<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – Adobe ColdFusion</title>
  <link>https://cvedaily.com/pages/tags/coldfusion.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/coldfusion.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – Adobe ColdFusion</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:56 +0000</lastBuildDate>
  <item>
    <title>[High] CVE-2026-34619 – ColdFusion versions 2023.18, 2025.6 and earlier are affected by an Improper Limi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-34619</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-34619</guid>
    <pubDate>Tue, 14 Apr 2026 22:16:31 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-34619</strong></p>
  <p>ColdFusion versions 2023.18, 2025.6 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to access unauthorized files or directories outside the intended restrictions. Exploitation of this issue does not require user interaction.</p>
  <p><strong>CVSS:</strong> 7.7 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34619">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2026-27308 – ColdFusion versions 2023.18, 2025.6 and earlier are affected by an Uncontrolled ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-27308</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-27308</guid>
    <pubDate>Tue, 14 Apr 2026 22:16:30 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2026-27308</strong></p>
  <p>ColdFusion versions 2023.18, 2025.6 and earlier are affected by an Uncontrolled Resource Consumption vulnerability that could lead to application denial-of-service. A high-privileged attacker could exploit this vulnerability and exhaust system resources, reducing application speed. Exploitation of this issue does not require user interaction.</p>
  <p><strong>CVSS:</strong> 2.4 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-27308">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2026-27307 – ColdFusion versions 2023.18, 2025.6 and earlier are affected by an Uncontrolled ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-27307</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-27307</guid>
    <pubDate>Tue, 14 Apr 2026 22:16:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2026-27307</strong></p>
  <p>ColdFusion versions 2023.18, 2025.6 and earlier are affected by an Uncontrolled Resource Consumption vulnerability that could lead to application denial-of-service. A high-privileged attacker could exploit this vulnerability and exhaust system resources, reducing application speed. Exploitation of this issue does not require user interaction.</p>
  <p><strong>CVSS:</strong> 2.4 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-27307">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-27306 – ColdFusion versions 2023.18, 2025.6 and earlier are affected by an Improper Inpu...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-27306</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-27306</guid>
    <pubDate>Tue, 14 Apr 2026 22:16:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-27306</strong></p>
  <p>ColdFusion versions 2023.18, 2025.6 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. Attacker requires elevated privileges. Exploitation of this issue requires user interaction in that a victim must open a malicious file.</p>
  <p><strong>CVSS:</strong> 8.4 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-27306">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-27305 – ColdFusion versions 2023.18, 2025.6 and earlier are affected by an Improper Limi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-27305</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-27305</guid>
    <pubDate>Tue, 14 Apr 2026 22:16:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-27305</strong></p>
  <p>ColdFusion versions 2023.18, 2025.6 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to access sensitive files and directories outside the intended access scope. Exploitation of this issue does not require user interaction.</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-27305">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-27304 – ColdFusion versions 2023.18, 2025.6 and earlier are affected by an Improper Inpu...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-27304</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-27304</guid>
    <pubDate>Tue, 14 Apr 2026 22:16:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-27304</strong></p>
  <p>ColdFusion versions 2023.18, 2025.6 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction.</p>
  <p><strong>CVSS:</strong> 9.3 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-27304">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-27282 – ColdFusion versions 2023.18, 2025.6 and earlier are affected by an Improper Inpu...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-27282</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-27282</guid>
    <pubDate>Tue, 14 Apr 2026 22:16:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-27282</strong></p>
  <p>ColdFusion versions 2023.18, 2025.6 and earlier are affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized access. Exploitation of this issue requires user interaction.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-27282">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-64898 – ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Insu...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-64898</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-64898</guid>
    <pubDate>Wed, 10 Dec 2025 00:16:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-64898</strong></p>
  <p>ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Insufficiently Protected Credentials vulnerability that could result in limited unauthorized write access. An attacker could leverage this vulnerability to gain unauthorized access by exploiting improperly stored or transmitted credentials. Exploitation of this issue does not require user interaction.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-522</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-64898">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-64897 – ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Impr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-64897</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-64897</guid>
    <pubDate>Wed, 10 Dec 2025 00:16:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-64897</strong></p>
  <p>ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Improper Access Control vulnerability. A low privileged attacker could leverage this vulnerability to bypass security measures and gain limited unauthorized write access potentially resulting in denial of service. Exploitation of this issue requires user interaction.</p>
  <p><strong>CVSS:</strong> 5.6 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-64897">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-61823 – ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Impr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-61823</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-61823</guid>
    <pubDate>Wed, 10 Dec 2025 00:16:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-61823</strong></p>
