- EPSS 1.18%
- Published 09.09.2025 16:58:42
- Last modified 03.10.2025 12:34:44
ColdFusion versions 2025.3, 2023.15, 2021.21 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary code execution by an attacker. The victim must have ...
CVE-2025-54234
- EPSS 0.05%
- Published 18.08.2025 16:43:51
- Last modified 01.10.2025 22:15:30
ColdFusion versions 2025.1, 2023.13, 2021.19 and earlier are affected by a Server-Side Request Forgery (SSRF) vulnerability that could lead to limited file system read. A high-privilege authenticated attacker can force the application to make arbitra...
CVE-2025-49542
- EPSS 0.08%
- Published 08.07.2025 20:49:41
- Last modified 11.07.2025 16:46:52
ColdFusion versions 2025.2, 2023.14, 2021.20 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an unauthenticated attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScr...
CVE-2025-49535
- EPSS 0.1%
- Published 08.07.2025 20:49:40
- Last modified 11.07.2025 16:46:44
ColdFusion versions 2025.2, 2023.14, 2021.20 and earlier are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could result in a Security feature bypass. An attacker could exploit this vulnerability to ac...
CVE-2025-49536
- EPSS 0.08%
- Published 08.07.2025 20:49:39
- Last modified 11.07.2025 17:45:09
ColdFusion versions 2025.2, 2023.14, 2021.20 and earlier are affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures ...
CVE-2025-49539
- EPSS 0.07%
- Published 08.07.2025 20:49:38
- Last modified 11.07.2025 16:46:47
ColdFusion versions 2025.2, 2023.14, 2021.20 and earlier are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could result in a security feature bypass. A high-privileged attacker could leverage this vul...
CVE-2025-49545
- EPSS 0.04%
- Published 08.07.2025 20:49:37
- Last modified 11.07.2025 16:46:57
ColdFusion versions 2025.2, 2023.14, 2021.20 and earlier are affected by a Server-Side Request Forgery (SSRF) vulnerability that could lead to arbitrary file system read. A high-privilege authenticated attacker can force the application to make arbit...
CVE-2025-49541
- EPSS 0.04%
- Published 08.07.2025 20:49:36
- Last modified 11.07.2025 16:46:50
ColdFusion versions 2025.2, 2023.14, 2021.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a high-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScrip...
CVE-2025-49537
- EPSS 0.14%
- Published 08.07.2025 20:49:35
- Last modified 11.07.2025 16:46:46
ColdFusion versions 2025.2, 2023.14, 2021.20 and earlier are affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could lead to arbitrary code execution by a high-privileged atta...
CVE-2025-49551
- EPSS 0.06%
- Published 08.07.2025 20:49:34
- Last modified 11.07.2025 16:47:01
ColdFusion versions 2025.2, 2023.14, 2021.20 and earlier are affected by a Use of Hard-coded Credentials vulnerability that could result in privilege escalation. An attacker could leverage this vulnerability to gain unauthorized access to sensitive s...