VendorsAdobecoldfusionall versions
Vulnerabilities

Adobe ColdFusion

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

266CVEs
CVE-2026-48332
ColdFusion | Server-Side Request Forgery (SSRF) (CWE-918)
Published 2026-07-14 · Analyzed
7.7EPSS 0.008
CVE-2023-29298
Adobe ColdFusion Improper Access Control Security feature bypass
Published 2023-07-12 · Analyzed
7.5KEVEPSS 0.998
CVE-2023-38205
ColdFusion Bypass - Vulnerability disclosure in ColdFusion | BYPASS CVE-2023-29298
Published 2023-09-14 · Analyzed
7.5KEVEPSS 0.997
CVE-2013-0631
Adobe ColdFusion 9.0, 9.0.1, and 9.0.2 allows attackers to obtain sensitive information via unspecified vectors, as exploited in the wild in January 2013.
Published 2013-01-09 · Analyzed
7.5KEVEPSS 0.664
CVE-2013-0629
Adobe ColdFusion 9.0, 9.0.1, 9.0.2, and 10, when a password is not configured, allows attackers to access restricted directories via unspecified vectors, as exploited in the wild in January 2013.
Published 2013-01-09 · Analyzed
7.5KEV1 PoCEPSS 0.658
CVE-2022-38419
Adobe ColdFusion Solr Service XML External Entity Processing Arbitrary file system read
Published 2022-10-14 · Modified
7.5EPSS 0.530
CVE-2022-38422
Adobe ColdFusion Application Server Directory Traversal Information Disclosure Vulnerability
Published 2022-10-14 · Modified
7.5EPSS 0.443
CVE-2022-38420
Adobe ColdFusion Use of Hard-coded Credentials Application denial-of-service
Published 2022-10-14 · Modified
7.5EPSS 0.440
CVE-2022-42341
Adobe ColdFusion Improper Restriction of XML External Entity Reference Arbitrary file system read
Published 2022-10-14 · Modified
7.5EPSS 0.355
CVE-2023-29301
Adobe ColdFusion Improper Restriction of Excessive Authentication Attempts Security feature bypass
Published 2023-07-12 · Modified
7.5EPSS 0.347
CVE-2022-42340
Adobe ColdFusion Improper Input Validation Arbitrary file system read
Published 2022-10-14 · Modified
7.5EPSS 0.338
CVE-2024-34112
ColdFusion CFDOCUMENT file retrieval / access control bypass
Published 2024-06-13 · Analyzed
7.5EPSS 0.237
CVE-2008-1203
The administrator interface for Adobe ColdFusion 8 and ColdFusion MX7 does not log failed authentication attempts, which makes it easier for remote attackers to conduct brute force attacks without detection.
Published 2008-03-12 · Modified
7.5EPSS 0.155
CVE-2023-26347
CVE-2023-38205 issues | ColdFusion Admin Panel Access
Published 2023-11-17 · Modified
7.5EPSS 0.101
CVE-2017-11286
Adobe ColdFusion has an XML external entity (XXE) injection vulnerability. This affects Update 4 and earlier versions for ColdFusion 2016, and Update 12 and earlier versions for ColdFusion 11.
Published 2017-12-01 · Modified
7.5EPSS 0.096
CVE-2018-15964
Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have a use of a component with a known vulnerability vulnerability. Successful exploitation could lead to information disclosure.
Published 2018-09-25 · Modified
7.5EPSS 0.079
CVE-2019-8072
ColdFusion 2018- update 4 and earlier and ColdFusion 2016- update 11 and earlier have a Security bypass vulnerability. Successful exploitation could lead to Information Disclosure in the context of the current user.
Published 2019-09-27 · Modified
7.5EPSS 0.074
CVE-2018-15960
Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have a use of a component with a known vulnerability vulnerability. Successful exploitation could lead to arbitrary file overwrite.
Published 2018-09-25 · Modified
7.5EPSS 0.055
CVE-2013-1387
Unspecified vulnerability in Adobe ColdFusion 9.0 before Update 10, 9.0.1 before Update 9, 9.0.2 before Update 4, and 10 before Update 9 allows attackers to impersonate users via unknown vectors.
Published 2013-04-10 · Modified
7.5EPSS 0.046
CVE-2013-1388
Unspecified vulnerability in Adobe ColdFusion 9.0 before Update 10, 9.0.1 before Update 9, 9.0.2 before Update 4, and 10 before Update 9 allows attackers to obtain administrator-console access via unknown vectors.
