VendorsAdobecoldfusion2023
Vulnerabilities

Adobe ColdFusion 2023

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

132CVEs
CVE-2026-48324
ColdFusion | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') (CWE-89)
Published 2026-07-14 · Analyzed
9.1EPSS 0.011
CVE-2026-75746
ColdFusion | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') (CWE-89)
Published 2026-09-08 · Analyzed
9.1EPSS 0.010
CVE-2025-61809
ColdFusion | Improper Input Validation (CWE-20)
Published 2025-12-09 · Analyzed
9.1EPSS 0.007
CVE-2026-48327
ColdFusion | Incorrect Authorization (CWE-863)
Published 2026-07-14 · Analyzed
9.0EPSS 0.004
CVE-2026-71386
ColdFusion | Cross-site Scripting (XSS) (CWE-79)
Published 2026-08-11 · Analyzed
8.8EPSS 0.006
CVE-2026-48307
ColdFusion | Cross-site Scripting (Reflected XSS) (CWE-79)
Published 2026-06-30 · Analyzed
8.8EPSS 0.006
CVE-2026-47932
ColdFusion | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)
Published 2026-06-09 · Analyzed
8.8EPSS 0.005
CVE-2026-71387
ColdFusion | Incorrect Authorization (CWE-863)
Published 2026-08-11 · Analyzed
8.8EPSS 0.005
CVE-2025-49551
ColdFusion | Use of Hard-coded Credentials (CWE-798)
Published 2025-07-08 · Analyzed
8.8EPSS 0.003
CVE-2025-30290
ColdFusion | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)
Published 2025-04-08 · Analyzed
8.7EPSS 0.195
CVE-2026-21273
ColdFusion | Improper Input Validation (CWE-20)
Published 2026-08-11 · Analyzed
8.7EPSS 0.009
CVE-2026-27305
ColdFusion | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)
Published 2026-04-14 · Analyzed
8.6EPSS 0.010
CVE-2026-48285
ColdFusion | Server-Side Request Forgery (SSRF) (CWE-918)
Published 2026-06-30 · Analyzed
8.6EPSS 0.008
CVE-2026-76190
ColdFusion | Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') (CWE-95)
Published 2026-09-08 · Analyzed
8.6EPSS 0.008
CVE-2026-75993
ColdFusion | Cross-site Scripting (Reflected XSS) (CWE-79)
Published 2026-09-08 · Analyzed
8.5EPSS 0.005
CVE-2026-48320
ColdFusion | Cross-site Scripting (Reflected XSS) (CWE-79)
Published 2026-07-14 · Analyzed
8.5EPSS 0.005
CVE-2025-30285
ColdFusion | Deserialization of Untrusted Data (CWE-502)
Published 2025-04-08 · Analyzed
8.4EPSS 0.309
CVE-2025-43565
ColdFusion | Incorrect Authorization (CWE-863)
Published 2025-05-13 · Analyzed
8.4EPSS 0.157
CVE-2025-61810
ColdFusion | Deserialization of Untrusted Data (CWE-502)
Published 2025-12-09 · Analyzed
8.4EPSS 0.095
CVE-2025-61812
ColdFusion | Improper Input Validation (CWE-20)
Published 2025-12-09 · Analyzed
8.4EPSS 0.047
CVE-2025-30286
ColdFusion | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') (CWE-78)
Published 2025-04-08 · Analyzed
8.4EPSS 0.026
CVE-2025-30284
ColdFusion | Deserialization of Untrusted Data (CWE-502)
Published 2025-04-08 · Analyzed
8.4EPSS 0.021
CVE-2026-27306
ColdFusion | Improper Input Validation (CWE-20)
Published 2026-04-14 · Analyzed
8.4EPSS 0.005
CVE-2026-75999
ColdFusion | Improper Input Validation (CWE-20)
Published 2026-09-08 · Analyzed
8.4EPSS 0.005
CVE-2026-47931
ColdFusion | Improper Input Validation (CWE-20)
Published 2026-06-09 · Analyzed
8.4EPSS 0.005
CVE-2026-47929
ColdFusion | Incorrect Authorization (CWE-863)
Published 2026-06-09 · Analyzed
8.4EPSS 0.005
CVE-2026-34635
ColdFusion | Use of Hard-coded Cryptographic Key (CWE-321)
Published 2026-08-11 · Analyzed
8.4EPSS 0.002
CVE-2025-30289
ColdFusion | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') (CWE-78)
Published 2025-04-08 · Analyzed
8.2EPSS 0.053
CVE-2025-30287
ColdFusion | Improper Authentication (CWE-287)
Published 2025-04-08 · Analyzed
8.2EPSS 0.029
CVE-2026-21279
ColdFusion | Improper Input Validation (CWE-20)
Published 2026-08-11 · Analyzed
8.2EPSS 0.008
CVE-2025-30288
ColdFusion | Improper Access Control (CWE-284)
Published 2025-04-08 · Analyzed
8.2EPSS 0.003
CVE-2026-48364
ColdFusion | Uncontrolled Search Path Element (CWE-427)
Published 2026-07-13 · Analyzed
8.2EPSS 0.003
CVE-2026-48363
ColdFusion | Uncontrolled Search Path Element (CWE-427)
Published 2026-07-13 · Analyzed
8.2EPSS 0.003
CVE-2024-53961
ColdFusion | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)
Published 2024-12-23 · Analyzed
8.1EPSS 0.142
CVE-2026-48440
ColdFusion | Heap-based Buffer Overflow (CWE-122)
Published 2026-08-11 · Analyzed
8.1EPSS 0.013
CVE-2026-47930
ColdFusion | Improper Input Validation (CWE-20)
Published 2026-06-09 · Analyzed
8.1EPSS 0.009
CVE-2025-49537
ColdFusion | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') (CWE-78)
Published 2025-07-08 · Analyzed
7.9EPSS 0.026
CVE-2026-25652
ColdFusion | Incorrect Authorization (CWE-863)
Published 2026-08-11 · Analyzed
7.8EPSS 0.002
CVE-2026-48385
ColdFusion | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') (CWE-78)
Published 2026-08-11 · Analyzed
7.7EPSS 0.016
CVE-2026-34619
ColdFusion | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)
Published 2026-04-14 · Analyzed
7.7EPSS 0.011
← Prev2 / 4Next →