VendorsAdobecoldfusion2023
Vulnerabilities

Adobe ColdFusion 2023

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

132CVEs
CVE-2026-48282
ColdFusion | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)
Published 2026-06-30 · Analyzed
10.0KEVEPSS 0.424
CVE-2025-54261
ColdFusion | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)
Published 2025-09-09 · Analyzed
10.0EPSS 0.213
CVE-2026-48362
ColdFusion | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') (CWE-78)
Published 2026-08-11 · Analyzed
10.0EPSS 0.035
CVE-2026-48281
ColdFusion | Improper Input Validation (CWE-20)
Published 2026-06-30 · Analyzed
10.0EPSS 0.014
CVE-2026-48277
ColdFusion | Improper Input Validation (CWE-20)
Published 2026-06-30 · Analyzed
10.0EPSS 0.013
CVE-2026-48276
ColdFusion | Unrestricted Upload of File with Dangerous Type (CWE-434)
Published 2026-06-30 · Analyzed
10.0EPSS 0.013
CVE-2026-48283
ColdFusion | Unrestricted Upload of File with Dangerous Type (CWE-434)
Published 2026-06-30 · Analyzed
10.0EPSS 0.013
CVE-2026-48316
ColdFusion | Improper Input Validation (CWE-20)
Published 2026-07-06 · Analyzed
10.0EPSS 0.011
CVE-2026-48273
ColdFusion | Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') (CWE-95)
Published 2026-09-08 · Analyzed
9.9EPSS 0.013
CVE-2026-48322
ColdFusion | Improper Control of Generation of Code ('Code Injection') (CWE-94)
Published 2026-07-14 · Analyzed
9.9EPSS 0.012
CVE-2026-48318
ColdFusion | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)
Published 2026-07-14 · Analyzed
9.9EPSS 0.011
CVE-2023-29300
Adobe ColdFusion Deserialization of Untrusted Data Arbitrary code execution
Published 2023-07-12 · Analyzed
9.8KEVEPSS 1.000
CVE-2023-38203
Analysis CVE-2023-29300 Bypass: Adobe ColdFusion Pre-Auth RCE
Published 2023-07-20 · Analyzed
9.8KEVEPSS 0.971
CVE-2023-44353
ColdFusion WDDX Deserialization Gadgets
Published 2023-11-17 · Modified
9.8EPSS 0.802
CVE-2023-38204
Bypass APSB23-41 (CVE-2023-38203) - Pre-Auth RCE ColdFusion 2021 Update 8
Published 2023-09-14 · Modified
9.8EPSS 0.662
CVE-2023-44350
ColdFusion | Deserialization of Untrusted Data (CWE-502)
Published 2023-11-17 · Modified
9.8EPSS 0.646
CVE-2023-44351
Adobe ColdFusion RCE Security Vulnerability
Published 2023-11-17 · Modified
9.8EPSS 0.502
CVE-2024-41874
ColdFusion | Deserialization of Untrusted Data (CWE-502)
Published 2024-09-13 · Analyzed
9.8EPSS 0.303
CVE-2026-48284
ColdFusion | Improper Input Validation (CWE-20)
Published 2026-07-14 · Analyzed
9.6EPSS 0.005
CVE-2026-47928
ColdFusion | Improper Input Validation (CWE-20)
Published 2026-06-09 · Analyzed
9.6EPSS 0.005
CVE-2026-71384
ColdFusion | Incorrect Authorization (CWE-863)
Published 2026-08-11 · Analyzed
9.6EPSS 0.005
CVE-2026-48313
ColdFusion | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)
Published 2026-06-30 · Analyzed
9.3EPSS 0.030
CVE-2026-48315
ColdFusion | Improper Input Validation (CWE-20)
Published 2026-06-30 · Analyzed
9.3EPSS 0.010
CVE-2026-48325
ColdFusion | Missing Authentication for Critical Function (CWE-306)
Published 2026-07-14 · Analyzed
9.3EPSS 0.006
CVE-2025-49535
ColdFusion | Improper Restriction of XML External Entity Reference ('XXE') (CWE-611)
Published 2025-07-08 · Analyzed
9.3EPSS 0.006
CVE-2026-27304
ColdFusion | Improper Input Validation (CWE-20)
Published 2026-04-14 · Analyzed
9.3EPSS 0.005
CVE-2026-48321
ColdFusion | Incorrect Authorization (CWE-863)
Published 2026-07-14 · Analyzed
9.3EPSS 0.004
CVE-2025-43562
ColdFusion | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') (CWE-78)
Published 2025-05-13 · Analyzed
9.1EPSS 0.451
CVE-2025-30281
ColdFusion | Improper Access Control (CWE-284)
Published 2025-04-08 · Analyzed
9.1EPSS 0.236
CVE-2025-43561
ColdFusion | Incorrect Authorization (CWE-863)
Published 2025-05-13 · Analyzed
9.1EPSS 0.206
CVE-2025-43560
ColdFusion | Improper Input Validation (CWE-20)
Published 2025-05-13 · Analyzed
9.1EPSS 0.194
CVE-2025-43564
ColdFusion | Incorrect Authorization (CWE-863)
Published 2025-05-13 · Analyzed
9.1EPSS 0.154
CVE-2025-43563
ColdFusion | Improper Access Control (CWE-284)
Published 2025-05-13 · Analyzed
9.1EPSS 0.153
CVE-2025-61808
ColdFusion | Unrestricted Upload of File with Dangerous Type (CWE-434)
Published 2025-12-09 · Analyzed
9.1EPSS 0.106
CVE-2025-24447
ColdFusion | Deserialization of Untrusted Data (CWE-502)
Published 2025-04-08 · Analyzed
9.1EPSS 0.021
CVE-2025-30282
ColdFusion | Improper Authentication (CWE-287)
Published 2025-04-08 · Analyzed
9.1EPSS 0.018
CVE-2025-24446
ColdFusion | Improper Input Validation (CWE-20)
Published 2025-04-08 · Analyzed
9.1EPSS 0.018
CVE-2025-43559
ColdFusion | Improper Input Validation (CWE-20)
Published 2025-05-13 · Analyzed
9.1EPSS 0.015
CVE-2026-48319
ColdFusion | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)
Published 2026-07-14 · Analyzed
9.1EPSS 0.014
CVE-2025-61811
ColdFusion | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)
Published 2025-12-09 · Modified
9.1EPSS 0.012
1 / 4Next →