CVE-2025-43560
- EPSS 2.32%
- Published 13.05.2025 20:49:27
- Last modified 19.05.2025 20:35:23
ColdFusion versions 2025.1, 2023.13, 2021.19 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. A high-privileged attacker could leverage this vulne...
CVE-2025-43563
- EPSS 0.12%
- Published 13.05.2025 20:49:26
- Last modified 15.07.2025 18:40:38
ColdFusion versions 2025.1, 2023.13, 2021.19 and earlier are affected by an Improper Access Control vulnerability that could result in arbitrary file system read. A high-privileged attacker could leverage this vulnerability to access or modify sensit...
CVE-2025-43561
- EPSS 0.57%
- Published 13.05.2025 20:49:25
- Last modified 19.05.2025 20:35:36
ColdFusion versions 2025.1, 2023.13, 2021.19 and earlier are affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. A high-privileged attacker could leverage this vulnera...
CVE-2025-30292
- EPSS 0.09%
- Published 08.04.2025 20:15:27
- Last modified 14.04.2025 15:57:32
ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may ...
CVE-2025-30293
- EPSS 0.19%
- Published 08.04.2025 20:15:27
- Last modified 21.04.2025 18:39:13
ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by an Improper Input Validation vulnerability that could result in a security feature bypass. A high-privileged attacker could leverage this vulnerability to bypass security protec...
CVE-2025-30294
- EPSS 0.27%
- Published 08.04.2025 20:15:27
- Last modified 23.04.2025 16:44:53
ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by an Improper Input Validation vulnerability that could result in a security feature bypass. A high-privileged attacker could leverage this vulnerability to bypass security protec...
CVE-2025-30287
- EPSS 0.02%
- Published 08.04.2025 20:15:26
- Last modified 21.04.2025 18:37:56
ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by an Improper Authentication vulnerability that could result in arbitrary code execution in the context of the current user. A low privileged attacker with local access could leve...
CVE-2025-30288
- EPSS 0.02%
- Published 08.04.2025 20:15:26
- Last modified 21.04.2025 18:33:41
ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. A low privileged attacker with local access could leverage this vulnerability to bypass ...
CVE-2025-30289
- EPSS 0.02%
- Published 08.04.2025 20:15:26
- Last modified 24.04.2025 17:23:25
ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could lead in arbitrary code execution by an attacker. A low pri...
CVE-2025-30290
- EPSS 0.09%
- Published 08.04.2025 20:15:26
- Last modified 12.05.2025 16:40:28
ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to a security feature bypass. A high privileged attacker could ex...