VendorsAdobecoldfusionall versions
Vulnerabilities

Adobe ColdFusion

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

266CVEs
CVE-2023-44350
ColdFusion | Deserialization of Untrusted Data (CWE-502)
Published 2023-11-17 · Modified
9.8EPSS 0.646
CVE-2023-44351
Adobe ColdFusion RCE Security Vulnerability
Published 2023-11-17 · Modified
9.8EPSS 0.502
CVE-2017-11283
Adobe ColdFusion has an Untrusted Data Deserialization vulnerability. This affects Update 4 and earlier versions for ColdFusion 2016, and Update 12 and earlier versions for ColdFusion 11.
Published 2017-12-01 · Modified
9.8EPSS 0.427
CVE-2017-11284
Adobe ColdFusion has an Untrusted Data Deserialization vulnerability. This affects Update 4 and earlier versions for ColdFusion 2016, and Update 12 and earlier versions for ColdFusion 11.
Published 2017-12-01 · Modified
9.8EPSS 0.427
CVE-2022-35710
Adobe ColdFusion ODBC Server Stack-based Buffer Overflow Remote Code Execution Vulnerability
Published 2022-10-14 · Modified
9.8EPSS 0.426
CVE-2022-35712
Adobe ColdFusion ODBC Agent Heap-based Buffer Overflow Remote Code Execution Vulnerability
Published 2022-10-14 · Modified
9.8EPSS 0.368
CVE-2024-41874
ColdFusion | Deserialization of Untrusted Data (CWE-502)
Published 2024-09-13 · Analyzed
9.8EPSS 0.303
CVE-2023-26359
Adobe ColdFusion Deserialization of Untrusted Data Arbitrary code execution
Published 2023-03-23 · Analyzed
9.8KEVEPSS 0.170
CVE-2016-1114
Adobe ColdFusion 10 before Update 19, 11 before Update 8, and 2016 before Update 1 allows remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the Apache Commons Collections library.
Published 2016-05-11 · Modified
9.8EPSS 0.088
CVE-2019-8256
ColdFusion versions Update 6 and earlier have an insecure inherited permissions of default installation directory vulnerability. Successful exploitation could lead to privilege escalation.
Published 2019-12-19 · Modified
9.8EPSS 0.040
CVE-2026-48284
ColdFusion | Improper Input Validation (CWE-20)
Published 2026-07-14 · Analyzed
9.6EPSS 0.005
CVE-2026-47928
ColdFusion | Improper Input Validation (CWE-20)
Published 2026-06-09 · Analyzed
9.6EPSS 0.005
CVE-2026-71384
ColdFusion | Incorrect Authorization (CWE-863)
Published 2026-08-11 · Analyzed
9.6EPSS 0.005
CVE-2026-48313
ColdFusion | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)
Published 2026-06-30 · Analyzed
9.3EPSS 0.030
CVE-2026-48315
ColdFusion | Improper Input Validation (CWE-20)
Published 2026-06-30 · Analyzed
9.3EPSS 0.010
CVE-2026-48325
ColdFusion | Missing Authentication for Critical Function (CWE-306)
Published 2026-07-14 · Analyzed
9.3EPSS 0.006
CVE-2025-49535
ColdFusion | Improper Restriction of XML External Entity Reference ('XXE') (CWE-611)
Published 2025-07-08 · Analyzed
9.3EPSS 0.006
CVE-2026-27304
ColdFusion | Improper Input Validation (CWE-20)
Published 2026-04-14 · Analyzed
9.3EPSS 0.005
CVE-2026-48321
ColdFusion | Incorrect Authorization (CWE-863)
Published 2026-07-14 · Analyzed
9.3EPSS 0.004
CVE-2025-43562
ColdFusion | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') (CWE-78)
Published 2025-05-13 · Analyzed
9.1EPSS 0.451
CVE-2025-30281
ColdFusion | Improper Access Control (CWE-284)
Published 2025-04-08 · Analyzed
9.1EPSS 0.236
CVE-2025-43561
ColdFusion | Incorrect Authorization (CWE-863)
Published 2025-05-13 · Analyzed
9.1EPSS 0.206
CVE-2025-43560
ColdFusion | Improper Input Validation (CWE-20)
Published 2025-05-13 · Analyzed
9.1EPSS 0.194
CVE-2025-43564
ColdFusion | Incorrect Authorization (CWE-863)
Published 2025-05-13 · Analyzed
9.1EPSS 0.154
CVE-2025-43563
ColdFusion | Improper Access Control (CWE-284)
Published 2025-05-13 · Analyzed
9.1EPSS 0.153
CVE-2025-61808
ColdFusion | Unrestricted Upload of File with Dangerous Type (CWE-434)
Published 2025-12-09 · Analyzed
9.1EPSS 0.106
CVE-2025-24447
ColdFusion | Deserialization of Untrusted Data (CWE-502)
Published 2025-04-08 · Analyzed
9.1EPSS 0.021
CVE-2025-30282
ColdFusion | Improper Authentication (CWE-287)
Published 2025-04-08 · Analyzed
9.1EPSS 0.018
CVE-2025-24446
ColdFusion | Improper Input Validation (CWE-20)
Published 2025-04-08 · Analyzed
9.1EPSS 0.018
CVE-2025-43559
ColdFusion | Improper Input Validation (CWE-20)
Published 2025-05-13 · Analyzed
9.1EPSS 0.015
CVE-2026-48319
ColdFusion | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)
Published 2026-07-14 · Analyzed
9.1EPSS 0.014
CVE-2025-61811
ColdFusion | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)
Published 2025-12-09 · Modified
9.1EPSS 0.012
CVE-2026-48324
ColdFusion | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') (CWE-89)
Published 2026-07-14 · Analyzed
9.1EPSS 0.011
CVE-2026-75746
ColdFusion | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') (CWE-89)
Published 2026-09-08 · Analyzed
9.1EPSS 0.010
CVE-2025-61809
ColdFusion | Improper Input Validation (CWE-20)
Published 2025-12-09 · Analyzed
9.1EPSS 0.007
CVE-2026-48327
ColdFusion | Incorrect Authorization (CWE-863)
Published 2026-07-14 · Analyzed
9.0EPSS 0.004
CVE-2026-71386
ColdFusion | Cross-site Scripting (XSS) (CWE-79)
Published 2026-08-11 · Analyzed
8.8EPSS 0.006
CVE-2026-48307
ColdFusion | Cross-site Scripting (Reflected XSS) (CWE-79)
Published 2026-06-30 · Analyzed
8.8EPSS 0.006
CVE-2026-47932
ColdFusion | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)
Published 2026-06-09 · Analyzed
8.8EPSS 0.005
CVE-2026-71387
ColdFusion | Incorrect Authorization (CWE-863)
Published 2026-08-11 · Analyzed
8.8EPSS 0.005
← Prev2 / 7Next →