cbcvebase.

Adobe Coldfusion vulnerabilities

240 known vulnerabilities affecting adobe/coldfusion.

Total CVEs
240
CISA KEV
17
actively exploited
Public exploits
23
Exploited in wild
27
Severity breakdown
CRITICAL76HIGH66MEDIUM89LOW9

Vulnerabilities

Page 5 of 12
CVE-2025-43560P2CRITICALCVSS 9.1v2021v2023+2 more2025-05-13
CVE-2025-43560 [CRITICAL] CWE-20 CVE-2025-43560: ColdFusion versions 2025.1, 2023.13, 2021.19 and earlier are affected by an Improper Input Validatio ColdFusion versions 2025.1, 2023.13, 2021.19 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. A high-privileged attacker could leverage this vulnerability to bypass security mechanisms and execute code. Exploitation of this issue does not require
nvd
CVE-2022-42340P3HIGHCVSS 7.5v2018v2021+1 more2022-10-14
CVE-2022-42340 [HIGH] CWE-20 CVE-2022-42340: Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are affected by an Impr Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are affected by an Improper Input Validation vulnerability that could result in arbitrary file system read. Exploitation of this issue does not require user interaction.
nvd
CVE-2025-24447P2CRITICALCVSS 9.1v2021v2023+2 more2025-04-08
CVE-2025-24447 [CRITICAL] CWE-502 CVE-2025-24447: ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by a Deserialization of Untrus ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could result in arbitrary code execution in the context of the current user resulting in a High impact to Confidentiality and Integrity. Exploitation of this issue does not require user interaction.
nvd
CVE-2019-7838P2CRITICALCVSS 9.8v11.0v2016+2 more2019-06-12
CVE-2019-7838 [CRITICAL] CWE-434 CVE-2019-7838: ColdFusion versions Update 3 and earlier, Update 10 and earlier, and Update 18 and earlier have a fi ColdFusion versions Update 3 and earlier, Update 10 and earlier, and Update 18 and earlier have a file extension blacklist bypass vulnerability. Successful exploitation could lead to arbitrary code execution.
nvd
CVE-2025-30285P3HIGHCVSS 8.4v2021v2023+2 more2025-04-08
CVE-2025-30285 [HIGH] CWE-502 CVE-2025-30285: ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by a Deserialization of Untrus ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could result in arbitrary code execution in the context of the current user. A high-privileged attacker could leverage this vulnerability to bypass security protections and execute code. Exploitation of this issue requires us
nvd
CVE-2026-27304P2CRITICALCVSS 9.3v2023v2023-update1+25 more2026-04-14
CVE-2026-27304 [CRITICAL] CWE-20 CVE-2026-27304: ColdFusion versions 2023.18, 2025.6 and earlier are affected by an Improper Input Validation vulnera ColdFusion versions 2023.18, 2025.6 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction.
nvd
CVE-2026-48315P2CRITICALCVSS 9.3v2023v2023-update1+30 more2026-06-30
CVE-2026-48315 [CRITICAL] CWE-20 CVE-2026-48315: ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Input Validation vulnera ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to inject malicious scripts into a web page, potentially gaining elevated access or control over the victim's accoun
nvd
CVE-2025-61809P2CRITICALCVSS 9.1v2021v2023+2 more2025-12-10
CVE-2025-61809 [CRITICAL] CWE-20 CVE-2025-61809: ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Improper Input Validatio ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized read and write access. Exploitation of this issue does not require user interaction and sc
nvd
CVE-2026-48285P3HIGHCVSS 8.6v2023v2023-update1+30 more2026-06-30
CVE-2026-48285 [HIGH] CWE-918 CVE-2026-48285: ColdFusion versions 2025.9, 2023.20 and earlier are affected by a Server-Side Request Forgery (SSRF) ColdFusion versions 2025.9, 2023.20 and earlier are affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized read access. Exploitation of this issue does not require user interaction. Scope is changed.
nvd
CVE-2024-53961P3HIGHCVSS 8.1v2021v2023+1 more2024-12-23
CVE-2024-53961 [HIGH] CWE-22 CVE-2024-53961: ColdFusion versions 2023.11, 2021.17 and earlier are affected by an Improper Limitation of a Pathnam ColdFusion versions 2023.11, 2021.17 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to access files or directories that are outside of the restricted directory set by the application. T
nvd
CVE-2025-61811P2CRITICALCVSS 9.1v2021v2023+2 more2025-12-10
