<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – Adobe ColdFusion (High+Critical)</title>
  <link>https://cvedaily.com/pages/tags/coldfusion.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/coldfusion-severe.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – Adobe ColdFusion (High+Critical)</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:56 +0000</lastBuildDate>
  <item>
    <title>[High] CVE-2026-34619 – ColdFusion versions 2023.18, 2025.6 and earlier are affected by an Improper Limi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-34619</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-34619</guid>
    <pubDate>Tue, 14 Apr 2026 22:16:31 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-34619</strong></p>
  <p>ColdFusion versions 2023.18, 2025.6 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to access unauthorized files or directories outside the intended restrictions. Exploitation of this issue does not require user interaction.</p>
  <p><strong>CVSS:</strong> 7.7 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34619">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-27306 – ColdFusion versions 2023.18, 2025.6 and earlier are affected by an Improper Inpu...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-27306</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-27306</guid>
    <pubDate>Tue, 14 Apr 2026 22:16:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-27306</strong></p>
  <p>ColdFusion versions 2023.18, 2025.6 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. Attacker requires elevated privileges. Exploitation of this issue requires user interaction in that a victim must open a malicious file.</p>
  <p><strong>CVSS:</strong> 8.4 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-27306">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-27305 – ColdFusion versions 2023.18, 2025.6 and earlier are affected by an Improper Limi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-27305</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-27305</guid>
    <pubDate>Tue, 14 Apr 2026 22:16:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-27305</strong></p>
  <p>ColdFusion versions 2023.18, 2025.6 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to access sensitive files and directories outside the intended access scope. Exploitation of this issue does not require user interaction.</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-27305">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-27304 – ColdFusion versions 2023.18, 2025.6 and earlier are affected by an Improper Inpu...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-27304</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-27304</guid>
    <pubDate>Tue, 14 Apr 2026 22:16:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-27304</strong></p>
  <p>ColdFusion versions 2023.18, 2025.6 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction.</p>
  <p><strong>CVSS:</strong> 9.3 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-27304">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-27282 – ColdFusion versions 2023.18, 2025.6 and earlier are affected by an Improper Inpu...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-27282</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-27282</guid>
    <pubDate>Tue, 14 Apr 2026 22:16:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-27282</strong></p>
  <p>ColdFusion versions 2023.18, 2025.6 and earlier are affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized access. Exploitation of this issue requires user interaction.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-27282">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-61813 – ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Impr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-61813</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-61813</guid>
    <pubDate>Wed, 10 Dec 2025 00:16:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-61813</strong></p>
  <p>ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to access sensitive files on the server. Exploitation of this issue does requires user interaction and scope is changed.</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-61813">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-61812 – ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Impr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-61812</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-61812</guid>
    <pubDate>Wed, 10 Dec 2025 00:16:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-61812</strong></p>
  <p>ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Improper Input Validation vulnerability that could allow a high privileged attacker to gain arbitrary code execution. Exploitation of this issue does not require user interaction.</p>
  <p><strong>CVSS:</strong> 8.4 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-61812">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-61811 – ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Impr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-61811</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-61811</guid>
    <pubDate>Wed, 10 Dec 2025 00:16:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-61811</strong></p>
  <p>ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Improper Access Control vulnerability that could result in arbitrary code execution in the context of the current user. A high privileged attacker could leverage this vulnerability to bypass security measures and execute malicious code. Exploitation of this issue does not require user interaction and scope is changed.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-61811">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-61810 – ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by a Deser...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-61810</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-61810</guid>
    <pubDate>Wed, 10 Dec 2025 00:16:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-61810</strong></p>
  <p>ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could result in arbitrary code execution in the context of the current user. A high privileged attacker could exploit this vulnerability by providing maliciously crafted serialized data to the application. Exploitation of this issue requires user interaction and scope is…</p>
  <p><strong>CVSS:</strong> 8.4 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-61810">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-61809 – ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Impr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-61809</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-61809</guid>
    <pubDate>Wed, 10 Dec 2025 00:16:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-61809</strong></p>
  <p>ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized read and write access. Exploitation of this issue does not require user interaction and scope is unchanged.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-61809">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-61808 – ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Unre...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-61808</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-61808</guid>
    <pubDate>Wed, 10 Dec 2025 00:16:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-61808</strong></p>
  <p>ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Unrestricted Upload of File with Dangerous Type vulnerability that could lead to arbitrary code execution by a high priviledged attacker. Exploitation of this issue does not require user interaction and scope is changed.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-434</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-61808">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-54261 – ColdFusion versions 2025.3, 2023.15, 2021.21 and earlier are affected by an Impr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-54261</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-54261</guid>
    <pubDate>Tue, 09 Sep 2025 17:15:59 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-54261</strong></p>
  <p>ColdFusion versions 2025.3, 2023.15, 2021.21 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary code execution by an attacker. The victim must have optional configurations enabled. Scope is changed.</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-54261">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-49551 – ColdFusion versions 2025.2, 2023.14, 2021.20 and earlier are affected by a Use o...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-49551</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-49551</guid>