  <p>ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could lead to arbitrary file system read. A high privileged attacker could exploit this vulnerability to access sensitive files and data on the server. Exploitation of this issue requires user interaction and scope is changed.</p>
  <p><strong>CVSS:</strong> 6.2 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-61823">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-61822 – ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Impr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-61822</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-61822</guid>
    <pubDate>Wed, 10 Dec 2025 00:16:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-61822</strong></p>
  <p>ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Improper Input Validation vulnerability that could lead to arbitrary file system write. An attacker could exploit this vulnerability to write malicious files to arbitrary locations on the file system. Exploitation of this issue does not require user interaction and scope is changed.</p>
  <p><strong>CVSS:</strong> 6.2 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-61822">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-61821 – ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Impr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-61821</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-61821</guid>
    <pubDate>Wed, 10 Dec 2025 00:16:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-61821</strong></p>
  <p>ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to access sensitive files and data on the server. Exploitation of this issue does not require user interaction and scope is changed.</p>
  <p><strong>CVSS:</strong> 6.8 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-61821">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-61813 – ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Impr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-61813</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-61813</guid>
    <pubDate>Wed, 10 Dec 2025 00:16:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-61813</strong></p>
  <p>ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to access sensitive files on the server. Exploitation of this issue does requires user interaction and scope is changed.</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-61813">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-61812 – ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Impr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-61812</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-61812</guid>
    <pubDate>Wed, 10 Dec 2025 00:16:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-61812</strong></p>
  <p>ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Improper Input Validation vulnerability that could allow a high privileged attacker to gain arbitrary code execution. Exploitation of this issue does not require user interaction.</p>
  <p><strong>CVSS:</strong> 8.4 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-61812">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-61811 – ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Impr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-61811</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-61811</guid>
    <pubDate>Wed, 10 Dec 2025 00:16:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-61811</strong></p>
  <p>ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Improper Access Control vulnerability that could result in arbitrary code execution in the context of the current user. A high privileged attacker could leverage this vulnerability to bypass security measures and execute malicious code. Exploitation of this issue does not require user interaction and scope is changed.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-61811">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-61810 – ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by a Deser...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-61810</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-61810</guid>
    <pubDate>Wed, 10 Dec 2025 00:16:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-61810</strong></p>
  <p>ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could result in arbitrary code execution in the context of the current user. A high privileged attacker could exploit this vulnerability by providing maliciously crafted serialized data to the application. Exploitation of this issue requires user interaction and scope is…</p>
  <p><strong>CVSS:</strong> 8.4 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-61810">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-61809 – ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Impr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-61809</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-61809</guid>
    <pubDate>Wed, 10 Dec 2025 00:16:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-61809</strong></p>
  <p>ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized read and write access. Exploitation of this issue does not require user interaction and scope is unchanged.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-61809">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-61808 – ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Unre...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-61808</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-61808</guid>
    <pubDate>Wed, 10 Dec 2025 00:16:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-61808</strong></p>
  <p>ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Unrestricted Upload of File with Dangerous Type vulnerability that could lead to arbitrary code execution by a high priviledged attacker. Exploitation of this issue does not require user interaction and scope is changed.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-434</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-61808">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-54261 – ColdFusion versions 2025.3, 2023.15, 2021.21 and earlier are affected by an Impr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-54261</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-54261</guid>
    <pubDate>Tue, 09 Sep 2025 17:15:59 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-54261</strong></p>
  <p>ColdFusion versions 2025.3, 2023.15, 2021.21 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary code execution by an attacker. The victim must have optional configurations enabled. Scope is changed.</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-54261">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2025-54234 – ColdFusion versions 2025.1, 2023.13, 2021.19 and earlier are affected by a Serve...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-54234</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-54234</guid>
    <pubDate>Mon, 18 Aug 2025 17:15:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2025-54234</strong></p>
  <p>ColdFusion versions 2025.1, 2023.13, 2021.19 and earlier are affected by a Server-Side Request Forgery (SSRF) vulnerability that could lead to limited file system read. A high-privilege authenticated attacker can force the application to make arbitrary requests via injection of arbitrary URLs. Exploitation of this issue does not require user interaction.</p>
