCVSS 9.3v2023v2023-update1+31 more2026-07-14
CVE-2026-48325 [CRITICAL] CWE-306 CVE-2026-48325: ColdFusion is affected by a Missing Authentication for Critical Function vulnerability that could re
ColdFusion is affected by a Missing Authentication for Critical Function vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed.
nvd
CVE-2026-34619P3HIGHCVSS 7.7v2023v2023-update1+25 more2026-04-14
CVE-2026-34619 [HIGH] CWE-22 CVE-2026-34619: ColdFusion versions 2023.18, 2025.6 and earlier are affected by an Improper Limitation of a Pathname
ColdFusion versions 2023.18, 2025.6 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to access unauthorized files or directories outside the intended restrictions. Exploitation of this
nvd
CVE-2026-47930P3HIGHCVSS 8.1v2023v2023-update1+28 more2026-06-09
CVE-2026-47930 [HIGH] CWE-20 CVE-2026-47930: ColdFusion versions 2023.19, 2025.8 and earlier are affected by an Improper Input Validation vulnera
ColdFusion versions 2023.19, 2025.8 and earlier are affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and gain unauthorized read and write access. Exploitation of this issue does not require user interaction.
nvd
CVE-2019-8073P3CRITICALCVSS 9.8v2016v20182019-09-27
CVE-2019-8073 [CRITICAL] CWE-77 CVE-2019-8073: ColdFusion 2018- update 4 and earlier and ColdFusion 2016- update 11 and earlier have a Command Inje
ColdFusion 2018- update 4 and earlier and ColdFusion 2016- update 11 and earlier have a Command Injection via Vulnerable component vulnerability. Successful exploitation could lead to Arbitrary code execution in the context of the current user.
nvd
CVE-2026-47931P3CRITICALCVSS 9.1v2023v2023-update1+28 more2026-06-09
CVE-2026-47931 [CRITICAL] CWE-20 CVE-2026-47931: ColdFusion versions 2023.19, 2025.8 and earlier are affected by an Improper Input Validation vulnera
ColdFusion versions 2023.19, 2025.8 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. An attacker with high privileges could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope
nvd
CVE-2025-61810P3HIGHCVSS 8.4v2021v2023+2 more2025-12-10
CVE-2025-61810 [HIGH] CWE-502 CVE-2025-61810: ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by a Deserialization of Untrus
ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could result in arbitrary code execution in the context of the current user. A high privileged attacker could exploit this vulnerability by providing maliciously crafted serialized data to the application. Exploitation of thi
nvd
CVE-2020-3794P3CRITICALCVSS 9.8v2016v2018+1 more2020-03-25
CVE-2020-3794 [CRITICAL] CWE-829 CVE-2020-3794: ColdFusion versions ColdFusion 2016, and ColdFusion 2018 have a file inclusion vulnerability. Succes
ColdFusion versions ColdFusion 2016, and ColdFusion 2018 have a file inclusion vulnerability. Successful exploitation could lead to arbitrary code execution of files located in the webroot or its subdirectory.
nvd