    <pubDate>Tue, 08 Jul 2025 21:15:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-49551</strong></p>
  <p>ColdFusion versions 2025.2, 2023.14, 2021.20 and earlier are affected by a Use of Hard-coded Credentials vulnerability that could result in privilege escalation. An attacker could leverage this vulnerability to gain unauthorized access to sensitive systems or data. Exploitation of this issue does not require user interaction. The vulnerable component is restricted to internal IP addresses.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-798</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-49551">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-49538 – ColdFusion versions 2025.2, 2023.14, 2021.20 and earlier are affected by an XML ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-49538</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-49538</guid>
    <pubDate>Tue, 08 Jul 2025 21:15:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-49538</strong></p>
  <p>ColdFusion versions 2025.2, 2023.14, 2021.20 and earlier are affected by an XML Injection vulnerability that could lead to arbitrary file system read. An attacker can exploit this issue by injecting crafted XML or XPath queries to access unauthorized files or lead to denial of service. Exploitation of this issue does not require user interaction, and attack must have access to shared secrets.</p>
  <p><strong>CVSS:</strong> 7.4 · <strong>CWE:</strong> CWE-91</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-49538">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-49537 – ColdFusion versions 2025.2, 2023.14, 2021.20 and earlier are affected by an Impr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-49537</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-49537</guid>
    <pubDate>Tue, 08 Jul 2025 21:15:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-49537</strong></p>
  <p>ColdFusion versions 2025.2, 2023.14, 2021.20 and earlier are affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could lead to arbitrary code execution by a high-privileged attacker. Exploitation of this issue requires user interaction and scope is changed. The vulnerable component is restricted to internal IP addresses.</p>
  <p><strong>CVSS:</strong> 7.9 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-49537">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-49536 – ColdFusion versions 2025.2, 2023.14, 2021.20 and earlier are affected by an Inco...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-49536</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-49536</guid>
    <pubDate>Tue, 08 Jul 2025 21:15:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-49536</strong></p>
  <p>ColdFusion versions 2025.2, 2023.14, 2021.20 and earlier are affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and gain unauthorized access. Exploitation of this issue does not require user interaction. The vulnerable component is restricted to internal IP add…</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-49536">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-49535 – ColdFusion versions 2025.2, 2023.14, 2021.20 and earlier are affected by an Impr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-49535</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-49535</guid>
    <pubDate>Tue, 08 Jul 2025 21:15:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-49535</strong></p>
  <p>ColdFusion versions 2025.2, 2023.14, 2021.20 and earlier are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could result in a Security feature bypass. An attacker could exploit this vulnerability to access sensitive information or denial of service by bypassing security measures. Exploitation of this issue does not require user interaction and scop…</p>
  <p><strong>CVSS:</strong> 9.3 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-49535">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-43565 – ColdFusion versions 2025.1, 2023.13, 2021.19 and earlier are affected by an Inco...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-43565</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-43565</guid>
    <pubDate>Tue, 13 May 2025 21:16:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-43565</strong></p>
  <p>ColdFusion versions 2025.1, 2023.13, 2021.19 and earlier are affected by an Incorrect Authorization vulnerability that could lead to arbitrary code execution in the context of the current user. A high-privileged attacker could leverage this vulnerability to bypass security protections and execute code. Exploitation of this issue requires user interaction and scope is changed.</p>
  <p><strong>CVSS:</strong> 8.4 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-43565">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-43564 – ColdFusion versions 2025.1, 2023.13, 2021.19 and earlier are affected by an Impr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-43564</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-43564</guid>
    <pubDate>Tue, 13 May 2025 21:16:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-43564</strong></p>
  <p>ColdFusion versions 2025.1, 2023.13, 2021.19 and earlier are affected by an Improper Access Control vulnerability that could result in arbitrary file system read. A high-privileged attacker could leverage this vulnerability to access or modify sensitive data without proper authorization. Exploitation of this issue does not require user interaction, and scope is changed</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-43564">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-43563 – ColdFusion versions 2025.1, 2023.13, 2021.19 and earlier are affected by an Impr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-43563</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-43563</guid>
    <pubDate>Tue, 13 May 2025 21:16:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-43563</strong></p>
  <p>ColdFusion versions 2025.1, 2023.13, 2021.19 and earlier are affected by an Improper Access Control vulnerability that could result in arbitrary file system read. A high-privileged attacker could leverage this vulnerability to access or modify sensitive data without proper authorization. Exploitation of this issue does not require user interaction, and scope is changed.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-43563">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-43562 – ColdFusion versions 2025.1, 2023.13, 2021.19 and earlier are affected by an Impr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-43562</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-43562</guid>
    <pubDate>Tue, 13 May 2025 21:16:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-43562</strong></p>
  <p>ColdFusion versions 2025.1, 2023.13, 2021.19 and earlier are affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could result in arbitrary code execution in the context of the current user. A high-privileged attacker could leverage this vulnerability to bypass security mechanisms and execute code. Exploitation of this issue…</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-43562">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-43561 – ColdFusion versions 2025.1, 2023.13, 2021.19 and earlier are affected by an Inco...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-43561</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-43561</guid>
    <pubDate>Tue, 13 May 2025 21:16:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-43561</strong></p>
  <p>ColdFusion versions 2025.1, 2023.13, 2021.19 and earlier are affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. A high-privileged attacker could leverage this vulnerability to bypass authentication mechanisms and execute code. Exploitation of this issue does not require user interaction and scope is changed.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-43561">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-43560 – ColdFusion versions 2025.1, 2023.13, 2021.19 and earlier are affected by an Impr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-43560</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-43560</guid>
    <pubDate>Tue, 13 May 2025 21:16:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-43560</strong></p>
