VendorsAdobecoldfusion2023
Vulnerabilities

Adobe ColdFusion 2023

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

132CVEs
CVE-2026-48328
ColdFusion | Improper Input Validation (CWE-20)
Published 2026-07-14 · Analyzed
7.7EPSS 0.008
CVE-2026-48332
ColdFusion | Server-Side Request Forgery (SSRF) (CWE-918)
Published 2026-07-14 · Analyzed
7.7EPSS 0.008
CVE-2023-29298
Adobe ColdFusion Improper Access Control Security feature bypass
Published 2023-07-12 · Analyzed
7.5KEVEPSS 0.998
CVE-2023-38205
ColdFusion Bypass - Vulnerability disclosure in ColdFusion | BYPASS CVE-2023-29298
Published 2023-09-14 · Analyzed
7.5KEVEPSS 0.997
CVE-2024-34112
ColdFusion CFDOCUMENT file retrieval / access control bypass
Published 2024-06-13 · Analyzed
7.5EPSS 0.237
CVE-2023-26347
CVE-2023-38205 issues | ColdFusion Admin Panel Access
Published 2023-11-17 · Modified
7.5EPSS 0.101
CVE-2026-48386
ColdFusion | Use of a Broken or Risky Cryptographic Algorithm (CWE-327)
Published 2026-08-11 · Analyzed
7.5EPSS 0.010
CVE-2026-75998
ColdFusion | Improper Access Control (CWE-284)
Published 2026-09-08 · Analyzed
7.5EPSS 0.008
CVE-2026-27282
ColdFusion | Improper Input Validation (CWE-20)
Published 2026-04-14 · Analyzed
7.5EPSS 0.008
CVE-2024-45113
ColdFusion | Improper Authentication (CWE-287)
Published 2024-09-13 · Analyzed
7.5EPSS 0.006
CVE-2024-20767
ColdFusion | Improper Access Control (CWE-284)
Published 2024-03-18 · Analyzed
7.4KEV1 PoCEPSS 0.985
CVE-2025-49538
ColdFusion | XML Injection (aka Blind XPath Injection) (CWE-91)
Published 2025-07-08 · Analyzed
7.4EPSS 0.020
CVE-2026-47960
ColdFusion | Improper Restriction of XML External Entity Reference ('XXE') (CWE-611)
Published 2026-06-09 · Analyzed
7.4EPSS 0.008
CVE-2025-61813
ColdFusion | Improper Restriction of XML External Entity Reference ('XXE') (CWE-611)
Published 2025-12-09 · Analyzed
7.4EPSS 0.005
CVE-2026-71383
ColdFusion | Incorrect Authorization (CWE-863)
Published 2026-08-11 · Analyzed
7.3EPSS 0.006
CVE-2025-49536
ColdFusion | Incorrect Authorization (CWE-863)
Published 2025-07-08 · Analyzed
7.3EPSS 0.003
CVE-2026-83961
ColdFusion | Improper Authentication (CWE-287)
Published 2026-09-03 · Analyzed
7.1EPSS 0.004
CVE-2025-43566
ColdFusion | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)
Published 2025-05-13 · Analyzed
6.8EPSS 0.551
CVE-2025-30294
ColdFusion | Improper Input Validation (CWE-20)
Published 2025-04-08 · Analyzed
6.8EPSS 0.172
CVE-2025-30293
ColdFusion | Improper Input Validation (CWE-20)
Published 2025-04-08 · Analyzed
6.8EPSS 0.008
CVE-2025-49544
ColdFusion | Improper Restriction of XML External Entity Reference ('XXE') (CWE-611)
Published 2025-07-08 · Analyzed
6.8EPSS 0.006
CVE-2025-61821
ColdFusion | Improper Restriction of XML External Entity Reference ('XXE') (CWE-611)
Published 2025-12-09 · Analyzed
6.8EPSS 0.005
CVE-2026-48338
ColdFusion | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)
Published 2026-07-14 · Analyzed
6.8EPSS 0.005
CVE-2026-48375
ColdFusion | Incorrect Authorization (CWE-863)
Published 2026-08-11 · Analyzed
6.5EPSS 0.008
CVE-2026-48314
ColdFusion | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)
Published 2026-06-30 · Analyzed
6.5EPSS 0.006
CVE-2026-76000
ColdFusion | Uncontrolled Resource Consumption (CWE-400)
Published 2026-09-08 · Analyzed
6.5EPSS 0.004
CVE-2025-61822
ColdFusion | Improper Input Validation (CWE-20)
Published 2025-12-09 · Analyzed
6.2EPSS 0.007
CVE-2025-61823
ColdFusion | Improper Restriction of XML External Entity Reference ('XXE') (CWE-611)
Published 2025-12-09 · Analyzed
6.2EPSS 0.005
CVE-2025-49545
ColdFusion | Server-Side Request Forgery (SSRF) (CWE-918)
Published 2025-07-08 · Analyzed
6.2EPSS 0.004
CVE-2023-44352
Unauthenticate Reflected XSS on Adobe Coldfusion 2018 - 2021 - 2023 last version
Published 2023-11-17 · Modified
6.1EPSS 0.848
CVE-2025-30292
ColdFusion | Cross-site Scripting (Reflected XSS) (CWE-79)
Published 2025-04-08 · Analyzed
6.1EPSS 0.155
CVE-2026-76002
ColdFusion | Cross-site Scripting (Reflected XSS) (CWE-79)
Published 2026-09-08 · Analyzed
6.1EPSS 0.004
CVE-2025-64897
ColdFusion | Improper Access Control (CWE-284)
Published 2025-12-09 · Analyzed
5.6EPSS 0.001
CVE-2024-34113
ColdFusion | Weak Cryptography for Passwords (CWE-261)
Published 2024-06-13 · Modified
5.5EPSS 0.003
CVE-2025-30291
ColdFusion | Information Exposure (CWE-200)
Published 2025-04-08 · Analyzed
5.5EPSS 0.002
CVE-2026-48376
ColdFusion | Improper Encoding or Escaping of Output (CWE-116)
Published 2026-08-11 · Analyzed
5.4EPSS 0.007
CVE-2026-21269
ColdFusion | Cross-site Scripting (Stored XSS) (CWE-79)
Published 2026-08-11 · Modified
5.4EPSS 0.005
CVE-2023-38206
ColdFusion | Improper Access Control (CWE-284)
Published 2023-09-14 · Modified
5.3EPSS 0.007
CVE-2025-64898
ColdFusion | Insufficiently Protected Credentials (CWE-522)
Published 2025-12-09 · Analyzed
5.3EPSS 0.004
CVE-2025-49542
ColdFusion | Cross-site Scripting (Reflected XSS) (CWE-79)
Published 2025-07-08 · Analyzed
5.2EPSS 0.011
← Prev3 / 4Next →