Unrated severityNVD Advisory· Published Jul 8, 2025· Updated Jul 9, 2025
ColdFusion | Improper Restriction of XML External Entity Reference ('XXE') (CWE-611)
CVE-2025-49539
Description
ColdFusion versions 2025.2, 2023.14, 2021.20 and earlier are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could result in a security feature bypass. A high-privileged attacker could leverage this vulnerability to access sensitive information. Exploitation of this issue does not require user interaction. The vulnerable component is restricted to internal IP addresses.
Affected products
2- Range: <=2025.2
- Range: 0
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- helpx.adobe.com/security/products/coldfusion/apsb25-69.htmlmitrevendor-advisory
News mentions
0No linked articles in our index yet.