  <p>ColdFusion versions 2025.1, 2023.13, 2021.19 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. A high-privileged attacker could leverage this vulnerability to bypass security mechanisms and execute code. Exploitation of this issue does not require user interaction and scope is changed.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-43560">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-43559 – ColdFusion versions 2025.1, 2023.13, 2021.19 and earlier are affected by an Impr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-43559</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-43559</guid>
    <pubDate>Tue, 13 May 2025 21:16:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-43559</strong></p>
  <p>ColdFusion versions 2025.1, 2023.13, 2021.19 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. A high-privileged attacker could leverage this vulnerability to bypass security mechanisms and execute code. Exploitation of this issue does not require user interaction and scope is changed.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-43559">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-30290 – ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by an Impr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-30290</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-30290</guid>
    <pubDate>Tue, 08 Apr 2025 20:15:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-30290</strong></p>
  <p>ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to a security feature bypass. A high privileged attacker could exploit this vulnerability to bypass security protections and gain unauthorized write and delete access. Exploitation of this issue does not require us…</p>
  <p><strong>CVSS:</strong> 8.7 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-30290">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-30289 – ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by an Impr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-30289</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-30289</guid>
    <pubDate>Tue, 08 Apr 2025 20:15:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-30289</strong></p>
  <p>ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could lead in arbitrary code execution by an attacker. A low privileged attacker with local access could leverage this vulnerability to bypass security protections and execute code. Exploitation of this issue requ…</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-30289">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-30288 – ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by an Impr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-30288</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-30288</guid>
    <pubDate>Tue, 08 Apr 2025 20:15:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-30288</strong></p>
  <p>ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. A low privileged attacker with local access could leverage this vulnerability to bypass security protections and execute code. Exploitation of this issue requires user interaction in that a victim must be coerced into performing actions…</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-30288">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-30287 – ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by an Impr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-30287</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-30287</guid>
    <pubDate>Tue, 08 Apr 2025 20:15:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-30287</strong></p>
  <p>ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by an Improper Authentication vulnerability that could result in arbitrary code execution in the context of the current user. A low privileged attacker with local access could leverage this vulnerability to bypass security protections and execute code. Exploitation of this issue requires user interaction in that a victim must b…</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-30287">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-30286 – ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by an Impr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-30286</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-30286</guid>
    <pubDate>Tue, 08 Apr 2025 20:15:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-30286</strong></p>
  <p>ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could lead in arbitrary code execution by an attacker. A high-privileged attacker could leverage this vulnerability to bypass security protections and execute code. Exploitation of this issue requires user interac…</p>
  <p><strong>CVSS:</strong> 8.4 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-30286">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-30285 – ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by a Deser...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-30285</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-30285</guid>
    <pubDate>Tue, 08 Apr 2025 20:15:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-30285</strong></p>
  <p>ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could result in arbitrary code execution in the context of the current user. A high-privileged attacker could leverage this vulnerability to bypass security protections and execute code. Exploitation of this issue requires user interaction and scope is changed.</p>
  <p><strong>CVSS:</strong> 8.4 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-30285">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-30284 – ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by a Deser...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-30284</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-30284</guid>
    <pubDate>Tue, 08 Apr 2025 20:15:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-30284</strong></p>
  <p>ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could result in arbitrary code execution in the context of the current user. A high-privileged attacker could leverage this vulnerability to bypass security protections and execute code. Exploitation of this issue requires user interaction and scope is changed.</p>
  <p><strong>CVSS:</strong> 8.4 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-30284">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-30282 – ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by an Impr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-30282</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-30282</guid>
    <pubDate>Tue, 08 Apr 2025 20:15:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-30282</strong></p>
  <p>ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by an Improper Authentication vulnerability that could result in arbitrary code execution in the context of the current user. A high-privileged attacker could leverage this vulnerability to bypass authentication mechanisms and execute code. Exploitation of this issue does not require user interaction and scope is changed.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-30282">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-30281 – ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by an Impr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-30281</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-30281</guid>
    <pubDate>Tue, 08 Apr 2025 20:15:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-30281</strong></p>
  <p>ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by an Improper Access Control vulnerability that could result in arbitrary code execution. A high-privileged attacker could leverage this vulnerability to access or modify sensitive data without proper authorization. Exploitation of this issue does not require user interaction, and scope is changed.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-30281">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-24447 – ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by a Deser...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-24447</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-24447</guid>
    <pubDate>Tue, 08 Apr 2025 20:15:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-24447</strong></p>
  <p>ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could result in arbitrary code execution in the context of the current user resulting in a High impact to Confidentiality and Integrity. Exploitation of this issue does not require user interaction.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-24447">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-24446 – ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by an Impr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-24446</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-24446</guid>
    <pubDate>Tue, 08 Apr 2025 20:15:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-24446</strong></p>