  <p><strong>CVSS:</strong> 2.7 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-54234">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-49551 – ColdFusion versions 2025.2, 2023.14, 2021.20 and earlier are affected by a Use o...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-49551</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-49551</guid>
    <pubDate>Tue, 08 Jul 2025 21:15:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-49551</strong></p>
  <p>ColdFusion versions 2025.2, 2023.14, 2021.20 and earlier are affected by a Use of Hard-coded Credentials vulnerability that could result in privilege escalation. An attacker could leverage this vulnerability to gain unauthorized access to sensitive systems or data. Exploitation of this issue does not require user interaction. The vulnerable component is restricted to internal IP addresses.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-798</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-49551">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2025-49546 – ColdFusion versions 2025.2, 2023.14, 2021.20 and earlier are affected by an Impr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-49546</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-49546</guid>
    <pubDate>Tue, 08 Jul 2025 21:15:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2025-49546</strong></p>
  <p>ColdFusion versions 2025.2, 2023.14, 2021.20 and earlier are affected by an Improper Access Control vulnerability that could lead to a partial application denial-of-service. A high-privileged attacker could exploit this vulnerability to partially disrupt the availability of the application. Exploitation of this issue does not require user interaction and scope is unchanged. The vulnerable compone…</p>
  <p><strong>CVSS:</strong> 2.4 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-49546">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-49545 – ColdFusion versions 2025.2, 2023.14, 2021.20 and earlier are affected by a Serve...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-49545</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-49545</guid>
    <pubDate>Tue, 08 Jul 2025 21:15:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-49545</strong></p>
  <p>ColdFusion versions 2025.2, 2023.14, 2021.20 and earlier are affected by a Server-Side Request Forgery (SSRF) vulnerability that could lead to arbitrary file system read. A high-privilege authenticated attacker can force the application to make arbitrary requests via injection of URLs. Exploitation of this issue does not require user interaction and scope is changed. The vulnerable component is r…</p>
  <p><strong>CVSS:</strong> 6.2 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-49545">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-49544 – ColdFusion versions 2025.2, 2023.14, 2021.20 and earlier are affected by an Impr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-49544</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-49544</guid>
    <pubDate>Tue, 08 Jul 2025 21:15:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-49544</strong></p>
  <p>ColdFusion versions 2025.2, 2023.14, 2021.20 and earlier are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could result in a Security feature bypass. A high-privileged attacker could leverage this vulnerability to access sensitive information or bypass security measures. Exploitation of this issue does not require user interaction and scope is cha…</p>
  <p><strong>CVSS:</strong> 6.8 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-49544">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-49543 – ColdFusion versions 2025.2, 2023.14, 2021.20 and earlier are affected by a store...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-49543</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-49543</guid>
    <pubDate>Tue, 08 Jul 2025 21:15:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-49543</strong></p>
  <p>ColdFusion versions 2025.2, 2023.14, 2021.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a high-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field, scope is changed. The vulnerable component is r…</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-49543">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-49542 – ColdFusion versions 2025.2, 2023.14, 2021.20 and earlier are affected by a refle...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-49542</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-49542</guid>
    <pubDate>Tue, 08 Jul 2025 21:15:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-49542</strong></p>
  <p>ColdFusion versions 2025.2, 2023.14, 2021.20 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an unauthenticated attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser, scope is changed. The vulnerable component is restricted to internal IP addre…</p>
  <p><strong>CVSS:</strong> 5.2 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-49542">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-49541 – ColdFusion versions 2025.2, 2023.14, 2021.20 and earlier are affected by a store...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-49541</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-49541</guid>
    <pubDate>Tue, 08 Jul 2025 21:15:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-49541</strong></p>
  <p>ColdFusion versions 2025.2, 2023.14, 2021.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a high-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field, scope is changed. The vulnerable component is r…</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-49541">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-49540 – ColdFusion versions 2025.2, 2023.14, 2021.20 and earlier are affected by a store...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-49540</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-49540</guid>
    <pubDate>Tue, 08 Jul 2025 21:15:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-49540</strong></p>
  <p>ColdFusion versions 2025.2, 2023.14, 2021.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a high-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field, scope is changed. The vulnerable component is r…</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-49540">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-49539 – ColdFusion versions 2025.2, 2023.14, 2021.20 and earlier are affected by an Impr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-49539</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-49539</guid>
    <pubDate>Tue, 08 Jul 2025 21:15:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-49539</strong></p>
  <p>ColdFusion versions 2025.2, 2023.14, 2021.20 and earlier are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could result in a security feature bypass. A high-privileged attacker could leverage this vulnerability to access sensitive information. Exploitation of this issue does not require user interaction. The vulnerable component is restricted to i…</p>
