VendorsAdobecoldfusionall versions
Vulnerabilities

Adobe ColdFusion

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

266CVEs
CVE-2026-83961
ColdFusion | Improper Authentication (CWE-287)
Published 2026-09-03 · Analyzed
7.1EPSS 0.004
CVE-2025-43566
ColdFusion | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)
Published 2025-05-13 · Analyzed
6.8EPSS 0.551
CVE-2025-30294
ColdFusion | Improper Input Validation (CWE-20)
Published 2025-04-08 · Analyzed
6.8EPSS 0.172
CVE-2007-5905
Adobe ColdFusion 8 and MX 7 allows remote attackers to hijack sessions via unspecified vectors that trigger establishment of a session to a ColdFusion application in which the (1) CFID or (2) CFTOKEN cookies have empty values, possibly due to a session fixation vulnerability.
Published 2007-11-15 · Modified
6.8EPSS 0.131
CVE-2014-0570
Cross-site request forgery (CSRF) vulnerability in Adobe ColdFusion 9.0 before Update 13, 9.0.1 before Update 12, 9.0.2 before Update 7, 10 before Update 14, and 11 before Update 2 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.
Published 2014-10-15 · Modified
6.8EPSS 0.025
CVE-2011-0629
Cross-site request forgery (CSRF) vulnerability in Adobe ColdFusion 8.0, 8.0.1, 9.0, and 9.0.1 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.
Published 2011-06-16 · Modified
6.8EPSS 0.014
CVE-2025-30293
ColdFusion | Improper Input Validation (CWE-20)
Published 2025-04-08 · Analyzed
6.8EPSS 0.008
CVE-2025-49544
ColdFusion | Improper Restriction of XML External Entity Reference ('XXE') (CWE-611)
Published 2025-07-08 · Analyzed
6.8EPSS 0.006
CVE-2025-61821
ColdFusion | Improper Restriction of XML External Entity Reference ('XXE') (CWE-611)
Published 2025-12-09 · Analyzed
6.8EPSS 0.005
CVE-2026-48338
ColdFusion | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)
Published 2026-07-14 · Analyzed
6.8EPSS 0.005
CVE-2009-3960
Unspecified vulnerability in BlazeDS 3.2 and earlier, as used in LiveCycle 8.0.1, 8.2.1, and 9.0, LiveCycle Data Services 2.5.1, 2.6.1, and 3.0, Flex Data Services 2.0.1, and ColdFusion 7.0.2, 8.0, 8.0.1, and 9.0, allows remote attackers to obtain sensitive information via vectors that are associated with a request, and related to injected tags and external entity references in XML documents.
Published 2010-02-15 · Analyzed
6.5KEV2 PoCEPSS 0.901
CVE-2020-3796
ColdFusion versions ColdFusion 2016, and ColdFusion 2018 have an improper access control vulnerability. Successful exploitation could lead to system file structure disclosure.
Published 2020-06-26 · Modified
6.5EPSS 0.043
CVE-2020-3767
ColdFusion versions ColdFusion 2016, and ColdFusion 2018 have an insufficient input validation vulnerability. Successful exploitation could lead to application-level denial-of-service (dos).
Published 2020-06-26 · Modified
6.5EPSS 0.035
CVE-2026-48375
ColdFusion | Incorrect Authorization (CWE-863)
Published 2026-08-11 · Analyzed
6.5EPSS 0.008
CVE-2026-48314
ColdFusion | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)
Published 2026-06-30 · Analyzed
6.5EPSS 0.006
CVE-2026-76000
ColdFusion | Uncontrolled Resource Consumption (CWE-400)
Published 2026-09-08 · Analyzed
6.5EPSS 0.004
CVE-2025-61822
ColdFusion | Improper Input Validation (CWE-20)
Published 2025-12-09 · Analyzed
6.2EPSS 0.007
CVE-2025-61823
ColdFusion | Improper Restriction of XML External Entity Reference ('XXE') (CWE-611)
Published 2025-12-09 · Analyzed
6.2EPSS 0.005
CVE-2025-49545
ColdFusion | Server-Side Request Forgery (SSRF) (CWE-918)
Published 2025-07-08 · Analyzed
6.2EPSS 0.004
CVE-2023-44352
Unauthenticate Reflected XSS on Adobe Coldfusion 2018 - 2021 - 2023 last version
Published 2023-11-17 · Modified
6.1EPSS 0.848
CVE-2022-28818
ColdFusion Reflected Cross-Site Scripting could lead to Arbitrary Code Execution