  <p>ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution. Exploitation of this issue does not require user interaction, but admin panel privileges are required, and scope is changed.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-24446">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-53961 – ColdFusion versions 2023.11, 2021.17 and earlier are affected by an Improper Lim...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-53961</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-53961</guid>
    <pubDate>Mon, 23 Dec 2024 21:15:05 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-53961</strong></p>
  <p>ColdFusion versions 2023.11, 2021.17 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to access files or directories that are outside of the restricted directory set by the application. This could lead to the disclosure of sensitive…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-53961">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-45113 – ColdFusion versions 2023.6, 2021.12 and earlier are affected by an Improper Auth...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-45113</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-45113</guid>
    <pubDate>Fri, 13 Sep 2024 10:15:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-45113</strong></p>
  <p>ColdFusion versions 2023.6, 2021.12 and earlier are affected by an Improper Authentication vulnerability that could result in privilege escalation. An attacker could exploit this vulnerability to gain unauthorized access and affect the integrity of the application. Exploitation of this issue does not require user interaction.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-45113">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-41874 – ColdFusion versions 2023.9, 2021.15 and earlier are affected by a Deserializatio...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-41874</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-41874</guid>
    <pubDate>Fri, 13 Sep 2024 10:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-41874</strong></p>
  <p>ColdFusion versions 2023.9, 2021.15 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability by providing crafted input to the application, which when deserialized, leads to execution of malicious code. Exploitation of this issue does not require user…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-41874">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-34112 – ColdFusion versions 2023u7, 2021u13 and earlier are affected by an Improper Acce...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-34112</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-34112</guid>
    <pubDate>Thu, 13 Jun 2024 12:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-34112</strong></p>
  <p>ColdFusion versions 2023u7, 2021u13 and earlier are affected by an Improper Access Control vulnerability that could result in arbitrary file system read. An attacker could exploit this vulnerability to gain unauthorized access to sensitive files or data. Exploitation of this issue does not require user interaction.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-34112">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-20767 – ColdFusion versions 2023.6, 2021.12 and earlier are affected by an Improper Acce...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-20767</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-20767</guid>
    <pubDate>Mon, 18 Mar 2024 12:15:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-20767</strong></p>
  <p>ColdFusion versions 2023.6, 2021.12 and earlier are affected by an Improper Access Control vulnerability that could result in arbitrary file system read. An attacker could leverage this vulnerability to access or modify restricted files. Exploitation of this issue does not require user interaction. Exploitation of this issue requires the admin panel be exposed to the internet.</p>
  <p><strong>CVSS:</strong> 7.4 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-20767">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2023-44353 – Adobe ColdFusion versions 2023.5 (and earlier) and 2021.11 (and earlier) are aff...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-44353</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-44353</guid>
    <pubDate>Fri, 17 Nov 2023 14:15:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2023-44353</strong></p>
  <p>Adobe ColdFusion versions 2023.5 (and earlier) and 2021.11 (and earlier) are affected by an Deserialization of Untrusted Data vulnerability that could result in Arbitrary code execution. Exploitation of this issue does not require user interaction.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-44353">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2023-44351 – Adobe ColdFusion versions 2023.5 (and earlier) and 2021.11 (and earlier) are aff...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-44351</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-44351</guid>
    <pubDate>Fri, 17 Nov 2023 14:15:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2023-44351</strong></p>
  <p>Adobe ColdFusion versions 2023.5 (and earlier) and 2021.11 (and earlier) are affected by an Deserialization of Untrusted Data vulnerability that could result in Arbitrary code execution. Exploitation of this issue does not require user interaction.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-44351">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2023-44350 – Adobe ColdFusion versions 2023.5 (and earlier) and 2021.11 (and earlier) are aff...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-44350</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-44350</guid>
    <pubDate>Fri, 17 Nov 2023 14:15:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2023-44350</strong></p>
  <p>Adobe ColdFusion versions 2023.5 (and earlier) and 2021.11 (and earlier) are affected by an Deserialization of Untrusted Data vulnerability that could result in Arbitrary code execution. Exploitation of this issue does not require user interaction.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-44350">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-26347 – Adobe ColdFusion versions 2023.5 (and earlier) and 2021.11 (and earlier) are aff...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-26347</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-26347</guid>
    <pubDate>Fri, 17 Nov 2023 14:15:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-26347</strong></p>
  <p>Adobe ColdFusion versions 2023.5 (and earlier) and 2021.11 (and earlier) are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. An unauthenticated attacker could leverage this vulnerability to access the administration CFM and CFC endpoints. Exploitation of this issue does not require user interaction.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-26347">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-38205 – Adobe ColdFusion versions 2018u18 (and earlier), 2021u8 (and earlier) and 2023u2...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-38205</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-38205</guid>
    <pubDate>Thu, 14 Sep 2023 08:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-38205</strong></p>
  <p>Adobe ColdFusion versions 2018u18 (and earlier), 2021u8 (and earlier) and 2023u2 (and earlier) are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to access the administration CFM and CFC endpoints. Exploitation of this issue does not require user interaction.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-38205">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2023-38204 – Adobe ColdFusion versions 2018u18 (and earlier), 2021u8 (and earlier) and 2023u2...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-38204</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-38204</guid>
    <pubDate>Thu, 14 Sep 2023 08:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2023-38204</strong></p>
  <p>Adobe ColdFusion versions 2018u18 (and earlier), 2021u8 (and earlier) and 2023u2 (and earlier) are affected by a Deserialization of Untrusted Data vulnerability that could result in Arbitrary code execution. Exploitation of this issue does not require user interaction.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-38204">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-40699 – ColdFusion version 2021 update 1 (and earlier) and versions 2018.10 (and earlier...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-40699</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-40699</guid>
    <pubDate>Thu, 07 Sep 2023 13:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-40699</strong></p>
