VendorsAdobecoldfusionall versions
Vulnerabilities

Adobe ColdFusion

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

266CVEs
CVE-2018-15961
Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have an unrestricted file upload vulnerability. Successful exploitation could lead to arbitrary code execution.
Published 2018-09-25 · Analyzed
10.0KEV1 PoCEPSS 1.000
CVE-2013-0632
administrator.cfc in Adobe ColdFusion 9.0, 9.0.1, 9.0.2, and 10 allows remote attackers to bypass authentication and possibly execute arbitrary code by logging in to the RDS component using the default empty password and leveraging this session to access the administrative web interface, as exploited in the wild in January 2013.
Published 2013-01-17 · Analyzed
10.0KEV3 PoCEPSS 0.936
CVE-2017-3066
Adobe ColdFusion 2016 Update 3 and earlier, ColdFusion 11 update 11 and earlier, ColdFusion 10 Update 22 and earlier have a Java deserialization vulnerability in the Apache BlazeDS library. Successful exploitation could lead to arbitrary code execution.
Published 2017-04-27 · Analyzed
10.0KEV1 PoCEPSS 0.906
CVE-2019-7816
ColdFusion versions Update 2 and earlier, Update 9 and earlier, and Update 17 and earlier have a file upload restriction bypass vulnerability. Successful exploitation could lead to arbitrary code execution.
Published 2019-05-24 · Modified
10.0EPSS 0.678
CVE-2018-4939
Adobe ColdFusion Update 5 and earlier versions, ColdFusion 11 Update 13 and earlier versions have an exploitable Deserialization of Untrusted Data vulnerability. Successful exploitation could lead to arbitrary code execution.
Published 2018-05-19 · Analyzed
10.0KEVEPSS 0.621
CVE-2019-7839
ColdFusion versions Update 3 and earlier, Update 10 and earlier, and Update 18 and earlier have a command injection vulnerability. Successful exploitation could lead to arbitrary code execution.
Published 2019-06-12 · Modified
10.0EPSS 0.441
CVE-2026-48282
ColdFusion | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)
Published 2026-06-30 · Analyzed
10.0KEVEPSS 0.424
CVE-2018-15957
Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have a deserialization of untrusted data vulnerability. Successful exploitation could lead to arbitrary code execution.
Published 2018-09-25 · Modified
10.0EPSS 0.282
CVE-2018-15959
Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have a deserialization of untrusted data vulnerability. Successful exploitation could lead to arbitrary code execution.
Published 2018-09-25 · Modified
10.0EPSS 0.259
CVE-2018-15958
Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have a deserialization of untrusted data vulnerability. Successful exploitation could lead to arbitrary code execution.
Published 2018-09-25 · Modified
10.0EPSS 0.259
CVE-2018-15965
Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have a deserialization of untrusted data vulnerability. Successful exploitation could lead to arbitrary code execution.
Published 2018-09-25 · Modified
10.0EPSS 0.259
CVE-2019-7091
ColdFusion versions Update 1 and earlier, Update 7 and earlier, and Update 15 and earlier have a deserialization of untrusted data vulnerability. Successful exploitation could lead to arbitrary code execution.
Published 2019-05-24 · Modified
10.0EPSS 0.257
CVE-2025-54261
ColdFusion | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)
Published 2025-09-09 · Analyzed
10.0EPSS 0.213
CVE-2019-8074
ColdFusion 2018- update 4 and earlier and ColdFusion 2016- update 11 and earlier have a Path Traversal vulnerability. Successful exploitation could lead to Access Control Bypass in the context of the current user.
Published 2019-09-27 · Modified
10.0EPSS 0.189
CVE-2019-7838
ColdFusion versions Update 3 and earlier, Update 10 and earlier, and Update 18 and earlier have a file extension blacklist bypass vulnerability. Successful exploitation could lead to arbitrary code execution.
Published 2019-06-12 · Modified
10.0EPSS 0.174
CVE-2019-7840
ColdFusion versions Update 3 and earlier, Update 10 and earlier, and Update 18 and earlier have a deserialization of untrusted data vulnerability. Successful exploitation could lead to arbitrary code execution.
Published 2019-06-12 · Modified
10.0EPSS 0.172
CVE-2013-3350
Adobe ColdFusion 10 before Update 11 allows remote attackers to call ColdFusion Components (CFC) public methods via WebSockets.
