cbcvebase.

Adobe Coldfusion vulnerabilities

240 known vulnerabilities affecting adobe/coldfusion.

Total CVEs
240
CISA KEV
17
actively exploited
Public exploits
23
Exploited in wild
27
Severity breakdown
CRITICAL76HIGH66MEDIUM89LOW9

Vulnerabilities

Page 8 of 12
CVE-2026-48363P3HIGHCVSS 8.2v2023v2023-update1+30 more2026-07-13
CVE-2026-48363 [HIGH] CWE-427 CVE-2026-48363: ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Uncontrolled Search Path Element ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Uncontrolled Search Path Element vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.
nvd
CVE-2026-48314P3MEDIUMCVSS 6.5v2023v2023-update1+30 more2026-06-30
CVE-2026-48314 [MEDIUM] CWE-22 CVE-2026-48314: ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Limitation of a Pathname ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to gain limited read and write access to unauthorized files or directories outside the intended re
nvd
CVE-2023-44355P3MEDIUMCVSS 4.3fixed in 2021v2021+2 more2023-11-17
CVE-2023-44355 [MEDIUM] CWE-20 CVE-2023-44355: Adobe ColdFusion versions 2023.5 (and earlier) and 2021.11 (and earlier) are affected by an Improper Adobe ColdFusion versions 2023.5 (and earlier) and 2021.11 (and earlier) are affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. An unauthenticated attacker could leverage this vulnerability to impact a minor integrity feature. Exploitation of this issue does require user interaction.
nvd
CVE-2007-0817P4MEDIUMCVSS 4.3PoCv6.1v7.0.1+1 more2007-02-07
CVE-2007-0817 [MEDIUM] CVE-2007-0817: Cross-site scripting (XSS) vulnerability in Adobe ColdFusion web server allows remote attackers to i Cross-site scripting (XSS) vulnerability in Adobe ColdFusion web server allows remote attackers to inject arbitrary HTML or web script via the User-Agent HTTP header, which is not sanitized before being displayed in an error page.
nvd
CVE-2025-30288P3HIGHCVSS 8.2v2021v2023+2 more2025-04-08
CVE-2025-30288 [HIGH] CWE-284 CVE-2025-30288: ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by an Improper Access Control ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. A low privileged attacker with local access could leverage this vulnerability to bypass security protections and execute code. Exploitation of this issue requires user interaction in that a vi
nvd
CVE-2025-61821P3MEDIUMCVSS 6.8v2021v2021-update1+44 more2025-12-10
CVE-2025-61821 [MEDIUM] CWE-611 CVE-2025-61821: ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Improper Restriction of ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to access sensitive files and data on the server. Exploit depends on conditions beyond the attacker's contro
nvd
CVE-2020-10145P3HIGHCVSS 7.8v2016v2018+1 more2021-05-27
CVE-2020-10145 [HIGH] CWE-284 CVE-2020-10145: The Adobe ColdFusion installer fails to set a secure access-control list (ACL) on the default instal The Adobe ColdFusion installer fails to set a secure access-control list (ACL) on the default installation directory, such as C:\ColdFusion2021\. By default, unprivileged users can create files in this directory structure, which creates a privilege-escalation vulnerability.
nvd
CVE-2018-4938P3HIGHCVSS 7.8v11.0v20162018-05-19
CVE-2018-4938 [HIGH] CWE-427 CVE-2018-4938: Adobe ColdFusion Update 5 and earlier versions, ColdFusion 11 Update 13 and earlier versions have an Adobe ColdFusion Update 5 and earlier versions, ColdFusion 11 Update 13 and earlier versions have an exploitable Insecure Library Loading vulnerability. Successful exploitation could lead to local privilege escalation.
nvd
CVE-2025-30293P3MEDIUMCVSS 6.8v2021v2023+2 more2025-04-08
CVE-2025-30293 [MEDIUM] CWE-20 CVE-2025-30293: ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by an Improper Input Validatio ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by an Improper Input Validation vulnerability that could result in a security feature bypass. A high-privileged attacker could leverage this vulnerability to bypass security protections and gain unauthorized write access. Exploitation of this issue does not require user interaction
nvd
CVE-2025-30292P4MEDIUMCVSS 6.1v2021v2023+2 more2025-04-08
CVE-2025-30292 [MEDIUM] CWE-79 CVE-2025-30292: ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by a reflected Cross-Site Scri ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser.