  <p>ColdFusion version 2021 update 1 (and earlier) and versions 2018.10 (and earlier) are impacted by an improper access control vulnerability when checking permissions in the CFIDE path. An authenticated attacker could leverage this vulnerability to access and manipulate arbitrary data on the environment.</p>
  <p><strong>CVSS:</strong> 7.4 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-40699">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-40698 – ColdFusion version 2021 update 1 (and earlier) and versions 2018.10 (and earlier...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-40698</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-40698</guid>
    <pubDate>Thu, 07 Sep 2023 13:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-40698</strong></p>
  <p>ColdFusion version 2021 update 1 (and earlier) and versions 2018.10 (and earlier) are impacted by an Use of Inherently Dangerous Function vulnerability that can lead to a security feature bypass  . An authenticated attacker could leverage this vulnerability to access and manipulate arbitrary data on the environment.</p>
  <p><strong>CVSS:</strong> 7.4 · <strong>CWE:</strong> CWE-242</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-40698">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2023-38203 – Adobe ColdFusion versions 2018u17 (and earlier), 2021u7 (and earlier) and 2023u1...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-38203</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-38203</guid>
    <pubDate>Thu, 20 Jul 2023 16:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2023-38203</strong></p>
  <p>Adobe ColdFusion versions 2018u17 (and earlier), 2021u7 (and earlier) and 2023u1 (and earlier) are affected by a Deserialization of Untrusted Data vulnerability that could result in Arbitrary code execution. Exploitation of this issue does not require user interaction.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-38203">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-29301 – Adobe ColdFusion versions 2018u16 (and earlier), 2021u6 (and earlier) and 2023.0...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-29301</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-29301</guid>
    <pubDate>Wed, 12 Jul 2023 16:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-29301</strong></p>
  <p>Adobe ColdFusion versions 2018u16 (and earlier), 2021u6 (and earlier) and 2023.0.0.330468 (and earlier) are affected by an Improper Restriction of Excessive Authentication Attempts vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to impact the confidentiality of the user. Exploitation of this issue does not require user interaction.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-307</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-29301">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2023-29300 – Adobe ColdFusion versions 2018u16 (and earlier), 2021u6 (and earlier) and 2023.0...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-29300</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-29300</guid>
    <pubDate>Wed, 12 Jul 2023 16:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2023-29300</strong></p>
  <p>Adobe ColdFusion versions 2018u16 (and earlier), 2021u6 (and earlier) and 2023.0.0.330468 (and earlier) are affected by a Deserialization of Untrusted Data vulnerability that could result in Arbitrary code execution. Exploitation of this issue does not require user interaction.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-29300">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-29298 – Adobe ColdFusion versions 2018u16 (and earlier), 2021u6 (and earlier) and 2023.0...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-29298</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-29298</guid>
    <pubDate>Wed, 12 Jul 2023 16:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-29298</strong></p>
  <p>Adobe ColdFusion versions 2018u16 (and earlier), 2021u6 (and earlier) and 2023.0.0.330468 (and earlier) are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to access the administration CFM and CFC endpoints. Exploitation of this issue does not require user interaction.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-29298">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-26360 – Adobe ColdFusion versions 2018 Update 15 (and earlier) and 2021 Update 5 (and ea...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-26360</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-26360</guid>
    <pubDate>Thu, 23 Mar 2023 20:15:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-26360</strong></p>
  <p>Adobe ColdFusion versions 2018 Update 15 (and earlier) and 2021 Update 5 (and earlier) are affected by an Improper Access Control vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction.</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-26360">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2023-26359 – Adobe ColdFusion versions 2018 Update 15 (and earlier) and 2021 Update 5 (and ea...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-26359</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-26359</guid>
    <pubDate>Thu, 23 Mar 2023 20:15:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2023-26359</strong></p>
  <p>Adobe ColdFusion versions 2018 Update 15 (and earlier) and 2021 Update 5 (and earlier) are affected by a Deserialization of Untrusted Data vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-26359">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-42341 – Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-42341</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-42341</guid>
    <pubDate>Fri, 14 Oct 2022 20:15:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-42341</strong></p>
  <p>Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could result in arbitrary file system read. Exploitation of this issue does not require user interaction.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-42341">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-42340 – Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-42340</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-42340</guid>
    <pubDate>Fri, 14 Oct 2022 20:15:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-42340</strong></p>
  <p>Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are affected by an Improper Input Validation vulnerability that could result in arbitrary file system read. Exploitation of this issue does not require user interaction.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-42340">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-38424 – Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-38424</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-38424</guid>
    <pubDate>Fri, 14 Oct 2022 20:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-38424</strong></p>
  <p>Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in arbitrary file system write. Exploitation of this issue does not require user interaction, but does require administrator privileges.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-38424">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-38422 – Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-38422</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-38422</guid>
    <pubDate>Fri, 14 Oct 2022 20:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-38422</strong></p>
  <p>Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in information disclosure. Exploitation of this issue does not require user interaction.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-38422">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-38421 – Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-38421</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-38421</guid>
    <pubDate>Fri, 14 Oct 2022 20:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-38421</strong></p>
  <p>Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction, but does require administrator privileges.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-38421">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-38420 – Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-38420</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-38420</guid>
    <pubDate>Fri, 14 Oct 2022 20:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-38420</strong></p>
  <p>Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are affected by a Use of Hard-coded Credentials vulnerability that could result in application denial-of-service by gaining access to start/stop arbitrary services. Exploitation of this issue does not require user interaction.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-798</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-38420">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-38419 – Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-38419</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-38419</guid>