  <p><strong>CVSS:</strong> 4.5 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-49539">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-49538 – ColdFusion versions 2025.2, 2023.14, 2021.20 and earlier are affected by an XML ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-49538</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-49538</guid>
    <pubDate>Tue, 08 Jul 2025 21:15:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-49538</strong></p>
  <p>ColdFusion versions 2025.2, 2023.14, 2021.20 and earlier are affected by an XML Injection vulnerability that could lead to arbitrary file system read. An attacker can exploit this issue by injecting crafted XML or XPath queries to access unauthorized files or lead to denial of service. Exploitation of this issue does not require user interaction, and attack must have access to shared secrets.</p>
  <p><strong>CVSS:</strong> 7.4 · <strong>CWE:</strong> CWE-91</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-49538">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-49537 – ColdFusion versions 2025.2, 2023.14, 2021.20 and earlier are affected by an Impr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-49537</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-49537</guid>
    <pubDate>Tue, 08 Jul 2025 21:15:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-49537</strong></p>
  <p>ColdFusion versions 2025.2, 2023.14, 2021.20 and earlier are affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could lead to arbitrary code execution by a high-privileged attacker. Exploitation of this issue requires user interaction and scope is changed. The vulnerable component is restricted to internal IP addresses.</p>
  <p><strong>CVSS:</strong> 7.9 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-49537">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-49536 – ColdFusion versions 2025.2, 2023.14, 2021.20 and earlier are affected by an Inco...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-49536</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-49536</guid>
    <pubDate>Tue, 08 Jul 2025 21:15:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-49536</strong></p>
  <p>ColdFusion versions 2025.2, 2023.14, 2021.20 and earlier are affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and gain unauthorized access. Exploitation of this issue does not require user interaction. The vulnerable component is restricted to internal IP add…</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-49536">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-49535 – ColdFusion versions 2025.2, 2023.14, 2021.20 and earlier are affected by an Impr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-49535</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-49535</guid>
    <pubDate>Tue, 08 Jul 2025 21:15:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-49535</strong></p>
  <p>ColdFusion versions 2025.2, 2023.14, 2021.20 and earlier are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could result in a Security feature bypass. An attacker could exploit this vulnerability to access sensitive information or denial of service by bypassing security measures. Exploitation of this issue does not require user interaction and scop…</p>
  <p><strong>CVSS:</strong> 9.3 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-49535">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-43566 – ColdFusion versions 2025.1, 2023.13, 2021.19 and earlier are affected by an Impr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-43566</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-43566</guid>
    <pubDate>Tue, 13 May 2025 21:16:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-43566</strong></p>
  <p>ColdFusion versions 2025.1, 2023.13, 2021.19 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary file system read. A high-privileged attacker could leverage this vulnerability to bypass security protections and gain unauthorized read access. Exploitation of this issue does not require user interac…</p>
  <p><strong>CVSS:</strong> 6.8 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-43566">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-43565 – ColdFusion versions 2025.1, 2023.13, 2021.19 and earlier are affected by an Inco...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-43565</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-43565</guid>
    <pubDate>Tue, 13 May 2025 21:16:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-43565</strong></p>
  <p>ColdFusion versions 2025.1, 2023.13, 2021.19 and earlier are affected by an Incorrect Authorization vulnerability that could lead to arbitrary code execution in the context of the current user. A high-privileged attacker could leverage this vulnerability to bypass security protections and execute code. Exploitation of this issue requires user interaction and scope is changed.</p>
  <p><strong>CVSS:</strong> 8.4 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-43565">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-43564 – ColdFusion versions 2025.1, 2023.13, 2021.19 and earlier are affected by an Impr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-43564</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-43564</guid>
    <pubDate>Tue, 13 May 2025 21:16:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-43564</strong></p>
  <p>ColdFusion versions 2025.1, 2023.13, 2021.19 and earlier are affected by an Improper Access Control vulnerability that could result in arbitrary file system read. A high-privileged attacker could leverage this vulnerability to access or modify sensitive data without proper authorization. Exploitation of this issue does not require user interaction, and scope is changed</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-43564">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-43563 – ColdFusion versions 2025.1, 2023.13, 2021.19 and earlier are affected by an Impr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-43563</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-43563</guid>
    <pubDate>Tue, 13 May 2025 21:16:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-43563</strong></p>
  <p>ColdFusion versions 2025.1, 2023.13, 2021.19 and earlier are affected by an Improper Access Control vulnerability that could result in arbitrary file system read. A high-privileged attacker could leverage this vulnerability to access or modify sensitive data without proper authorization. Exploitation of this issue does not require user interaction, and scope is changed.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-43563">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-43562 – ColdFusion versions 2025.1, 2023.13, 2021.19 and earlier are affected by an Impr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-43562</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-43562</guid>
    <pubDate>Tue, 13 May 2025 21:16:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-43562</strong></p>
