9.3
CVE-2026-48315
- EPSS 1.45%
- Veröffentlicht 30.06.2026 15:12:03
- Zuletzt bearbeitet 28.08.2026 00:17:47
- Erkennungen
ColdFusion | Improper Input Validation (CWE-20)
ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to inject malicious scripts into a web page, potentially gaining elevated access or control over the victim's account or session. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Adobe ≫ Coldfusion Version 2023 Update -
Adobe ≫ Coldfusion Version 2023 Update update1
Adobe ≫ Coldfusion Version 2023 Update update10
Adobe ≫ Coldfusion Version 2023 Update update11
Adobe ≫ Coldfusion Version 2023 Update update12
Adobe ≫ Coldfusion Version 2023 Update update13
Adobe ≫ Coldfusion Version 2023 Update update14
Adobe ≫ Coldfusion Version 2023 Update update15
Adobe ≫ Coldfusion Version 2023 Update update16
Adobe ≫ Coldfusion Version 2023 Update update17
Adobe ≫ Coldfusion Version 2023 Update update18
Adobe ≫ Coldfusion Version 2023 Update update19
Adobe ≫ Coldfusion Version 2023 Update update2
Adobe ≫ Coldfusion Version 2023 Update update20
Adobe ≫ Coldfusion Version 2023 Update update3
Adobe ≫ Coldfusion Version 2023 Update update4
Adobe ≫ Coldfusion Version 2023 Update update5
Adobe ≫ Coldfusion Version 2023 Update update6
Adobe ≫ Coldfusion Version 2023 Update update7
Adobe ≫ Coldfusion Version 2023 Update update8
Adobe ≫ Coldfusion Version 2023 Update update9
Adobe ≫ Coldfusion Version 2025 Update -
Adobe ≫ Coldfusion Version 2025 Update update1
Adobe ≫ Coldfusion Version 2025 Update update2
Adobe ≫ Coldfusion Version 2025 Update update3
Adobe ≫ Coldfusion Version 2025 Update update4
Adobe ≫ Coldfusion Version 2025 Update update5
Adobe ≫ Coldfusion Version 2025 Update update6
Adobe ≫ Coldfusion Version 2025 Update update7
Adobe ≫ Coldfusion Version 2025 Update update8
Adobe ≫ Coldfusion Version 2025 Update update9
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.45% | 0.707 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| Adobe | 9.3 | 2.8 | 5.8 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N
|
CWE-20 Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
https://helpx.adobe.com/security/products/coldfusion/apsb26-68.html