VendorsAdobecoldfusionall versions
Vulnerabilities

Adobe ColdFusion

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

266CVEs
CVE-2011-0737
Adobe ColdFusion 9.0.1 CHF1 and earlier allows remote attackers to obtain sensitive information via an id=- query to a .cfm file, which reveals the installation path in an error message. NOTE: the vendor disputes the significance of this issue because the Site-wide Error Handler and Debug Output Settings sections of the ColdFusion Lockdown guide explain the requirement for settings that prevent this information disclosure
Published 2011-02-01 · Modified
5.3EPSS 0.028
CVE-2011-0736
Adobe ColdFusion 9.0.1 CHF1 and earlier, when a web application is configured to use a DBMS, allows remote attackers to obtain potentially sensitive information about the database structure via an id=- query to a .cfm file. NOTE: the vendor disputes the significance of this issue because the Site-wide Error Handler and Debug Output Settings sections of the ColdFusion Lockdown guide explain the requirement for settings that prevent this information disclosure
Published 2011-02-01 · Modified
5.3EPSS 0.027
CVE-2023-38206
ColdFusion | Improper Access Control (CWE-284)
Published 2023-09-14 · Modified
5.3EPSS 0.007
CVE-2025-64898
ColdFusion | Insufficiently Protected Credentials (CWE-522)
Published 2025-12-09 · Analyzed
5.3EPSS 0.004
CVE-2025-49542
ColdFusion | Cross-site Scripting (Reflected XSS) (CWE-79)
Published 2025-07-08 · Analyzed
5.2EPSS 0.011
CVE-2013-3336
Unspecified vulnerability in Adobe ColdFusion 9.0, 9.0.1, 9.0.2, and 10 allows remote attackers to read arbitrary files via unknown vectors.
Published 2013-05-09 · Modified
5.01 PoCEPSS 0.743
CVE-2006-5858
Adobe ColdFusion MX 7 through 7.0.2, and JRun 4, when run on Microsoft IIS, allows remote attackers to read arbitrary files, list directories, or read source code via a double URL-encoded NULL byte in a ColdFusion filename, such as a CFM file.
Published 2007-01-10 · Modified
5.0EPSS 0.133
CVE-2010-0185
The default configuration of Adobe ColdFusion 9.0 does not restrict access to collections that have been created by the Solr Service, which allows remote attackers to obtain collection metadata, search information, and index data via a request to an unspecified URL.
Published 2010-02-03 · Modified
5.0EPSS 0.044
CVE-2011-0582
Unspecified vulnerability in the administrator console in Adobe ColdFusion 8.0 through 9.0.1 allows attackers to obtain sensitive information via unknown vectors.
Published 2011-02-10 · Modified
5.0EPSS 0.038
CVE-2012-2048
Unspecified vulnerability in Adobe ColdFusion 10 and earlier allows attackers to cause a denial of service via unknown vectors.
Published 2012-09-12 · Modified
5.0EPSS 0.036
CVE-2011-2091
Unspecified vulnerability in Adobe ColdFusion 8.0, 8.0.1, 9.0, and 9.0.1 allows remote attackers to cause a denial of service via unknown vectors.
Published 2011-06-16 · Modified
5.0EPSS 0.033
CVE-2008-0644
Adobe ColdFusion MX 7 and ColdFusion 8 allows remote attackers to bypass the cross-site scripting (XSS) protection mechanism for applications via unspecified vectors related to the setEncoding function.
Published 2008-03-12 · Modified
5.0EPSS 0.031
CVE-2014-9166
Adobe ColdFusion 10 before Update 15 and 11 before Update 3 allows attackers to cause a denial of service (resource consumption) via unspecified vectors.
Published 2014-12-10 · Modified
5.0EPSS 0.030
CVE-2012-0770
Adobe ColdFusion 8.0, 8.0.1, 9.0, and 9.0.1 computes hash values for form parameters without restricting the ability to trigger hash collisions predictably, which allows remote attackers to cause a denial of service (CPU consumption) by sending many crafted parameters.