    <pubDate>Fri, 14 Oct 2022 20:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-38419</strong></p>
  <p>Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could result in arbitrary file system read. Exploitation of this issue does not require user interaction.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-38419">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2022-38418 – Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-38418</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-38418</guid>
    <pubDate>Fri, 14 Oct 2022 20:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2022-38418</strong></p>
  <p>Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-38418">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2022-35712 – Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-35712</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-35712</guid>
    <pubDate>Fri, 14 Oct 2022 20:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2022-35712</strong></p>
  <p>Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction, the vulnerability is triggered when a crafted network packet is sent to the server.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-122</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-35712">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2022-35711 – Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-35711</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-35711</guid>
    <pubDate>Fri, 14 Oct 2022 20:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2022-35711</strong></p>
  <p>Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction, the vulnerability is triggered when a crafted network packet is sent to the server.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-122</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-35711">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2022-35710 – Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-35710</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-35710</guid>
    <pubDate>Fri, 14 Oct 2022 20:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2022-35710</strong></p>
  <p>Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction, the vulnerability is triggered when a crafted network packet is sent to the server.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-121</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-35710">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2022-35690 – Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-35690</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-35690</guid>
    <pubDate>Fri, 14 Oct 2022 20:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2022-35690</strong></p>
  <p>Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction, the vulnerability is triggered when a crafted network packet is sent to the server.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-121</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-35690">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-10145 – The Adobe ColdFusion installer fails to set a secure access-control list (ACL) o...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-10145</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-10145</guid>
    <pubDate>Thu, 27 May 2021 21:15:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-10145</strong></p>
  <p>The Adobe ColdFusion installer fails to set a secure access-control list (ACL) on the default installation directory, such as C:\ColdFusion2021\. By default, unprivileged users can create files in this directory structure, which creates a privilege-escalation vulnerability.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-10145">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-9673 – Adobe ColdFusion 2016 update 15 and earlier versions, and ColdFusion 2018 update...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-9673</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-9673</guid>
    <pubDate>Fri, 17 Jul 2020 00:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-9673</strong></p>
  <p>Adobe ColdFusion 2016 update 15 and earlier versions, and ColdFusion 2018 update 9 and earlier versions have a dll search-order hijacking vulnerability. Successful exploitation could lead to privilege escalation.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-426</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-9673">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-9672 – Adobe ColdFusion 2016 update 15 and earlier versions, and ColdFusion 2018 update...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-9672</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-9672</guid>
    <pubDate>Fri, 17 Jul 2020 00:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-9672</strong></p>
  <p>Adobe ColdFusion 2016 update 15 and earlier versions, and ColdFusion 2018 update 9 and earlier versions have a dll search-order hijacking vulnerability. Successful exploitation could lead to privilege escalation.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-426</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-9672">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-3768 – ColdFusion versions ColdFusion 2016, and ColdFusion 2018 have a dll search-order...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-3768</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-3768</guid>
    <pubDate>Fri, 26 Jun 2020 21:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-3768</strong></p>
  <p>ColdFusion versions ColdFusion 2016, and ColdFusion 2018 have a dll search-order hijacking vulnerability. Successful exploitation could lead to privilege escalation.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-426</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-3768">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2020-3794 – ColdFusion versions ColdFusion 2016, and ColdFusion 2018 have a file inclusion v...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-3794</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-3794</guid>
    <pubDate>Wed, 25 Mar 2020 20:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2020-3794</strong></p>
  <p>ColdFusion versions ColdFusion 2016, and ColdFusion 2018 have a file inclusion vulnerability. Successful exploitation could lead to arbitrary code execution of files located in the webroot or its subdirectory.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-829</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-3794">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-3761 – ColdFusion versions ColdFusion 2016, and ColdFusion 2018 have a remote file read...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-3761</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-3761</guid>
    <pubDate>Wed, 25 Mar 2020 20:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-3761</strong></p>
  <p>ColdFusion versions ColdFusion 2016, and ColdFusion 2018 have a remote file read vulnerability. Successful exploitation could lead to arbitrary file read from the coldfusion install directory.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-3761">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2019-8256 – ColdFusion versions Update 6 and earlier have an insecure inherited permissions ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-8256</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-8256</guid>
    <pubDate>Thu, 19 Dec 2019 20:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2019-8256</strong></p>
  <p>ColdFusion versions Update 6 and earlier have an insecure inherited permissions of default installation directory vulnerability. Successful exploitation could lead to privilege escalation.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-732</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-8256">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2019-8074 – ColdFusion 2018- update 4 and earlier and ColdFusion 2016- update 11 and earlier...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-8074</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-8074</guid>
    <pubDate>Fri, 27 Sep 2019 16:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2019-8074</strong></p>
