VendorsAdobecoldfusion2021
Vulnerabilities

Adobe ColdFusion 2021

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

88CVEs
CVE-2024-53961
ColdFusion | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)
Published 2024-12-23 · Analyzed
8.1EPSS 0.142
CVE-2025-49537
ColdFusion | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') (CWE-78)
Published 2025-07-08 · Analyzed
7.9EPSS 0.026
CVE-2020-10145
The Adobe ColdFusion installer fails to set a secure access-control list (ACL) on the default installation directory, such as C:\ColdFusion2021\. By default, unprivileged users can create files in this directory structure, which creates a privilege-escalation vulnerability.
Published 2021-05-27 · Modified
7.8EPSS 0.005
CVE-2023-29298
Adobe ColdFusion Improper Access Control Security feature bypass
Published 2023-07-12 · Analyzed
7.5KEVEPSS 0.998
CVE-2023-38205
ColdFusion Bypass - Vulnerability disclosure in ColdFusion | BYPASS CVE-2023-29298
Published 2023-09-14 · Analyzed
7.5KEVEPSS 0.997
CVE-2022-38419
Adobe ColdFusion Solr Service XML External Entity Processing Arbitrary file system read
Published 2022-10-14 · Modified
7.5EPSS 0.530
CVE-2022-38422
Adobe ColdFusion Application Server Directory Traversal Information Disclosure Vulnerability
Published 2022-10-14 · Modified
7.5EPSS 0.443
CVE-2022-38420
Adobe ColdFusion Use of Hard-coded Credentials Application denial-of-service
Published 2022-10-14 · Modified
7.5EPSS 0.440
CVE-2022-42341
Adobe ColdFusion Improper Restriction of XML External Entity Reference Arbitrary file system read
Published 2022-10-14 · Modified
7.5EPSS 0.355
CVE-2023-29301
Adobe ColdFusion Improper Restriction of Excessive Authentication Attempts Security feature bypass
Published 2023-07-12 · Modified
7.5EPSS 0.347
CVE-2022-42340
Adobe ColdFusion Improper Input Validation Arbitrary file system read
Published 2022-10-14 · Modified
7.5EPSS 0.338
CVE-2024-34112
ColdFusion CFDOCUMENT file retrieval / access control bypass
Published 2024-06-13 · Analyzed
7.5EPSS 0.237
CVE-2023-26347
CVE-2023-38205 issues | ColdFusion Admin Panel Access
Published 2023-11-17 · Modified
7.5EPSS 0.101
CVE-2024-45113
ColdFusion | Improper Authentication (CWE-287)
Published 2024-09-13 · Analyzed
7.5EPSS 0.006
CVE-2024-20767
ColdFusion | Improper Access Control (CWE-284)
Published 2024-03-18 · Analyzed
7.4KEV1 PoCEPSS 0.985
CVE-2025-49538
ColdFusion | XML Injection (aka Blind XPath Injection) (CWE-91)
Published 2025-07-08 · Analyzed
7.4EPSS 0.020
CVE-2021-40698
ColdFusion Use of Inherently Dangerous Function Leads To Security feature bypass  
Published 2023-09-07 · Modified
7.4EPSS 0.006
CVE-2025-61813
ColdFusion | Improper Restriction of XML External Entity Reference ('XXE') (CWE-611)
Published 2025-12-09 · Analyzed
7.4EPSS 0.005
CVE-2021-40699
ColdFusion CFIDE Improper Access Control Leads To Privilege Escalation
Published 2023-09-07 · Modified
7.4EPSS 0.005
CVE-2025-49536
ColdFusion | Incorrect Authorization (CWE-863)
Published 2025-07-08 · Analyzed
7.3EPSS 0.003
CVE-2022-38421
Adobe ColdFusion Application Server Directory Traversal Remote Code Execution Vulnerability
Published 2022-10-14 · Modified
7.2EPSS 0.792
CVE-2022-38424
Adobe ColdFusion Application Server Directory Traversal Arbitrary file system write
Published 2022-10-14 · Modified
7.2EPSS 0.452
CVE-2025-43566
ColdFusion | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)
Published 2025-05-13 · Analyzed
6.8EPSS 0.551
CVE-2025-30294
ColdFusion | Improper Input Validation (CWE-20)
Published 2025-04-08 · Analyzed
6.8EPSS 0.172
CVE-2025-30293
ColdFusion | Improper Input Validation (CWE-20)
Published 2025-04-08 · Analyzed
6.8EPSS 0.008
CVE-2025-49544
ColdFusion | Improper Restriction of XML External Entity Reference ('XXE') (CWE-611)
Published 2025-07-08 · Analyzed
6.8EPSS 0.006
CVE-2025-61821
ColdFusion | Improper Restriction of XML External Entity Reference ('XXE') (CWE-611)
Published 2025-12-09 · Analyzed
6.8EPSS 0.005
CVE-2025-61822
ColdFusion | Improper Input Validation (CWE-20)
Published 2025-12-09 · Analyzed
6.2EPSS 0.007
CVE-2025-61823
ColdFusion | Improper Restriction of XML External Entity Reference ('XXE') (CWE-611)
Published 2025-12-09 · Analyzed
6.2EPSS 0.005
CVE-2025-49545
ColdFusion | Server-Side Request Forgery (SSRF) (CWE-918)
Published 2025-07-08 · Analyzed
6.2EPSS 0.004
CVE-2023-44352
Unauthenticate Reflected XSS on Adobe Coldfusion 2018 - 2021 - 2023 last version
Published 2023-11-17 · Modified
6.1EPSS 0.848
CVE-2022-28818
ColdFusion Reflected Cross-Site Scripting could lead to Arbitrary Code Execution
Published 2022-05-12 · Modified
6.1EPSS 0.448
CVE-2025-30292
ColdFusion | Cross-site Scripting (Reflected XSS) (CWE-79)
Published 2025-04-08 · Analyzed
6.1EPSS 0.155
CVE-2025-64897
ColdFusion | Improper Access Control (CWE-284)
Published 2025-12-09 · Analyzed
5.6EPSS 0.001
CVE-2024-34113
ColdFusion | Weak Cryptography for Passwords (CWE-261)
Published 2024-06-13 · Modified
5.5EPSS 0.003
CVE-2025-30291
ColdFusion | Information Exposure (CWE-200)
Published 2025-04-08 · Analyzed
5.5EPSS 0.002
CVE-2023-38206
ColdFusion | Improper Access Control (CWE-284)
Published 2023-09-14 · Modified
5.3EPSS 0.007
CVE-2025-64898
ColdFusion | Insufficiently Protected Credentials (CWE-522)
Published 2025-12-09 · Analyzed
5.3EPSS 0.004
CVE-2025-49542
ColdFusion | Cross-site Scripting (Reflected XSS) (CWE-79)
Published 2025-07-08 · Analyzed
5.2EPSS 0.011
CVE-2023-26361
Adobe ColdFusion Directory Traversal Arbitrary file system read Vulnerability
Published 2023-03-23 · Modified
4.9EPSS 0.587
← Prev2 / 3Next →