Published 2012-03-13 · Modified
5.0EPSS 0.029
CVE-2009-1876
Adobe ColdFusion 8.0.1 and earlier might allow attackers to obtain sensitive information via unspecified vectors, related to a "double-encoded null character vulnerability."
Published 2009-08-18 · Modified
5.0EPSS 0.028
CVE-2006-4724
Unspecified vulnerability in the ColdFusion Flash Remoting Gateway in Adobe ColdFusion MX 7 and 7.01 allows remote attackers to cause a denial of service (infinite loop) via unspecified vectors involving a crafted command.
Published 2006-09-14 · Modified
5.0EPSS 0.025
CVE-2006-6482
Adobe ColdFusion MX7 allows remote attackers to obtain sensitive information via a URL request (1) for a non-existent (a) JWS, (b) CFM, (c) CFML, or (d) CFC file, which displays the installation path in the resulting error message; or (2) to /CFIDE/administrator/login.cfm without a host, which can reveal the server's internal IP address in an HREF tag.
Published 2006-12-12 · Modified
5.0EPSS 0.023
CVE-2013-3349
Unspecified vulnerability in Adobe ColdFusion 9.0 through 9.0.2, when the JRun application server is used, allows remote attackers to cause a denial of service via unknown vectors.
Published 2013-07-10 · Modified
5.0EPSS 0.022
CVE-2023-26361
Adobe ColdFusion Directory Traversal Arbitrary file system read Vulnerability
Published 2023-03-23 · Modified
4.9EPSS 0.587
CVE-2022-38423
Adobe ColdFusion Application Server Directory Traversal Information Disclosure Vulnerability
Published 2022-10-14 · Modified
4.9EPSS 0.450
CVE-2026-48384
ColdFusion | Improper Input Validation (CWE-20)
Published 2026-08-11 · Analyzed
4.9EPSS 0.010
CVE-2026-47933
ColdFusion | Cross-site Scripting (Stored XSS) (CWE-79)
Published 2026-06-09 · Analyzed
4.8EPSS 0.004
CVE-2014-0572
Adobe ColdFusion 9.0 before Update 13, 9.0.1 before Update 12, 9.0.2 before Update 7, 10 before Update 14, and 11 before Update 2 allows local users to bypass intended IP-based access restrictions via unspecified vectors.
Published 2014-10-15 · Modified
4.6EPSS 0.015
CVE-2006-3978
Unspecified vulnerability in a Verity third party library, as used on Adobe ColdFusion MX 7 through MX 7.0.2 and possibly other products, allows local users to execute arbitrary code via unknown attack vectors.
Published 2006-10-10 · Modified
4.6EPSS 0.009
CVE-2006-4725
Adobe ColdFusion MX 7 and 7.01 allows local users to bypass security restrictions and call components (CFC) within a sandbox from CFML templates that are located outside of the sandbox.
Published 2006-09-14 · Modified
4.6EPSS 0.006
CVE-2025-49539
ColdFusion | Improper Restriction of XML External Entity Reference ('XXE') (CWE-611)
Published 2025-07-08 · Analyzed
4.5EPSS 0.005
CVE-2012-5675
Adobe ColdFusion 9.0 through 9.0.2, and 10, allows local users to bypass intended shared-hosting sandbox permissions via unspecified vectors.
Published 2012-12-12 · Modified
4.4EPSS 0.007
CVE-2023-44355
ColdFusion | Improper Input Validation (CWE-20)
Published 2023-11-17 · Modified
4.3EPSS 0.472
CVE-2007-1278
Unspecified vulnerability in the IIS connector in Adobe JRun 4.0 Updater 6, and ColdFusion MX 6.1 and 7.0 Enterprise, when using Microsoft IIS 6, allows remote attackers to cause a denial of service via unspecified vectors, involving the request of a file in the JRun web root.
