VYPR
Vendor

ColdFusion

Products
3
CVEs
11
Across products
11
Status
Private

Products

3

Recent CVEs

11
  • CVE-2019-8073CriSep 27, 2019
    risk 0.64cvss 9.8epss 0.08

    ColdFusion 2018- update 4 and earlier and ColdFusion 2016- update 11 and earlier have a Command Injection via Vulnerable component vulnerability. Successful exploitation could lead to Arbitrary code execution in the context of the current user.

  • CVE-2026-75746CriSep 8, 2026
    risk 0.59cvss 9.1epss 0.01

    ColdFusion is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker with high privileges could exploit this vulnerability to…

  • CVE-2025-30290HigApr 8, 2025
    risk 0.58cvss 8.7epss 0.20

    ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to a security feature bypass. A high privileged attacker could exploit this vulnerability to…

  • CVE-2025-61812HigDec 10, 2025
    risk 0.55cvss 8.4epss 0.05

    ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Improper Input Validation vulnerability that could allow a high privileged attacker to gain arbitrary code execution. Exploitation of this issue does not require user interaction.

  • CVE-2026-48328HigJul 14, 2026
    risk 0.50cvss 7.7epss 0.01

    ColdFusion is affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and gain unauthorized read access. Exploitation of this issue does not…

  • CVE-2026-75998HigSep 8, 2026
    risk 0.49cvss 7.5epss 0.01

    ColdFusion is affected by an Improper Access Control vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to access sensitive files and directories outside the intended access scope. Exploitation of this issue does not require…

  • CVE-2025-43566MedMay 13, 2025
    risk 0.47cvss 6.8epss 0.55

    ColdFusion versions 2025.1, 2023.13, 2021.19 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary file system read. A high-privileged attacker could leverage this vulnerability to…

  • CVE-2024-46878MedMar 23, 2026
    risk 0.35cvss 5.4epss 0.00

    A Cross-Site Scripting (XSS) vulnerability exists in the page parameter of tiki-editpage.php in Tiki version 26.3 and earlier. This vulnerability allows attackers to execute arbitrary JavaScript code via a crafted payload, leading to potential access to sensitive information or…

  • CVE-2008-6580Apr 2, 2009
    risk 0.03cvss epss 0.02

    The Red_Reservations script for ColdFusion stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database via a direct request to (1) makered.mdb and (2) makered97.mdb.

  • CVE-2005-2481Aug 5, 2005
    risk 0.00cvss epss 0.01

    ColdFusion Fusebox 4.1.0 allows remote attackers to obtain sensitive information via an invalid fuseaction parameter, which leaks the full server path in an error message, as demonstrated using the "?" (question mark) character.

  • CVE-1999-1124Dec 31, 1999
    risk 0.00cvss epss 0.01

    HTTP Client application in ColdFusion allows remote attackers to bypass access restrictions for web pages on other ports by providing the target page to the mainframeset.cfm application, which requests the page from the server, making it look like the request is coming from the…