VendorsAdobecoldfusion2025
Vulnerabilities

Adobe ColdFusion 2025

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

114CVEs
CVE-2026-48282
ColdFusion | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)
Published 2026-06-30 · Analyzed
10.0KEVEPSS 0.424
CVE-2025-54261
ColdFusion | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)
Published 2025-09-09 · Analyzed
10.0EPSS 0.213
CVE-2026-48362
ColdFusion | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') (CWE-78)
Published 2026-08-11 · Analyzed
10.0EPSS 0.035
CVE-2026-48281
ColdFusion | Improper Input Validation (CWE-20)
Published 2026-06-30 · Analyzed
10.0EPSS 0.014
CVE-2026-48277
ColdFusion | Improper Input Validation (CWE-20)
Published 2026-06-30 · Analyzed
10.0EPSS 0.013
CVE-2026-48283
ColdFusion | Unrestricted Upload of File with Dangerous Type (CWE-434)
Published 2026-06-30 · Analyzed
10.0EPSS 0.013
CVE-2026-48276
ColdFusion | Unrestricted Upload of File with Dangerous Type (CWE-434)
Published 2026-06-30 · Analyzed
10.0EPSS 0.013
CVE-2026-48316
ColdFusion | Improper Input Validation (CWE-20)
Published 2026-07-06 · Analyzed
10.0EPSS 0.011
CVE-2026-48273
ColdFusion | Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') (CWE-95)
Published 2026-09-08 · Analyzed
9.9EPSS 0.013
CVE-2026-48322
ColdFusion | Improper Control of Generation of Code ('Code Injection') (CWE-94)
Published 2026-07-14 · Analyzed
9.9EPSS 0.012
CVE-2026-48318
ColdFusion | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)
Published 2026-07-14 · Analyzed
9.9EPSS 0.011
CVE-2026-48284
ColdFusion | Improper Input Validation (CWE-20)
Published 2026-07-14 · Analyzed
9.6EPSS 0.005
CVE-2026-47928
ColdFusion | Improper Input Validation (CWE-20)
Published 2026-06-09 · Analyzed
9.6EPSS 0.005
CVE-2026-71384
ColdFusion | Incorrect Authorization (CWE-863)
Published 2026-08-11 · Analyzed
9.6EPSS 0.005
CVE-2026-48313
ColdFusion | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)
Published 2026-06-30 · Analyzed
9.3EPSS 0.030
CVE-2026-48315
ColdFusion | Improper Input Validation (CWE-20)
Published 2026-06-30 · Analyzed
9.3EPSS 0.010
CVE-2026-48325
ColdFusion | Missing Authentication for Critical Function (CWE-306)
Published 2026-07-14 · Analyzed
9.3EPSS 0.006
CVE-2025-49535
ColdFusion | Improper Restriction of XML External Entity Reference ('XXE') (CWE-611)
Published 2025-07-08 · Analyzed
9.3EPSS 0.006
CVE-2026-27304
ColdFusion | Improper Input Validation (CWE-20)
Published 2026-04-14 · Analyzed
9.3EPSS 0.005
CVE-2026-48321
ColdFusion | Incorrect Authorization (CWE-863)
Published 2026-07-14 · Analyzed
9.3EPSS 0.004
CVE-2025-43562
ColdFusion | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') (CWE-78)
Published 2025-05-13 · Analyzed
9.1EPSS 0.451
CVE-2025-30281
ColdFusion | Improper Access Control (CWE-284)
Published 2025-04-08 · Analyzed
9.1EPSS 0.236
CVE-2025-43561
ColdFusion | Incorrect Authorization (CWE-863)
Published 2025-05-13 · Analyzed
9.1EPSS 0.206
CVE-2025-43560
ColdFusion | Improper Input Validation (CWE-20)
Published 2025-05-13 · Analyzed
9.1EPSS 0.194
CVE-2025-43564
ColdFusion | Incorrect Authorization (CWE-863)
Published 2025-05-13 · Analyzed
9.1EPSS 0.154
CVE-2025-43563
ColdFusion | Improper Access Control (CWE-284)
Published 2025-05-13 · Analyzed
9.1EPSS 0.153
CVE-2025-61808
ColdFusion | Unrestricted Upload of File with Dangerous Type (CWE-434)
Published 2025-12-09 · Analyzed
9.1EPSS 0.106
CVE-2025-24447
ColdFusion | Deserialization of Untrusted Data (CWE-502)
Published 2025-04-08 · Analyzed
9.1EPSS 0.021
CVE-2025-30282
ColdFusion | Improper Authentication (CWE-287)
Published 2025-04-08 · Analyzed
9.1EPSS 0.018
CVE-2025-24446
ColdFusion | Improper Input Validation (CWE-20)
Published 2025-04-08 · Analyzed
9.1EPSS 0.018
CVE-2025-43559
ColdFusion | Improper Input Validation (CWE-20)
Published 2025-05-13 · Analyzed
9.1EPSS 0.015
CVE-2026-48319
ColdFusion | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)
Published 2026-07-14 · Analyzed
9.1EPSS 0.014
CVE-2025-61811
ColdFusion | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)
Published 2025-12-09 · Modified
9.1EPSS 0.012
CVE-2026-48324
ColdFusion | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') (CWE-89)
Published 2026-07-14 · Analyzed
9.1EPSS 0.011
CVE-2026-75746
ColdFusion | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') (CWE-89)
Published 2026-09-08 · Analyzed
9.1EPSS 0.010
CVE-2025-61809
ColdFusion | Improper Input Validation (CWE-20)
Published 2025-12-09 · Analyzed
9.1EPSS 0.007
CVE-2026-48327
ColdFusion | Incorrect Authorization (CWE-863)
Published 2026-07-14 · Analyzed
9.0EPSS 0.004
CVE-2026-71386
ColdFusion | Cross-site Scripting (XSS) (CWE-79)
Published 2026-08-11 · Analyzed
8.8EPSS 0.006
CVE-2026-48307
ColdFusion | Cross-site Scripting (Reflected XSS) (CWE-79)
Published 2026-06-30 · Analyzed
8.8EPSS 0.006
CVE-2026-47932
ColdFusion | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)
Published 2026-06-09 · Analyzed
8.8EPSS 0.005
1 / 3Next →