  <p>ColdFusion 2018- update 4 and earlier and ColdFusion 2016- update 11 and earlier have a Path Traversal vulnerability. Successful exploitation could lead to Access Control Bypass in the context of the current user.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-8074">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2019-8073 – ColdFusion 2018- update 4 and earlier and ColdFusion 2016- update 11 and earlier...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-8073</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-8073</guid>
    <pubDate>Fri, 27 Sep 2019 16:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2019-8073</strong></p>
  <p>ColdFusion 2018- update 4 and earlier and ColdFusion 2016- update 11 and earlier have a Command Injection via Vulnerable component vulnerability. Successful exploitation could lead to Arbitrary code execution in the context of the current user.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-8073">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-8072 – ColdFusion 2018- update 4 and earlier and ColdFusion 2016- update 11 and earlier...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-8072</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-8072</guid>
    <pubDate>Fri, 27 Sep 2019 16:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-8072</strong></p>
  <p>ColdFusion 2018- update 4 and earlier and ColdFusion 2016- update 11 and earlier have a Security bypass vulnerability. Successful exploitation could lead to Information Disclosure in the context of the current user.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-8072">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-15862 – An issue was discovered in CKFinder through 2.6.2.1. Improper checks of file nam...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-15862</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-15862</guid>
    <pubDate>Thu, 26 Sep 2019 21:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-15862</strong></p>
  <p>An issue was discovered in CKFinder through 2.6.2.1. Improper checks of file names allows remote attackers to upload files without any extension (even if the application was configured to accept files only with a defined set of extensions). This affects CKFinder for ASP, CKFinder for ASP.NET, CKFinder for ColdFusion, and CKFinder for PHP.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-434</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-15862">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2019-7840 – ColdFusion versions Update 3 and earlier, Update 10 and earlier, and Update 18 a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-7840</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-7840</guid>
    <pubDate>Wed, 12 Jun 2019 16:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2019-7840</strong></p>
  <p>ColdFusion versions Update 3 and earlier, Update 10 and earlier, and Update 18 and earlier have a deserialization of untrusted data vulnerability. Successful exploitation could lead to arbitrary code execution.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-7840">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2019-7839 – ColdFusion versions Update 3 and earlier, Update 10 and earlier, and Update 18 a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-7839</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-7839</guid>
    <pubDate>Wed, 12 Jun 2019 16:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2019-7839</strong></p>
  <p>ColdFusion versions Update 3 and earlier, Update 10 and earlier, and Update 18 and earlier have a command injection vulnerability. Successful exploitation could lead to arbitrary code execution.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-7839">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2019-7838 – ColdFusion versions Update 3 and earlier, Update 10 and earlier, and Update 18 a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-7838</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-7838</guid>
    <pubDate>Wed, 12 Jun 2019 16:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2019-7838</strong></p>
  <p>ColdFusion versions Update 3 and earlier, Update 10 and earlier, and Update 18 and earlier have a file extension blacklist bypass vulnerability. Successful exploitation could lead to arbitrary code execution.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-434</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-7838">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2019-7091 – ColdFusion versions Update 1 and earlier, Update 7 and earlier, and Update 15 an...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-7091</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-7091</guid>
    <pubDate>Fri, 24 May 2019 19:29:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2019-7091</strong></p>
  <p>ColdFusion versions Update 1 and earlier, Update 7 and earlier, and Update 15 and earlier have a deserialization of untrusted data vulnerability. Successful exploitation could lead to arbitrary code execution.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-7091">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2019-7816 – ColdFusion versions Update 2 and earlier, Update 9 and earlier, and Update 17 an...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-7816</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-7816</guid>
    <pubDate>Fri, 24 May 2019 18:29:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2019-7816</strong></p>
  <p>ColdFusion versions Update 2 and earlier, Update 9 and earlier, and Update 17 and earlier have a file upload restriction bypass vulnerability. Successful exploitation could lead to arbitrary code execution.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-434</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-7816">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2018-15965 – Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlie...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-15965</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-15965</guid>
    <pubDate>Tue, 25 Sep 2018 13:29:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2018-15965</strong></p>
  <p>Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have a deserialization of untrusted data vulnerability. Successful exploitation could lead to arbitrary code execution.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-15965">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-15964 – Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlie...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-15964</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-15964</guid>
    <pubDate>Tue, 25 Sep 2018 13:29:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-15964</strong></p>
  <p>Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have a use of a component with a known vulnerability vulnerability. Successful exploitation could lead to information disclosure.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-15964">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2018-15961 – Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlie...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-15961</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-15961</guid>
    <pubDate>Tue, 25 Sep 2018 13:29:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2018-15961</strong></p>
  <p>Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have an unrestricted file upload vulnerability. Successful exploitation could lead to arbitrary code execution.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-434</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-15961">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-15960 – Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlie...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-15960</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-15960</guid>
    <pubDate>Tue, 25 Sep 2018 13:29:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-15960</strong></p>
  <p>Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have a use of a component with a known vulnerability vulnerability. Successful exploitation could lead to arbitrary file overwrite.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-15960">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2018-15959 – Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlie...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-15959</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-15959</guid>
    <pubDate>Tue, 25 Sep 2018 13:29:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2018-15959</strong></p>
