VYPR

Coldfusion

by Adobe Inc.

Source repositories

CVEs (264)

  • CVE-2026-48322CriJul 14, 2026
    risk 0.64cvss 9.9epss 0.01

    ColdFusion is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability that could result in arbitrary code execution in the context of the current user. A low-privileged attacker could exploit this vulnerability to execute arbitrary code.…

  • CVE-2020-3794CriMar 25, 2020
    risk 0.64cvss 9.8epss 0.07

    ColdFusion versions ColdFusion 2016, and ColdFusion 2018 have a file inclusion vulnerability. Successful exploitation could lead to arbitrary code execution of files located in the webroot or its subdirectory.

  • CVE-2019-8256CriDec 19, 2019
    risk 0.64cvss 9.8epss 0.04

    ColdFusion versions Update 6 and earlier have an insecure inherited permissions of default installation directory vulnerability. Successful exploitation could lead to privilege escalation.

  • CVE-2019-8073CriSep 27, 2019
    risk 0.64cvss 9.8epss 0.08

    ColdFusion 2018- update 4 and earlier and ColdFusion 2016- update 11 and earlier have a Command Injection via Vulnerable component vulnerability. Successful exploitation could lead to Arbitrary code execution in the context of the current user.

  • CVE-2016-4264HigSep 1, 2016
    risk 0.64cvss 8.6epss 0.69

    The Office Open XML (OOXML) feature in Adobe ColdFusion 10 before Update 21 and 11 before Update 10 allows remote attackers to read arbitrary files or send TCP requests to intranet servers via a crafted OOXML spreadsheet containing an external entity declaration in conjunction…

  • CVE-2016-1114CriMay 11, 2016
    risk 0.64cvss 9.8epss 0.09

    Adobe ColdFusion 10 before Update 19, 11 before Update 8, and 2016 before Update 1 allows remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the Apache Commons Collections library.

  • CVE-2026-48284CriJul 14, 2026
    risk 0.63cvss 9.6epss 0.05

    ColdFusion is affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. The vulnerable component is restricted to an administrative network zone by default. Exploitation of this issue does not require…

  • CVE-2026-47928CriJun 9, 2026
    risk 0.63cvss 9.6epss 0.02

    ColdFusion versions 2023.19, 2025.8 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. The vulnerable component is restricted to an administrative network zone by default.…

  • CVE-2026-71384CriAug 11, 2026
    risk 0.62cvss 9.6epss 0.00

    is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized read and write access, potentially resulting in an application…

  • CVE-2025-43562CriMay 13, 2025
    risk 0.62cvss 9.1epss 0.37

    ColdFusion versions 2025.1, 2023.13, 2021.19 and earlier are affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could result in arbitrary code execution in the context of the current user. A…

  • CVE-2026-27304CriApr 14, 2026
    risk 0.61cvss 9.3epss 0.04

    ColdFusion versions 2023.18, 2025.6 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction.

  • CVE-2026-48321CriJul 14, 2026
    risk 0.60cvss 9.3epss 0.00

    ColdFusion is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could leverage this vulnerability to gain unauthorized read and write access. The vulnerable component is restricted to an administrative network zone by…

  • CVE-2025-61808CriDec 10, 2025
    risk 0.60cvss 9.1epss 0.10

    ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Unrestricted Upload of File with Dangerous Type vulnerability that could lead to arbitrary code execution by a high priviledged attacker. Exploitation of this issue does not require user interaction and…

  • CVE-2025-49535CriJul 8, 2025
    risk 0.60cvss 9.3epss 0.01

    ColdFusion versions 2025.2, 2023.14, 2021.20 and earlier are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could result in a Security feature bypass. An attacker could exploit this vulnerability to access sensitive information or…

  • CVE-2025-43564CriMay 13, 2025
    risk 0.60cvss 9.1epss 0.11

    ColdFusion versions 2025.1, 2023.13, 2021.19 and earlier are affected by an Improper Access Control vulnerability that could result in arbitrary file system read. A high-privileged attacker could leverage this vulnerability to access or modify sensitive data without proper…

  • CVE-2025-43563CriMay 13, 2025
    risk 0.60cvss 9.1epss 0.11

    ColdFusion versions 2025.1, 2023.13, 2021.19 and earlier are affected by an Improper Access Control vulnerability that could result in arbitrary file system read. A high-privileged attacker could leverage this vulnerability to access or modify sensitive data without proper…

  • CVE-2025-43561CriMay 13, 2025
    risk 0.60cvss 9.1epss 0.16

    ColdFusion versions 2025.1, 2023.13, 2021.19 and earlier are affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. A high-privileged attacker could leverage this vulnerability to bypass…

  • CVE-2025-43560CriMay 13, 2025
    risk 0.60cvss 9.1epss 0.14

    ColdFusion versions 2025.1, 2023.13, 2021.19 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. A high-privileged attacker could leverage this vulnerability to bypass security…

  • CVE-2025-30281CriApr 8, 2025
    risk 0.60cvss 9.1epss 0.20

    ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by an Improper Access Control vulnerability that could result in arbitrary code execution. A high-privileged attacker could leverage this vulnerability to access or modify sensitive data without proper…

  • CVE-2025-61811CriDec 10, 2025
    risk 0.59cvss 9.1epss 0.01

    ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Improper Access Control vulnerability that could result in arbitrary code execution in the context of the current user. A high privileged attacker could leverage this vulnerability to bypass security…

Page 3 of 14