  <p>ColdFusion versions 2025.1, 2023.13, 2021.19 and earlier are affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could result in arbitrary code execution in the context of the current user. A high-privileged attacker could leverage this vulnerability to bypass security mechanisms and execute code. Exploitation of this issue…</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-43562">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-43561 – ColdFusion versions 2025.1, 2023.13, 2021.19 and earlier are affected by an Inco...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-43561</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-43561</guid>
    <pubDate>Tue, 13 May 2025 21:16:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-43561</strong></p>
  <p>ColdFusion versions 2025.1, 2023.13, 2021.19 and earlier are affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. A high-privileged attacker could leverage this vulnerability to bypass authentication mechanisms and execute code. Exploitation of this issue does not require user interaction and scope is changed.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-43561">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-43560 – ColdFusion versions 2025.1, 2023.13, 2021.19 and earlier are affected by an Impr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-43560</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-43560</guid>
    <pubDate>Tue, 13 May 2025 21:16:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-43560</strong></p>
  <p>ColdFusion versions 2025.1, 2023.13, 2021.19 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. A high-privileged attacker could leverage this vulnerability to bypass security mechanisms and execute code. Exploitation of this issue does not require user interaction and scope is changed.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-43560">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-43559 – ColdFusion versions 2025.1, 2023.13, 2021.19 and earlier are affected by an Impr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-43559</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-43559</guid>
    <pubDate>Tue, 13 May 2025 21:16:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-43559</strong></p>
  <p>ColdFusion versions 2025.1, 2023.13, 2021.19 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. A high-privileged attacker could leverage this vulnerability to bypass security mechanisms and execute code. Exploitation of this issue does not require user interaction and scope is changed.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-43559">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-30294 – ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by an Impr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-30294</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-30294</guid>
    <pubDate>Tue, 08 Apr 2025 20:15:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-30294</strong></p>
  <p>ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by an Improper Input Validation vulnerability that could result in a security feature bypass. A high-privileged attacker could leverage this vulnerability to bypass security protections and gain unauthorized read access. Exploitation of this issue does not require user interaction and scope is changed.</p>
  <p><strong>CVSS:</strong> 6.8 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-30294">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-30293 – ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by an Impr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-30293</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-30293</guid>
    <pubDate>Tue, 08 Apr 2025 20:15:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-30293</strong></p>
  <p>ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by an Improper Input Validation vulnerability that could result in a security feature bypass. A high-privileged attacker could leverage this vulnerability to bypass security protections and gain unauthorized write access. Exploitation of this issue does not require user interaction and scope is changed.</p>
  <p><strong>CVSS:</strong> 6.8 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-30293">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-30292 – ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by a refle...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-30292</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-30292</guid>
    <pubDate>Tue, 08 Apr 2025 20:15:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-30292</strong></p>
  <p>ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-30292">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-30291 – ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by an Info...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-30291</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-30291</guid>
    <pubDate>Tue, 08 Apr 2025 20:15:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-30291</strong></p>
  <p>ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by an Information Exposure vulnerability that could result in a security feature bypass. A low privileged attacker with local access could leverage this vulnerability to gain access to sensitive information which could be used to further compromise the system or bypass security mechanisms. Exploitation of this issue does not re…</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-30291">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-30290 – ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by an Impr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-30290</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-30290</guid>
    <pubDate>Tue, 08 Apr 2025 20:15:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-30290</strong></p>
  <p>ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to a security feature bypass. A high privileged attacker could exploit this vulnerability to bypass security protections and gain unauthorized write and delete access. Exploitation of this issue does not require us…</p>
  <p><strong>CVSS:</strong> 8.7 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-30290">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-30289 – ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by an Impr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-30289</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-30289</guid>
    <pubDate>Tue, 08 Apr 2025 20:15:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-30289</strong></p>
  <p>ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could lead in arbitrary code execution by an attacker. A low privileged attacker with local access could leverage this vulnerability to bypass security protections and execute code. Exploitation of this issue requ…</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-30289">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-30288 – ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by an Impr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-30288</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-30288</guid>
    <pubDate>Tue, 08 Apr 2025 20:15:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-30288</strong></p>