nvd
CVE-2013-1388P3HIGHCVSS 7.5v9.0v9.0.1+2 more2013-04-10
CVE-2013-1388 [HIGH] CVE-2013-1388: Unspecified vulnerability in Adobe ColdFusion 9.0 before Update 10, 9.0.1 before Update 9, 9.0.2 bef Unspecified vulnerability in Adobe ColdFusion 9.0 before Update 10, 9.0.1 before Update 9, 9.0.2 before Update 4, and 10 before Update 9 allows attackers to obtain administrator-console access via unknown vectors.
nvd
CVE-2026-48338P3MEDIUMCVSS 6.8v2023v2023-update1+31 more2026-07-14
CVE-2026-48338 [MEDIUM] CWE-22 CVE-2026-48338: ColdFusion is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Trav ColdFusion is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to access sensitive files and directories outside the intended access scope. Exploitation of this issue does not require user interaction.
nvd
CVE-2020-9672P3HIGHCVSS 7.8v2016v20182020-07-17
CVE-2020-9672 [HIGH] CWE-426 CVE-2020-9672: Adobe ColdFusion 2016 update 15 and earlier versions, and ColdFusion 2018 update 9 and earlier versi Adobe ColdFusion 2016 update 15 and earlier versions, and ColdFusion 2018 update 9 and earlier versions have a dll search-order hijacking vulnerability. Successful exploitation could lead to privilege escalation.
nvd
CVE-2020-9673P3HIGHCVSS 7.8v2016v20182020-07-17
CVE-2020-9673 [HIGH] CWE-426 CVE-2020-9673: Adobe ColdFusion 2016 update 15 and earlier versions, and ColdFusion 2018 update 9 and earlier versi Adobe ColdFusion 2016 update 15 and earlier versions, and ColdFusion 2018 update 9 and earlier versions have a dll search-order hijacking vulnerability. Successful exploitation could lead to privilege escalation.
nvd
CVE-2007-5905P4MEDIUMCVSS 6.8v7.0v8.02007-11-15
CVE-2007-5905 [MEDIUM] CWE-255 CVE-2007-5905: Adobe ColdFusion 8 and MX 7 allows remote attackers to hijack sessions via unspecified vectors that Adobe ColdFusion 8 and MX 7 allows remote attackers to hijack sessions via unspecified vectors that trigger establishment of a session to a ColdFusion application in which the (1) CFID or (2) CFTOKEN cookies have empty values, possibly due to a session fixation vulnerability.
nvd
CVE-2013-1387P4HIGHCVSS 7.5v9.0v9.0.1+2 more2013-04-10
CVE-2013-1387 [HIGH] CVE-2013-1387: Unspecified vulnerability in Adobe ColdFusion 9.0 before Update 10, 9.0.1 before Update 9, 9.0.2 bef Unspecified vulnerability in Adobe ColdFusion 9.0 before Update 10, 9.0.1 before Update 9, 9.0.2 before Update 4, and 10 before Update 9 allows attackers to impersonate users via unknown vectors.
nvd
CVE-2008-1656P3HIGHCVSS 7.5v8.0v8.12008-04-09
CVE-2008-1656 [HIGH] CVE-2008-1656: Adobe ColdFusion 8 and 8.0.1 does not properly implement the public access level for CFC methods, wh Adobe ColdFusion 8 and 8.0.1 does not properly implement the public access level for CFC methods, which allows remote attackers to invoke these methods via Flex 2 remoting, a different vulnerability than CVE-2006-4725.
nvd
CVE-2020-3768P4HIGHCVSS 7.8v2016v2018+1 more2020-06-26
CVE-2020-3768 [HIGH] CWE-426 CVE-2020-3768: ColdFusion versions ColdFusion 2016, and ColdFusion 2018 have a dll search-order hijacking vulnerabi ColdFusion versions ColdFusion 2016, and ColdFusion 2018 have a dll search-order hijacking vulnerability. Successful exploitation could lead to privilege escalation.
nvd
CVE-2025-61823P4MEDIUMCVSS 6.2v2021v2023+2 more2025-12-10
CVE-2025-61823 [MEDIUM] CWE-611 CVE-2025-61823: ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Improper Restriction of ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could lead to arbitrary file system read. A high privileged attacker could exploit this vulnerability to access sensitive files and data on the server. Exploitation of this issue requires user in
nvd
CVE-2025-64898P4MEDIUMCVSS 5.3v2021v2021-update1+44 more2025-12-10
CVE-2025-64898 [MEDIUM] CWE-522 CVE-2025-64898: ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Insufficiently Protected ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Insufficiently Protected Credentials vulnerability that could result in limited unauthorized write access. An attacker could leverage this vulnerability to gain unauthorized access by exploiting improperly stored or transmitted credentials. Exploitation of this issue does no
nvd
Adobe Coldfusion vulnerabilities | cvebase