Published 2013-04-10 · Modified
7.5EPSS 0.045
CVE-2020-3761
ColdFusion versions ColdFusion 2016, and ColdFusion 2018 have a remote file read vulnerability. Successful exploitation could lead to arbitrary file read from the coldfusion install directory.
Published 2020-03-25 · Modified
7.5EPSS 0.042
CVE-2018-4942
Adobe ColdFusion Update 5 and earlier versions, ColdFusion 11 Update 13 and earlier versions have an exploitable Unsafe XML External Entity Processing vulnerability. Successful exploitation could lead to information disclosure.
Published 2018-05-19 · Modified
7.5EPSS 0.039
CVE-2008-1656
Adobe ColdFusion 8 and 8.0.1 does not properly implement the public access level for CFC methods, which allows remote attackers to invoke these methods via Flex 2 remoting, a different vulnerability than CVE-2006-4725.
Published 2008-04-09 · Modified
7.5EPSS 0.026
CVE-2026-48386
ColdFusion | Use of a Broken or Risky Cryptographic Algorithm (CWE-327)
Published 2026-08-11 · Analyzed
7.5EPSS 0.010
CVE-2026-75998
ColdFusion | Improper Access Control (CWE-284)
Published 2026-09-08 · Analyzed
7.5EPSS 0.008
CVE-2026-27282
ColdFusion | Improper Input Validation (CWE-20)
Published 2026-04-14 · Analyzed
7.5EPSS 0.008
CVE-2024-45113
ColdFusion | Improper Authentication (CWE-287)
Published 2024-09-13 · Analyzed
7.5EPSS 0.006
CVE-2024-20767
ColdFusion | Improper Access Control (CWE-284)
Published 2024-03-18 · Analyzed
7.4KEV1 PoCEPSS 0.985
CVE-2025-49538
ColdFusion | XML Injection (aka Blind XPath Injection) (CWE-91)
Published 2025-07-08 · Analyzed
7.4EPSS 0.020
CVE-2026-47960
ColdFusion | Improper Restriction of XML External Entity Reference ('XXE') (CWE-611)
Published 2026-06-09 · Analyzed
7.4EPSS 0.008
CVE-2021-40698
ColdFusion Use of Inherently Dangerous Function Leads To Security feature bypass  
Published 2023-09-07 · Modified
7.4EPSS 0.006
CVE-2025-61813
ColdFusion | Improper Restriction of XML External Entity Reference ('XXE') (CWE-611)
Published 2025-12-09 · Analyzed
7.4EPSS 0.005
CVE-2021-40699
ColdFusion CFIDE Improper Access Control Leads To Privilege Escalation
Published 2023-09-07 · Modified
7.4EPSS 0.005
CVE-2026-71383
ColdFusion | Incorrect Authorization (CWE-863)
Published 2026-08-11 · Analyzed
7.3EPSS 0.006
CVE-2025-49536
ColdFusion | Incorrect Authorization (CWE-863)
Published 2025-07-08 · Analyzed
7.3EPSS 0.003
CVE-2022-38421
Adobe ColdFusion Application Server Directory Traversal Remote Code Execution Vulnerability
Published 2022-10-14 · Modified
7.2EPSS 0.792
CVE-2022-38424
Adobe ColdFusion Application Server Directory Traversal Arbitrary file system write
Published 2022-10-14 · Modified
7.2EPSS 0.452
CVE-2008-4831
Unspecified vulnerability in Adobe ColdFusion 8 and 8.0.1 and ColdFusion MX 7.0.2 allows local users to bypass sandbox restrictions, and obtain sensitive information or possibly gain privileges, via unknown vectors.
Published 2008-11-10 · Modified
7.2EPSS 0.007
CVE-2007-1874
Adobe ColdFusion MX 7 for Linux and Solaris uses insecure permissions for certain scripts and directories, which allows local users to execute arbitrary code or obtain sensitive information via the (1) CFMX7DreamWeaverExtensions.mxp, (2) CFReportBuilderInstaller.exe, (3) .com.zerog.registry.xml, (4) uninstall.lax, (5) license.txt, (6) Readme.htm, (7) .com.zerog.registry.xml, (8) k2adminstop, or (9) k2adminstart files; or (10) certain files in lib/wsconfig/.
Published 2007-04-11 · Modified
7.2EPSS 0.007
CVE-2012-5674
Unspecified vulnerability in Adobe ColdFusion 10 before Update 5, when Internet Information Services (IIS) is used, allows attackers to cause a denial of service via unknown vectors.
Published 2012-11-20 · Modified
7.1EPSS 0.041
← Prev4 / 7Next →