Published 2022-05-12 · Modified
6.1EPSS 0.448
CVE-2025-30292
ColdFusion | Cross-site Scripting (Reflected XSS) (CWE-79)
Published 2025-04-08 · Analyzed
6.1EPSS 0.155
CVE-2017-3008
Adobe ColdFusion 2016 Update 3 and earlier, ColdFusion 11 update 11 and earlier, ColdFusion 10 Update 22 and earlier have a reflected cross-site scripting vulnerability.
Published 2017-04-27 · Modified
6.1EPSS 0.031
CVE-2016-1113
Cross-site scripting (XSS) vulnerability in Adobe ColdFusion 10 before Update 19, 11 before Update 8, and 2016 before Update 1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Published 2016-05-11 · Modified
6.1EPSS 0.031
CVE-2017-11285
Adobe ColdFusion has a cross-site scripting (XSS) vulnerability. This affects Update 4 and earlier versions for ColdFusion 2016, and Update 12 and earlier versions for ColdFusion 11.
Published 2017-12-01 · Modified
6.1EPSS 0.027
CVE-2019-7092
ColdFusion versions Update 1 and earlier, Update 7 and earlier, and Update 15 and earlier have a cross site scripting vulnerability. Successful exploitation could lead to information disclosure .
Published 2019-05-24 · Modified
6.1EPSS 0.024
CVE-2016-4159
Cross-site scripting (XSS) vulnerability in Adobe ColdFusion 10 before Update 20, 11 before Update 9, and 2016 before Update 2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Published 2016-06-16 · Modified
6.1EPSS 0.019
CVE-2018-4940
Adobe ColdFusion Update 5 and earlier versions, ColdFusion 11 Update 13 and earlier versions have an exploitable Cross-Site Scripting vulnerability. Successful exploitation could lead to information disclosure.
Published 2018-05-19 · Modified
6.1EPSS 0.017
CVE-2018-4941
Adobe ColdFusion Update 5 and earlier versions, ColdFusion 11 Update 13 and earlier versions have an exploitable Cross-Site Scripting vulnerability. Successful exploitation could lead to information disclosure.
Published 2018-05-19 · Modified
6.1EPSS 0.017
CVE-2026-76002
ColdFusion | Cross-site Scripting (Reflected XSS) (CWE-79)
Published 2026-09-08 · Analyzed
6.1EPSS 0.004
CVE-2016-1115
Adobe ColdFusion 10 before Update 19, 11 before Update 8, and 2016 before Update 1 mishandles wildcards in name fields of X.509 certificates, which might allow man-in-the-middle attackers to spoof servers via a crafted certificate.
Published 2016-05-11 · Modified
5.9EPSS 0.025
CVE-2009-1878
Session fixation vulnerability in Adobe ColdFusion 8.0.1 and earlier allows remote attackers to hijack web sessions via unspecified vectors.
Published 2009-08-18 · Modified
5.8EPSS 0.023
CVE-2025-64897
ColdFusion | Improper Access Control (CWE-284)
Published 2025-12-09 · Analyzed
5.6EPSS 0.001
CVE-2024-34113
ColdFusion | Weak Cryptography for Passwords (CWE-261)
Published 2024-06-13 · Modified
5.5EPSS 0.003
CVE-2025-30291
ColdFusion | Information Exposure (CWE-200)
Published 2025-04-08 · Analyzed
5.5EPSS 0.002
CVE-2021-21087
ColdFusion Improper neutralization of web input during page generation could lead to arbitrary JavaScript execution in the browser
Published 2021-04-15 · Modified
5.4EPSS 0.371
CVE-2026-48376
ColdFusion | Improper Encoding or Escaping of Output (CWE-116)
Published 2026-08-11 · Analyzed
5.4EPSS 0.007
CVE-2026-21269
ColdFusion | Cross-site Scripting (Stored XSS) (CWE-79)
Published 2026-08-11 · Modified
5.4EPSS 0.005
CVE-2018-15963
Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have a security bypass vulnerability. Successful exploitation could lead to arbitrary folder creation.
Published 2018-09-25 · Modified
5.3EPSS 0.057
CVE-2018-15962
Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have a directory listing vulnerability. Successful exploitation could lead to information disclosure.
Published 2018-09-25 · Modified
5.3EPSS 0.055
← Prev5 / 7Next →