Published 2007-03-16 · Modified
4.3EPSS 0.226
CVE-2009-1872
Multiple cross-site scripting (XSS) vulnerabilities in Adobe ColdFusion Server 8.0.1, 8, and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the startRow parameter to administrator/logviewer/searchlog.cfm, or the query string to (2) wizards/common/_logintowizard.cfm, (3) wizards/common/_authenticatewizarduser.cfm, or (4) administrator/enter.cfm.
Published 2009-08-18 · Modified
4.34 PoCEPSS 0.161
CVE-2007-0817
Cross-site scripting (XSS) vulnerability in Adobe ColdFusion web server allows remote attackers to inject arbitrary HTML or web script via the User-Agent HTTP header, which is not sanitized before being displayed in an error page.
Published 2007-02-07 · Modified
4.31 PoCEPSS 0.086
CVE-2015-5255
Adobe BlazeDS, as used in ColdFusion 10 before Update 18 and 11 before Update 7 and LiveCycle Data Services 3.0.x before 3.0.0.354175, 3.1.x before 3.1.0.354180, 4.5.x before 4.5.1.354177, 4.6.2.x before 4.6.2.354178, and 4.7.x before 4.7.0.354178, allows remote attackers to send HTTP traffic to intranet servers via a crafted XML document, related to a Server-Side Request Forgery (SSRF) issue.
Published 2015-11-18 · Modified
4.3EPSS 0.045
CVE-2011-0733
Cross-site scripting (XSS) vulnerability in Adobe ColdFusion before 9.0.1 CHF1 allows remote attackers to inject arbitrary web script or HTML via the User-Agent HTTP header in an id=- query to a .cfm file.
Published 2011-02-01 · Modified
4.3EPSS 0.041
CVE-2011-0734
Cross-site scripting (XSS) vulnerability in Adobe ColdFusion before 9.0.1 CHF1 allows remote attackers to inject arbitrary web script or HTML via an id parameter containing a JavaScript onLoad event handler for a BODY element, related to a "tag body" attack. NOTE: this was originally reported as affecting 9.0.1 CHF1 and earlier.
Published 2011-02-01 · Modified
4.3EPSS 0.041
CVE-2015-0345
Cross-site scripting (XSS) vulnerability in Adobe ColdFusion 10 before Update 16 and 11 before Update 5 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Published 2015-04-15 · Modified
4.3EPSS 0.034
CVE-2015-8052
Cross-site scripting (XSS) vulnerability in Adobe ColdFusion 10 before Update 18 and 11 before Update 7 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2015-8053.
Published 2015-11-18 · Modified
4.3EPSS 0.031
CVE-2015-8053
Cross-site scripting (XSS) vulnerability in Adobe ColdFusion 10 before Update 18 and 11 before Update 7 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2015-8052.
Published 2015-11-18 · Modified
4.3EPSS 0.031
CVE-2006-5860
Cross-site scripting (XSS) vulnerability in the administrator console for Adobe JRun 4.0, as used in ColdFusion, allows remote attackers to inject arbitrary web script or HTML via unknown vectors.
Published 2007-02-14 · Modified
4.3EPSS 0.029
CVE-2014-0571
Cross-site scripting (XSS) vulnerability in Adobe ColdFusion 9.0 before Update 13, 9.0.1 before Update 12, 9.0.2 before Update 7, 10 before Update 14, and 11 before Update 2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Published 2014-10-15 · Modified
4.3EPSS 0.027
CVE-2006-5859
Cross-site scripting (XSS) vulnerability in Adobe ColdFusion MX 7 7.0 and 7.0.1, when Global Script Protection is not enabled, allows remote attackers to inject arbitrary HTML and web script via unknown vectors, possibly related to Linkdirect.cfm, Topnav.cfm, and Welcomedoc.cfm.
Published 2007-02-14 · Modified
4.3EPSS 0.027
← Prev6 / 7Next →