- EPSS 1.18%
- Veröffentlicht 09.09.2025 16:58:42
- Zuletzt bearbeitet 03.10.2025 12:34:44
ColdFusion versions 2025.3, 2023.15, 2021.21 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary code execution by an attacker. The victim must have ...
CVE-2025-54234
- EPSS 0.05%
- Veröffentlicht 18.08.2025 16:43:51
- Zuletzt bearbeitet 01.10.2025 22:15:30
ColdFusion versions 2025.1, 2023.13, 2021.19 and earlier are affected by a Server-Side Request Forgery (SSRF) vulnerability that could lead to limited file system read. A high-privilege authenticated attacker can force the application to make arbitra...
CVE-2025-49542
- EPSS 0.08%
- Veröffentlicht 08.07.2025 20:49:41
- Zuletzt bearbeitet 11.07.2025 16:46:52
ColdFusion versions 2025.2, 2023.14, 2021.20 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an unauthenticated attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScr...
CVE-2025-49535
- EPSS 0.1%
- Veröffentlicht 08.07.2025 20:49:40
- Zuletzt bearbeitet 11.07.2025 16:46:44
ColdFusion versions 2025.2, 2023.14, 2021.20 and earlier are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could result in a Security feature bypass. An attacker could exploit this vulnerability to ac...
CVE-2025-49536
- EPSS 0.08%
- Veröffentlicht 08.07.2025 20:49:39
- Zuletzt bearbeitet 11.07.2025 17:45:09
ColdFusion versions 2025.2, 2023.14, 2021.20 and earlier are affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures ...
CVE-2025-49539
- EPSS 0.07%
- Veröffentlicht 08.07.2025 20:49:38
- Zuletzt bearbeitet 11.07.2025 16:46:47
ColdFusion versions 2025.2, 2023.14, 2021.20 and earlier are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could result in a security feature bypass. A high-privileged attacker could leverage this vul...
CVE-2025-49545
- EPSS 0.04%
- Veröffentlicht 08.07.2025 20:49:37
- Zuletzt bearbeitet 11.07.2025 16:46:57
ColdFusion versions 2025.2, 2023.14, 2021.20 and earlier are affected by a Server-Side Request Forgery (SSRF) vulnerability that could lead to arbitrary file system read. A high-privilege authenticated attacker can force the application to make arbit...
CVE-2025-49541
- EPSS 0.04%
- Veröffentlicht 08.07.2025 20:49:36
- Zuletzt bearbeitet 11.07.2025 16:46:50
ColdFusion versions 2025.2, 2023.14, 2021.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a high-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScrip...
CVE-2025-49537
- EPSS 0.14%
- Veröffentlicht 08.07.2025 20:49:35
- Zuletzt bearbeitet 11.07.2025 16:46:46
ColdFusion versions 2025.2, 2023.14, 2021.20 and earlier are affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could lead to arbitrary code execution by a high-privileged atta...
CVE-2025-49551
- EPSS 0.06%
- Veröffentlicht 08.07.2025 20:49:34
- Zuletzt bearbeitet 11.07.2025 16:47:01
ColdFusion versions 2025.2, 2023.14, 2021.20 and earlier are affected by a Use of Hard-coded Credentials vulnerability that could result in privilege escalation. An attacker could leverage this vulnerability to gain unauthorized access to sensitive s...