CVE-2025-61811 [CRITICAL] CWE-22 CVE-2025-61811: ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Improper Access Control ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Improper Access Control vulnerability that could result in arbitrary code execution in the context of the current user. A high privileged attacker could leverage this vulnerability to bypass security measures and execute malicious code. Exploitation of this issue does not re
nvd
CVE-2025-30282P3CRITICALCVSS 9.1v2021v2023+2 more2025-04-08
CVE-2025-30282 [CRITICAL] CWE-287 CVE-2025-30282: ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by an Improper Authentication ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by an Improper Authentication vulnerability that could result in arbitrary code execution in the context of the current user. A high-privileged attacker could leverage this vulnerability to bypass authentication mechanisms and execute code. Exploitation of this issue does not req
nvd
CVE-2026-48320P3CRITICALCVSS 9.6v2023v2023-update1+31 more2026-07-14
CVE-2026-48320 [CRITICAL] CWE-79 CVE-2026-48320: ColdFusion is affected by a reflected Cross-Site Scripting (XSS) vulnerability. An attacker could ex ColdFusion is affected by a reflected Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this vulnerability to inject malicious scripts into a web page, potentially gaining elevated access or control over the victim's account or session. Exploitation of this issue requires user interaction in that a victim must open a malicious fil
nvd
CVE-2026-48325P3CRITICALCVSS 9.3v2023v2023-update1+31 more2026-07-14
CVE-2026-48325 [CRITICAL] CWE-306 CVE-2026-48325: ColdFusion is affected by a Missing Authentication for Critical Function vulnerability that could re ColdFusion is affected by a Missing Authentication for Critical Function vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed.
nvd
CVE-2026-34619P3HIGHCVSS 7.7v2023v2023-update1+25 more2026-04-14
CVE-2026-34619 [HIGH] CWE-22 CVE-2026-34619: ColdFusion versions 2023.18, 2025.6 and earlier are affected by an Improper Limitation of a Pathname ColdFusion versions 2023.18, 2025.6 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to access unauthorized files or directories outside the intended restrictions. Exploitation of this
nvd
CVE-2026-47930P3HIGHCVSS 8.1v2023v2023-update1+28 more2026-06-09
CVE-2026-47930 [HIGH] CWE-20 CVE-2026-47930: ColdFusion versions 2023.19, 2025.8 and earlier are affected by an Improper Input Validation vulnera ColdFusion versions 2023.19, 2025.8 and earlier are affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and gain unauthorized read and write access. Exploitation of this issue does not require user interaction.
nvd
CVE-2019-8073P3CRITICALCVSS 9.8v2016v20182019-09-27
CVE-2019-8073 [CRITICAL] CWE-77 CVE-2019-8073: ColdFusion 2018- update 4 and earlier and ColdFusion 2016- update 11 and earlier have a Command Inje ColdFusion 2018- update 4 and earlier and ColdFusion 2016- update 11 and earlier have a Command Injection via Vulnerable component vulnerability. Successful exploitation could lead to Arbitrary code execution in the context of the current user.
nvd
CVE-2026-47931P3CRITICALCVSS 9.1v2023v2023-update1+28 more2026-06-09
CVE-2026-47931 [CRITICAL] CWE-20 CVE-2026-47931: ColdFusion versions 2023.19, 2025.8 and earlier are affected by an Improper Input Validation vulnera ColdFusion versions 2023.19, 2025.8 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. An attacker with high privileges could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope
nvd
CVE-2025-61810P3HIGHCVSS 8.4v2021v2023+2 more2025-12-10
CVE-2025-61810 [HIGH] CWE-502 CVE-2025-61810: ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by a Deserialization of Untrus ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could result in arbitrary code execution in the context of the current user. A high privileged attacker could exploit this vulnerability by providing maliciously crafted serialized data to the application. Exploitation of thi
nvd
CVE-2020-3794P3CRITICALCVSS 9.8v2016v2018+1 more2020-03-25
CVE-2020-3794 [CRITICAL] CWE-829 CVE-2020-3794: ColdFusion versions ColdFusion 2016, and ColdFusion 2018 have a file inclusion vulnerability. Succes ColdFusion versions ColdFusion 2016, and ColdFusion 2018 have a file inclusion vulnerability. Successful exploitation could lead to arbitrary code execution of files located in the webroot or its subdirectory.
nvd
Adobe Coldfusion vulnerabilities | cvebase