VendorsAdobecoldfusionall versions
Vulnerabilities

Adobe ColdFusion

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

266CVEs
CVE-2025-49551
ColdFusion | Use of Hard-coded Credentials (CWE-798)
Published 2025-07-08 · Analyzed
8.8EPSS 0.003
CVE-2025-30290
ColdFusion | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)
Published 2025-04-08 · Analyzed
8.7EPSS 0.195
CVE-2026-21273
ColdFusion | Improper Input Validation (CWE-20)
Published 2026-08-11 · Analyzed
8.7EPSS 0.009
CVE-2016-4264
The Office Open XML (OOXML) feature in Adobe ColdFusion 10 before Update 21 and 11 before Update 10 allows remote attackers to read arbitrary files or send TCP requests to intranet servers via a crafted OOXML spreadsheet containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.
Published 2016-09-01 · Modified
8.61 PoCEPSS 0.690
CVE-2026-27305
ColdFusion | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)
Published 2026-04-14 · Analyzed
8.6EPSS 0.010
CVE-2026-48285
ColdFusion | Server-Side Request Forgery (SSRF) (CWE-918)
Published 2026-06-30 · Analyzed
8.6EPSS 0.008
CVE-2026-76190
ColdFusion | Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') (CWE-95)
Published 2026-09-08 · Analyzed
8.6EPSS 0.008
CVE-2026-48320
ColdFusion | Cross-site Scripting (Reflected XSS) (CWE-79)
Published 2026-07-14 · Analyzed
8.5EPSS 0.005
CVE-2026-75993
ColdFusion | Cross-site Scripting (Reflected XSS) (CWE-79)
Published 2026-09-08 · Analyzed
8.5EPSS 0.005
CVE-2025-30285
ColdFusion | Deserialization of Untrusted Data (CWE-502)
Published 2025-04-08 · Analyzed
8.4EPSS 0.309
CVE-2025-43565
ColdFusion | Incorrect Authorization (CWE-863)
Published 2025-05-13 · Analyzed
8.4EPSS 0.157
CVE-2025-61810
ColdFusion | Deserialization of Untrusted Data (CWE-502)
Published 2025-12-09 · Analyzed
8.4EPSS 0.095
CVE-2025-61812
ColdFusion | Improper Input Validation (CWE-20)
Published 2025-12-09 · Analyzed
8.4EPSS 0.047
CVE-2025-30286
ColdFusion | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') (CWE-78)
Published 2025-04-08 · Analyzed
8.4EPSS 0.026
CVE-2025-30284
ColdFusion | Deserialization of Untrusted Data (CWE-502)
Published 2025-04-08 · Analyzed
8.4EPSS 0.021
CVE-2026-27306
ColdFusion | Improper Input Validation (CWE-20)
Published 2026-04-14 · Analyzed
8.4EPSS 0.005
CVE-2026-47931
ColdFusion | Improper Input Validation (CWE-20)
Published 2026-06-09 · Analyzed
8.4EPSS 0.005
CVE-2026-75999
ColdFusion | Improper Input Validation (CWE-20)
Published 2026-09-08 · Analyzed
8.4EPSS 0.005
CVE-2026-47929
ColdFusion | Incorrect Authorization (CWE-863)
Published 2026-06-09 · Analyzed
8.4EPSS 0.005
CVE-2026-34635
ColdFusion | Use of Hard-coded Cryptographic Key (CWE-321)
Published 2026-08-11 · Analyzed
8.4EPSS 0.002
CVE-2025-30289
ColdFusion | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') (CWE-78)
Published 2025-04-08 · Analyzed
8.2EPSS 0.053
CVE-2025-30287
ColdFusion | Improper Authentication (CWE-287)
Published 2025-04-08 · Analyzed
8.2EPSS 0.029
CVE-2026-21279
ColdFusion | Improper Input Validation (CWE-20)
Published 2026-08-11 · Analyzed
8.2EPSS 0.008
CVE-2025-30288
ColdFusion | Improper Access Control (CWE-284)
Published 2025-04-08 · Analyzed
8.2EPSS 0.003
CVE-2026-48363
ColdFusion | Uncontrolled Search Path Element (CWE-427)
Published 2026-07-13 · Analyzed
8.2EPSS 0.003
CVE-2026-48364
ColdFusion | Uncontrolled Search Path Element (CWE-427)
Published 2026-07-13 · Analyzed
8.2EPSS 0.003
CVE-2024-53961
ColdFusion | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)
Published 2024-12-23 · Analyzed
8.1EPSS 0.142
CVE-2026-48440
ColdFusion | Heap-based Buffer Overflow (CWE-122)
Published 2026-08-11 · Analyzed
8.1EPSS 0.013
CVE-2026-47930
ColdFusion | Improper Input Validation (CWE-20)
Published 2026-06-09 · Analyzed
8.1EPSS 0.009
CVE-2025-49537
ColdFusion | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') (CWE-78)
Published 2025-07-08 · Analyzed
7.9EPSS 0.026
CVE-2013-5328
Adobe ColdFusion 10 before Update 12 allows remote attackers to read arbitrary files via unspecified vectors.
Published 2013-11-13 · Modified
7.8EPSS 0.031
CVE-2020-9672
Adobe ColdFusion 2016 update 15 and earlier versions, and ColdFusion 2018 update 9 and earlier versions have a dll search-order hijacking vulnerability. Successful exploitation could lead to privilege escalation.
Published 2020-07-17 · Modified
7.8EPSS 0.010
CVE-2020-9673
Adobe ColdFusion 2016 update 15 and earlier versions, and ColdFusion 2018 update 9 and earlier versions have a dll search-order hijacking vulnerability. Successful exploitation could lead to privilege escalation.
Published 2020-07-17 · Modified
7.8EPSS 0.010
CVE-2020-3768
ColdFusion versions ColdFusion 2016, and ColdFusion 2018 have a dll search-order hijacking vulnerability. Successful exploitation could lead to privilege escalation.
Published 2020-06-26 · Modified
7.8EPSS 0.009
CVE-2018-4938
Adobe ColdFusion Update 5 and earlier versions, ColdFusion 11 Update 13 and earlier versions have an exploitable Insecure Library Loading vulnerability. Successful exploitation could lead to local privilege escalation.
Published 2018-05-19 · Modified
7.8EPSS 0.007
CVE-2020-10145
The Adobe ColdFusion installer fails to set a secure access-control list (ACL) on the default installation directory, such as C:\ColdFusion2021\. By default, unprivileged users can create files in this directory structure, which creates a privilege-escalation vulnerability.
Published 2021-05-27 · Modified
7.8EPSS 0.005
CVE-2026-25652
ColdFusion | Incorrect Authorization (CWE-863)
Published 2026-08-11 · Analyzed
7.8EPSS 0.002
CVE-2026-48385
ColdFusion | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') (CWE-78)
Published 2026-08-11 · Analyzed
7.7EPSS 0.016
CVE-2026-34619
ColdFusion | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)
Published 2026-04-14 · Analyzed
7.7EPSS 0.011
CVE-2026-48328
ColdFusion | Improper Input Validation (CWE-20)
Published 2026-07-14 · Analyzed
7.7EPSS 0.008
← Prev3 / 7Next →