Unrated severityNVD Advisory· Published Jul 8, 2025· Updated Jul 9, 2025
ColdFusion | Cross-site Scripting (Stored XSS) (CWE-79)
CVE-2025-49541
Description
ColdFusion versions 2025.2, 2023.14, 2021.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a high-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field, scope is changed. The vulnerable component is restricted to internal IP addresses.
Affected products
2<=2021.20, <=2023.14, <=2025.2+ 1 more
- (no CPE)range: <=2021.20, <=2023.14, <=2025.2
- (no CPE)range: 0
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- helpx.adobe.com/security/products/coldfusion/apsb25-69.htmlmitrevendor-advisory
News mentions
0No linked articles in our index yet.