VYPR

Coldfusion

by Adobe Inc.

Source repositories

CVEs (264)

  • CVE-2007-1278Mar 16, 2007
    risk 0.02cvss epss 0.23

    Unspecified vulnerability in the IIS connector in Adobe JRun 4.0 Updater 6, and ColdFusion MX 6.1 and 7.0 Enterprise, when using Microsoft IIS 6, allows remote attackers to cause a denial of service via unspecified vectors, involving the request of a file in the JRun web root.

  • CVE-2026-48332HigJul 14, 2026
    risk 0.01cvss 7.7epss 0.11

    ColdFusion is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and gain unauthorized read access. Exploitation of this issue does…

  • CVE-2013-3350Jul 10, 2013
    risk 0.01cvss epss 0.08

    Adobe ColdFusion 10 before Update 11 allows remote attackers to call ColdFusion Components (CFC) public methods via WebSockets.

  • CVE-2008-1203Mar 12, 2008
    risk 0.01cvss epss 0.15

    The administrator interface for Adobe ColdFusion 8 and ColdFusion MX7 does not log failed authentication attempts, which makes it easier for remote attackers to conduct brute force attacks without detection.

  • CVE-2007-5905Nov 15, 2007
    risk 0.01cvss epss 0.13

    Adobe ColdFusion 8 and MX 7 allows remote attackers to hijack sessions via unspecified vectors that trigger establishment of a session to a ColdFusion application in which the (1) CFID or (2) CFTOKEN cookies have empty values, possibly due to a session fixation vulnerability.

  • CVE-2006-5858Dec 31, 2006
    risk 0.01cvss epss 0.13

    Adobe ColdFusion MX 7 through 7.0.2, and JRun 4, when run on Microsoft IIS, allows remote attackers to read arbitrary files, list directories, or read source code via a double URL-encoded NULL byte in a ColdFusion filename, such as a CFM file.

  • CVE-2026-48338MedJul 14, 2026
    risk 0.00cvss 6.8epss 0.00

    ColdFusion is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to access sensitive files and directories outside the intended…

  • CVE-2026-48329LowJul 14, 2026
    risk 0.00cvss 2.7epss 0.00

    ColdFusion is affected by an Insufficient Session Expiration vulnerability that could result in a Security feature bypass. A high-privileged attacker could leverage this vulnerability to bypass security measures and gain unauthorized write access. Exploitation of this issue does…

  • CVE-2026-48328HigJul 14, 2026
    risk 0.00cvss 7.7epss 0.01

    ColdFusion is affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and gain unauthorized read access. Exploitation of this issue does not…

  • CVE-2026-48327CriJul 14, 2026
    risk 0.00cvss 9.0epss 0.00

    ColdFusion is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed.

  • CVE-2026-48325CriJul 14, 2026
    risk 0.00cvss 9.3epss 0.01

    ColdFusion is affected by a Missing Authentication for Critical Function vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed.

  • CVE-2026-48324CriJul 14, 2026
    risk 0.00cvss 9.1epss 0.01

    ColdFusion is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker with high privileges could exploit this vulnerability to…

  • CVE-2026-48364HigJul 13, 2026
    risk 0.00cvss 8.2epss 0.00

    ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Uncontrolled Search Path Element vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a…

  • CVE-2026-48363HigJul 13, 2026
    risk 0.00cvss 8.2epss 0.00

    ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Uncontrolled Search Path Element vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a…

  • CVE-2026-48316CriJul 6, 2026
    risk 0.00cvss 10.0epss 0.02

    ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed.

  • CVE-2026-48315CriJun 30, 2026
    risk 0.00cvss 9.3epss 0.01

    ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to inject malicious scripts into a web page,…

  • CVE-2026-48314MedJun 30, 2026
    risk 0.00cvss 6.5epss 0.01

    ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to gain limited read and…

  • CVE-2026-48313CriJun 30, 2026
    risk 0.00cvss 9.3epss 0.04

    ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary file system read and limited write access. An attacker could exploit this vulnerability to…

  • CVE-2026-48307HigJun 30, 2026
    risk 0.00cvss 8.8epss 0.01

    ColdFusion versions 2025.9, 2023.20 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this vulnerability to inject malicious scripts into a web page, potentially resulting in arbitrary code execution in the context of the…

  • CVE-2026-48285HigJun 30, 2026
    risk 0.00cvss 8.6epss 0.01

    ColdFusion versions 2025.9, 2023.20 and earlier are affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized read access.…

Page 10 of 14