Adobe Coldfusion 2023 vulnerabilities
65 known vulnerabilities affecting adobe/coldfusion_2023.
Total CVEs
65
CISA KEV
1
actively exploited
Public exploits
2
Exploited in wild
2
Severity breakdown
CRITICAL22HIGH31MEDIUM9LOW3
Vulnerabilities
Page 4 of 4
CVE-2026-48384P4MEDIUMCVSS 4.9≤ 2023.0.222026-08-11
CVE-2026-48384 [MEDIUM] CWE-20 CVE-2026-48384: ColdFusion is affected by an Improper Input Validation vulnerability that could result in an applica
ColdFusion is affected by an Improper Input Validation vulnerability that could result in an application denial-of-service. An attacker with high privileges could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this issue does not require user interaction.
nvd
CVE-2026-47933P4MEDIUMCVSS 4.8≤ 192026-06-09
CVE-2026-47933 [MEDIUM] CWE-79 CVE-2026-47933: ColdFusion versions 2023.19, 2025.8 and earlier are affected by a stored Cross-Site Scripting (XSS)
ColdFusion versions 2023.19, 2025.8 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. The vulnera
nvd
CVE-2026-27307P4LOWCVSS 2.4≤ 182026-04-14
CVE-2026-27307 [LOW] CWE-400 CVE-2026-27307: ColdFusion versions 2023.18, 2025.6 and earlier are affected by an Uncontrolled Resource Consumption
ColdFusion versions 2023.18, 2025.6 and earlier are affected by an Uncontrolled Resource Consumption vulnerability that could lead to application denial-of-service. A high-privileged attacker could exploit this vulnerability and exhaust system resources, reducing application speed. Exploitation of this issue does not require user interaction.
nvd
CVE-2026-27308P4LOWCVSS 2.4≤ 182026-04-14
CVE-2026-27308 [LOW] CWE-400 CVE-2026-27308: ColdFusion versions 2023.18, 2025.6 and earlier are affected by an Uncontrolled Resource Consumption
ColdFusion versions 2023.18, 2025.6 and earlier are affected by an Uncontrolled Resource Consumption vulnerability that could lead to application denial-of-service. A high-privileged attacker could exploit this vulnerability and exhaust system resources, reducing application speed. Exploitation of this issue does not require user interaction.
nvd
CVE-2026-48329P4LOWCVSS 2.7≤ 212026-07-14
CVE-2026-48329 [LOW] CWE-613 CVE-2026-48329: ColdFusion is affected by an Insufficient Session Expiration vulnerability that could result in a Se
ColdFusion is affected by an Insufficient Session Expiration vulnerability that could result in a Security feature bypass. A high-privileged attacker could leverage this vulnerability to bypass security measures and gain unauthorized write access. Exploitation of this issue does not require user interaction.
nvd
← Previous4 / 4