VYPR

Coldfusion

by Adobe Inc.

Source repositories

CVEs (273)

  • CVE-2025-64897MedDec 10, 2025
    risk 0.36cvss 5.6epss 0.00

    ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Improper Access Control vulnerability. A low privileged attacker could leverage this vulnerability to bypass security measures and gain limited unauthorized write access potentially resulting in denial…

  • CVE-2025-30291MedApr 8, 2025
    risk 0.36cvss 5.5epss 0.00

    ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by an Information Exposure vulnerability that could result in a security feature bypass. A low privileged attacker with local access could leverage this vulnerability to gain access to sensitive information…

  • CVE-2024-34113MedJun 13, 2024
    risk 0.36cvss 5.5epss 0.00

    ColdFusion versions 2023u7, 2021u13 and earlier are affected by a Weak Cryptography for Passwords vulnerability that could result in a security feature bypass. This vulnerability arises due to the use of insufficiently strong cryptographic algorithms or flawed implementation…

  • CVE-2023-38206MedSep 14, 2023
    risk 0.35cvss 5.3epss 0.01

    Adobe ColdFusion versions 2018u18 (and earlier), 2021u8 (and earlier) and 2023u2 (and earlier) are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to access the administration CFM…

  • CVE-2022-38423MedOct 14, 2022
    risk 0.35cvss 4.9epss 0.45

    Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in information disclosure. Exploitation of this issue does not require…

  • CVE-2018-15963MedSep 25, 2018
    risk 0.35cvss 5.3epss 0.06

    Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have a security bypass vulnerability. Successful exploitation could lead to arbitrary folder creation.

  • CVE-2018-15962MedSep 25, 2018
    risk 0.35cvss 5.3epss 0.06

    Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have a directory listing vulnerability. Successful exploitation could lead to information disclosure.

  • CVE-2011-0737MedFeb 1, 2011
    risk 0.35cvss 5.3epss 0.03

    Adobe ColdFusion 9.0.1 CHF1 and earlier allows remote attackers to obtain sensitive information via an id=- query to a .cfm file, which reveals the installation path in an error message. NOTE: the vendor disputes the significance of this issue because the Site-wide Error…

  • CVE-2011-0736MedFeb 1, 2011
    risk 0.35cvss 5.3epss 0.03

    Adobe ColdFusion 9.0.1 CHF1 and earlier, when a web application is configured to use a DBMS, allows remote attackers to obtain potentially sensitive information about the database structure via an id=- query to a .cfm file. NOTE: the vendor disputes the significance of this…

  • CVE-2025-64898MedDec 10, 2025
    risk 0.34cvss 5.3epss 0.00

    ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Insufficiently Protected Credentials vulnerability that could result in limited unauthorized write access. An attacker could leverage this vulnerability to gain unauthorized access by exploiting…

  • CVE-2025-49542MedJul 8, 2025
    risk 0.34cvss 5.2epss 0.01

    ColdFusion versions 2025.2, 2023.14, 2021.20 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an unauthenticated attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed…

  • CVE-2026-48384MedAug 11, 2026
    risk 0.32cvss 4.9epss 0.01

    ColdFusion is affected by an Improper Input Validation vulnerability that could result in an application denial-of-service. An attacker with high privileges could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this…

  • CVE-2023-44355MedNov 17, 2023
    risk 0.32cvss 4.3epss 0.47

    Adobe ColdFusion versions 2023.5 (and earlier) and 2021.11 (and earlier) are affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. An unauthenticated attacker could leverage this vulnerability to impact a minor integrity feature.…

  • CVE-2026-47933MedJun 9, 2026
    risk 0.31cvss 4.8epss 0.00

    ColdFusion versions 2023.19, 2025.8 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser…

  • CVE-2026-21269MedAug 11, 2026
    risk 0.30cvss 4.6epss 0.01

    ColdFusion is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page…

  • CVE-2025-49539MedJul 8, 2025
    risk 0.29cvss 4.5epss 0.00

    ColdFusion versions 2025.2, 2023.14, 2021.20 and earlier are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could result in a security feature bypass. A high-privileged attacker could leverage this vulnerability to access…

  • CVE-2025-49543MedJul 8, 2025
    risk 0.28cvss 4.3epss 0.01

    ColdFusion versions 2025.2, 2023.14, 2021.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a high-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a…

  • CVE-2025-49541MedJul 8, 2025
    risk 0.28cvss 4.3epss 0.01

    ColdFusion versions 2025.2, 2023.14, 2021.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a high-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a…

  • CVE-2025-49540MedJul 8, 2025
    risk 0.28cvss 4.3epss 0.01

    ColdFusion versions 2025.2, 2023.14, 2021.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a high-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a…

  • CVE-2026-48329LowJul 14, 2026
    risk 0.18cvss 2.7epss 0.01

    ColdFusion is affected by an Insufficient Session Expiration vulnerability that could result in a Security feature bypass. A high-privileged attacker could leverage this vulnerability to bypass security measures and gain unauthorized write access. Exploitation of this issue does…

Page 10 of 14