VYPR

Coldfusion

by Adobe Inc.

Source repositories

CVEs (264)

  • CVE-2018-4941MedMay 19, 2018
    risk 0.40cvss 6.1epss 0.02

    Adobe ColdFusion Update 5 and earlier versions, ColdFusion 11 Update 13 and earlier versions have an exploitable Cross-Site Scripting vulnerability. Successful exploitation could lead to information disclosure.

  • CVE-2018-4940MedMay 19, 2018
    risk 0.40cvss 6.1epss 0.02

    Adobe ColdFusion Update 5 and earlier versions, ColdFusion 11 Update 13 and earlier versions have an exploitable Cross-Site Scripting vulnerability. Successful exploitation could lead to information disclosure.

  • CVE-2017-11285MedDec 1, 2017
    risk 0.40cvss 6.1epss 0.03

    Adobe ColdFusion has a cross-site scripting (XSS) vulnerability. This affects Update 4 and earlier versions for ColdFusion 2016, and Update 12 and earlier versions for ColdFusion 11.

  • CVE-2017-3008MedApr 27, 2017
    risk 0.40cvss 6.1epss 0.03

    Adobe ColdFusion 2016 Update 3 and earlier, ColdFusion 11 update 11 and earlier, ColdFusion 10 Update 22 and earlier have a reflected cross-site scripting vulnerability.

  • CVE-2016-4159MedJun 16, 2016
    risk 0.40cvss 6.1epss 0.02

    Cross-site scripting (XSS) vulnerability in Adobe ColdFusion 10 before Update 20, 11 before Update 9, and 2016 before Update 2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

  • CVE-2016-1113MedMay 11, 2016
    risk 0.40cvss 6.1epss 0.03

    Cross-site scripting (XSS) vulnerability in Adobe ColdFusion 10 before Update 19, 11 before Update 8, and 2016 before Update 1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

  • CVE-2016-1115MedMay 11, 2016
    risk 0.39cvss 5.9epss 0.02

    Adobe ColdFusion 10 before Update 19, 11 before Update 8, and 2016 before Update 1 mishandles wildcards in name fields of X.509 certificates, which might allow man-in-the-middle attackers to spoof servers via a crafted certificate.

  • CVE-2021-21087MedApr 15, 2021
    risk 0.38cvss 5.4epss 0.37

    Adobe Coldfusion versions 2016 (update 16 and earlier), 2018 (update 10 and earlier) and 2021.0.0.323925 are affected by an Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability. An attacker could abuse this vulnerability to execute…

  • CVE-2023-26361MedMar 23, 2023
    risk 0.37cvss 4.9epss 0.62

    Adobe ColdFusion versions 2018 Update 15 (and earlier) and 2021 Update 5 (and earlier) are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in Arbitrary file system read. Exploitation of this issue does…

  • CVE-2025-64897MedDec 10, 2025
    risk 0.36cvss 5.6epss 0.00

    ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Improper Access Control vulnerability. A low privileged attacker could leverage this vulnerability to bypass security measures and gain limited unauthorized write access potentially resulting in denial…

  • CVE-2025-30291MedApr 8, 2025
    risk 0.36cvss 5.5epss 0.00

    ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by an Information Exposure vulnerability that could result in a security feature bypass. A low privileged attacker with local access could leverage this vulnerability to gain access to sensitive information…

  • CVE-2024-34113MedJun 13, 2024
    risk 0.36cvss 5.5epss 0.00

    ColdFusion versions 2023u7, 2021u13 and earlier are affected by a Weak Cryptography for Passwords vulnerability that could result in a security feature bypass. This vulnerability arises due to the use of insufficiently strong cryptographic algorithms or flawed implementation…

  • CVE-2026-48376MedAug 11, 2026
    risk 0.35cvss 5.4epss 0.01

    is affected by an Improper Encoding or Escaping of Output vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and gain limited unauthorized write access, causing a limited…

  • CVE-2023-38206MedSep 14, 2023
    risk 0.35cvss 5.3epss 0.01

    Adobe ColdFusion versions 2018u18 (and earlier), 2021u8 (and earlier) and 2023u2 (and earlier) are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to access the administration CFM…

  • CVE-2022-38423MedOct 14, 2022
    risk 0.35cvss 4.9epss 0.45

    Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in information disclosure. Exploitation of this issue does not require…

  • CVE-2018-15963MedSep 25, 2018
    risk 0.35cvss 5.3epss 0.06

    Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have a security bypass vulnerability. Successful exploitation could lead to arbitrary folder creation.

  • CVE-2018-15962MedSep 25, 2018
    risk 0.35cvss 5.3epss 0.06

    Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have a directory listing vulnerability. Successful exploitation could lead to information disclosure.

  • CVE-2011-0737MedFeb 1, 2011
    risk 0.35cvss 5.3epss 0.03

    Adobe ColdFusion 9.0.1 CHF1 and earlier allows remote attackers to obtain sensitive information via an id=- query to a .cfm file, which reveals the installation path in an error message. NOTE: the vendor disputes the significance of this issue because the Site-wide Error…

  • CVE-2011-0736MedFeb 1, 2011
    risk 0.35cvss 5.3epss 0.03

    Adobe ColdFusion 9.0.1 CHF1 and earlier, when a web application is configured to use a DBMS, allows remote attackers to obtain potentially sensitive information about the database structure via an id=- query to a .cfm file. NOTE: the vendor disputes the significance of this…

  • CVE-2025-64898MedDec 10, 2025
    risk 0.34cvss 5.3epss 0.00

    ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Insufficiently Protected Credentials vulnerability that could result in limited unauthorized write access. An attacker could leverage this vulnerability to gain unauthorized access by exploiting…

Page 8 of 14