  <p>Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have a deserialization of untrusted data vulnerability. Successful exploitation could lead to arbitrary code execution.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-15959">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2018-15958 – Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlie...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-15958</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-15958</guid>
    <pubDate>Tue, 25 Sep 2018 13:29:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2018-15958</strong></p>
  <p>Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have a deserialization of untrusted data vulnerability. Successful exploitation could lead to arbitrary code execution.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-15958">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2018-15957 – Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlie...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-15957</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-15957</guid>
    <pubDate>Tue, 25 Sep 2018 13:29:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2018-15957</strong></p>
  <p>Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have a deserialization of untrusted data vulnerability. Successful exploitation could lead to arbitrary code execution.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-15957">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-4942 – Adobe ColdFusion Update 5 and earlier versions, ColdFusion 11 Update 13 and earl...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-4942</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-4942</guid>
    <pubDate>Sat, 19 May 2018 17:29:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-4942</strong></p>
  <p>Adobe ColdFusion Update 5 and earlier versions, ColdFusion 11 Update 13 and earlier versions have an exploitable Unsafe XML External Entity Processing vulnerability. Successful exploitation could lead to information disclosure.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-4942">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2018-4939 – Adobe ColdFusion Update 5 and earlier versions, ColdFusion 11 Update 13 and earl...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-4939</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-4939</guid>
    <pubDate>Sat, 19 May 2018 17:29:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2018-4939</strong></p>
  <p>Adobe ColdFusion Update 5 and earlier versions, ColdFusion 11 Update 13 and earlier versions have an exploitable Deserialization of Untrusted Data vulnerability. Successful exploitation could lead to arbitrary code execution.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-4939">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-4938 – Adobe ColdFusion Update 5 and earlier versions, ColdFusion 11 Update 13 and earl...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-4938</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-4938</guid>
    <pubDate>Sat, 19 May 2018 17:29:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-4938</strong></p>
  <p>Adobe ColdFusion Update 5 and earlier versions, ColdFusion 11 Update 13 and earlier versions have an exploitable Insecure Library Loading vulnerability. Successful exploitation could lead to local privilege escalation.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-427</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-4938">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-7486 – Blue River Mura CMS before v7.0.7029 supports inline function calls with an [m] ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-7486</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-7486</guid>
    <pubDate>Mon, 26 Feb 2018 14:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-7486</strong></p>
  <p>Blue River Mura CMS before v7.0.7029 supports inline function calls with an [m] tag and [/m] end tag, without proper restrictions on file types or pathnames, which allows remote attackers to execute arbitrary code via an [m]$.dspinclude("../pathname/executable.jpeg")[/m] approach, where executable.jpeg contains ColdFusion Markup Language code. This can be exploited in conjunction with a CKFinder…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-7486">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2017-11286 – Adobe ColdFusion has an XML external entity (XXE) injection vulnerability. This ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-11286</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-11286</guid>
    <pubDate>Fri, 01 Dec 2017 08:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2017-11286</strong></p>
  <p>Adobe ColdFusion has an XML external entity (XXE) injection vulnerability. This affects Update 4 and earlier versions for ColdFusion 2016, and Update 12 and earlier versions for ColdFusion 11.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-11286">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2017-11284 – Adobe ColdFusion has an Untrusted Data Deserialization vulnerability. This affec...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-11284</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-11284</guid>
    <pubDate>Fri, 01 Dec 2017 08:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2017-11284</strong></p>
  <p>Adobe ColdFusion has an Untrusted Data Deserialization vulnerability. This affects Update 4 and earlier versions for ColdFusion 2016, and Update 12 and earlier versions for ColdFusion 11.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-11284">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2017-11283 – Adobe ColdFusion has an Untrusted Data Deserialization vulnerability. This affec...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-11283</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-11283</guid>
    <pubDate>Fri, 01 Dec 2017 08:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2017-11283</strong></p>
  <p>Adobe ColdFusion has an Untrusted Data Deserialization vulnerability. This affects Update 4 and earlier versions for ColdFusion 2016, and Update 12 and earlier versions for ColdFusion 11.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-11283">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2017-3066 – Adobe ColdFusion 2016 Update 3 and earlier, ColdFusion 11 update 11 and earlier,...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-3066</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-3066</guid>
    <pubDate>Thu, 27 Apr 2017 14:59:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2017-3066</strong></p>
  <p>Adobe ColdFusion 2016 Update 3 and earlier, ColdFusion 11 update 11 and earlier, ColdFusion 10 Update 22 and earlier have a Java deserialization vulnerability in the Apache BlazeDS library. Successful exploitation could lead to arbitrary code execution.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-3066">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2016-7887 – Adobe ColdFusion Builder versions 2016 update 2 and earlier, 3.0.3 and earlier h...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-7887</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-7887</guid>
    <pubDate>Thu, 15 Dec 2016 06:59:51 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2016-7887</strong></p>
  <p>Adobe ColdFusion Builder versions 2016 update 2 and earlier, 3.0.3 and earlier have an important vulnerability that could lead to information disclosure.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-7887">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2016-4264 – The Office Open XML (OOXML) feature in Adobe ColdFusion 10 before Update 21 and ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-4264</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-4264</guid>
    <pubDate>Thu, 01 Sep 2016 23:59:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2016-4264</strong></p>
  <p>The Office Open XML (OOXML) feature in Adobe ColdFusion 10 before Update 21 and 11 before Update 10 allows remote attackers to read arbitrary files or send TCP requests to intranet servers via a crafted OOXML spreadsheet containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-4264">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2016-1114 – Adobe ColdFusion 10 before Update 19, 11 before Update 8, and 2016 before Update...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-1114</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-1114</guid>
    <pubDate>Wed, 11 May 2016 01:59:43 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2016-1114</strong></p>
  <p>Adobe ColdFusion 10 before Update 19, 11 before Update 8, and 2016 before Update 1 allows remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the Apache Commons Collections library.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-1114">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