Published 2013-07-10 · Modified
10.0EPSS 0.092
CVE-2019-8073
ColdFusion 2018- update 4 and earlier and ColdFusion 2016- update 11 and earlier have a Command Injection via Vulnerable component vulnerability. Successful exploitation could lead to Arbitrary code execution in the context of the current user.
Published 2019-09-27 · Modified
10.0EPSS 0.083
CVE-2020-3794
ColdFusion versions ColdFusion 2016, and ColdFusion 2018 have a file inclusion vulnerability. Successful exploitation could lead to arbitrary code execution of files located in the webroot or its subdirectory.
Published 2020-03-25 · Modified
10.0EPSS 0.071
CVE-2013-1389
Unspecified vulnerability in Adobe ColdFusion 9.0 before Update 11, 9.0.1 before Update 10, 9.0.2 before Update 5, and 10 before Update 10 allows remote attackers to execute arbitrary code via unknown vectors.
Published 2013-05-16 · Modified
10.0EPSS 0.061
CVE-2010-5290
The authentication process in Adobe ColdFusion before 10 does not require knowledge of the cleartext password if the password hash is known, which makes it easier for context-dependent attackers to obtain administrative privileges by leveraging read access to the configuration file, a different vulnerability than CVE-2010-2861.
Published 2013-09-20 · Modified
10.0EPSS 0.055
CVE-2026-48362
ColdFusion | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') (CWE-78)
Published 2026-08-11 · Analyzed
10.0EPSS 0.035
CVE-2026-48281
ColdFusion | Improper Input Validation (CWE-20)
Published 2026-06-30 · Analyzed
10.0EPSS 0.014
CVE-2026-48277
ColdFusion | Improper Input Validation (CWE-20)
Published 2026-06-30 · Analyzed
10.0EPSS 0.013
CVE-2026-48276
ColdFusion | Unrestricted Upload of File with Dangerous Type (CWE-434)
Published 2026-06-30 · Analyzed
10.0EPSS 0.013
CVE-2026-48283
ColdFusion | Unrestricted Upload of File with Dangerous Type (CWE-434)
Published 2026-06-30 · Analyzed
10.0EPSS 0.013
CVE-2026-48316
ColdFusion | Improper Input Validation (CWE-20)
Published 2026-07-06 · Analyzed
10.0EPSS 0.011
CVE-2026-48273
ColdFusion | Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') (CWE-95)
Published 2026-09-08 · Analyzed
9.9EPSS 0.013
CVE-2026-48322
ColdFusion | Improper Control of Generation of Code ('Code Injection') (CWE-94)
Published 2026-07-14 · Analyzed
9.9EPSS 0.012
CVE-2026-48318
ColdFusion | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)
Published 2026-07-14 · Analyzed
9.9EPSS 0.011
CVE-2023-29300
Adobe ColdFusion Deserialization of Untrusted Data Arbitrary code execution
Published 2023-07-12 · Analyzed
9.8KEVEPSS 1.000
CVE-2010-2861
Multiple directory traversal vulnerabilities in the administrator console in Adobe ColdFusion 9.0.1 and earlier allow remote attackers to read arbitrary files via the locale parameter to (1) CFIDE/administrator/settings/mappings.cfm, (2) logging/settings.cfm, (3) datasources/index.cfm, (4) j2eepackaging/editarchive.cfm, and (5) enter.cfm in CFIDE/administrator/.
Published 2010-08-11 · Analyzed
9.8KEV2 PoCEPSS 0.997
CVE-2023-26360
Adobe ColdFusion Improper Access Control Arbitrary code execution
Published 2023-03-23 · Analyzed
9.8KEVEPSS 0.973
CVE-2023-38203
Analysis CVE-2023-29300 Bypass: Adobe ColdFusion Pre-Auth RCE
Published 2023-07-20 · Analyzed
9.8KEVEPSS 0.971
CVE-2013-0625
Adobe ColdFusion 9.0, 9.0.1, and 9.0.2, when a password is not configured, allows remote attackers to bypass authentication and possibly execute arbitrary code via unspecified vectors, as exploited in the wild in January 2013.
Published 2013-01-09 · Analyzed
9.8KEV1 PoCEPSS 0.938
CVE-2023-44353
ColdFusion WDDX Deserialization Gadgets
Published 2023-11-17 · Modified
9.8EPSS 0.802
CVE-2022-38418
Adobe ColdFusion Application Server Directory Traversal Remote Code Execution Vulnerability
Published 2022-10-14 · Modified
9.8EPSS 0.800
CVE-2022-35711
Adobe ColdFusion ODBC Server Heap-based Buffer Overflow Remote Code Execution Vulnerability
Published 2022-10-14 · Modified
9.8EPSS 0.735
CVE-2022-35690
Adobe ColdFusion ODBC Agent Stack-based Buffer Overflow Remote Code Execution Vulnerability
Published 2022-10-14 · Modified
9.8EPSS 0.722
CVE-2023-38204
Bypass APSB23-41 (CVE-2023-38203) - Pre-Auth RCE ColdFusion 2021 Update 8
Published 2023-09-14 · Modified
9.8EPSS 0.662
1 / 7Next →