  <p>ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. A low privileged attacker with local access could leverage this vulnerability to bypass security protections and execute code. Exploitation of this issue requires user interaction in that a victim must be coerced into performing actions…</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-30288">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-30287 – ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by an Impr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-30287</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-30287</guid>
    <pubDate>Tue, 08 Apr 2025 20:15:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-30287</strong></p>
  <p>ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by an Improper Authentication vulnerability that could result in arbitrary code execution in the context of the current user. A low privileged attacker with local access could leverage this vulnerability to bypass security protections and execute code. Exploitation of this issue requires user interaction in that a victim must b…</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-30287">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-30286 – ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by an Impr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-30286</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-30286</guid>
    <pubDate>Tue, 08 Apr 2025 20:15:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-30286</strong></p>
  <p>ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could lead in arbitrary code execution by an attacker. A high-privileged attacker could leverage this vulnerability to bypass security protections and execute code. Exploitation of this issue requires user interac…</p>
  <p><strong>CVSS:</strong> 8.4 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-30286">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-30285 – ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by a Deser...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-30285</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-30285</guid>
    <pubDate>Tue, 08 Apr 2025 20:15:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-30285</strong></p>
  <p>ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could result in arbitrary code execution in the context of the current user. A high-privileged attacker could leverage this vulnerability to bypass security protections and execute code. Exploitation of this issue requires user interaction and scope is changed.</p>
  <p><strong>CVSS:</strong> 8.4 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-30285">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-30284 – ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by a Deser...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-30284</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-30284</guid>
    <pubDate>Tue, 08 Apr 2025 20:15:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-30284</strong></p>
  <p>ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could result in arbitrary code execution in the context of the current user. A high-privileged attacker could leverage this vulnerability to bypass security protections and execute code. Exploitation of this issue requires user interaction and scope is changed.</p>
  <p><strong>CVSS:</strong> 8.4 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-30284">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-30282 – ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by an Impr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-30282</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-30282</guid>
    <pubDate>Tue, 08 Apr 2025 20:15:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-30282</strong></p>
  <p>ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by an Improper Authentication vulnerability that could result in arbitrary code execution in the context of the current user. A high-privileged attacker could leverage this vulnerability to bypass authentication mechanisms and execute code. Exploitation of this issue does not require user interaction and scope is changed.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-30282">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-30281 – ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by an Impr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-30281</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-30281</guid>
    <pubDate>Tue, 08 Apr 2025 20:15:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-30281</strong></p>
  <p>ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by an Improper Access Control vulnerability that could result in arbitrary code execution. A high-privileged attacker could leverage this vulnerability to access or modify sensitive data without proper authorization. Exploitation of this issue does not require user interaction, and scope is changed.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-30281">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-24447 – ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by a Deser...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-24447</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-24447</guid>
    <pubDate>Tue, 08 Apr 2025 20:15:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-24447</strong></p>
  <p>ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could result in arbitrary code execution in the context of the current user resulting in a High impact to Confidentiality and Integrity. Exploitation of this issue does not require user interaction.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-24447">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-24446 – ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by an Impr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-24446</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-24446</guid>
    <pubDate>Tue, 08 Apr 2025 20:15:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-24446</strong></p>
  <p>ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution. Exploitation of this issue does not require user interaction, but admin panel privileges are required, and scope is changed.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-24446">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-53961 – ColdFusion versions 2023.11, 2021.17 and earlier are affected by an Improper Lim...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-53961</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-53961</guid>
    <pubDate>Mon, 23 Dec 2024 21:15:05 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-53961</strong></p>
  <p>ColdFusion versions 2023.11, 2021.17 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to access files or directories that are outside of the restricted directory set by the application. This could lead to the disclosure of sensitive…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-53961">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-45113 – ColdFusion versions 2023.6, 2021.12 and earlier are affected by an Improper Auth...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-45113</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-45113</guid>
    <pubDate>Fri, 13 Sep 2024 10:15:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-45113</strong></p>
  <p>ColdFusion versions 2023.6, 2021.12 and earlier are affected by an Improper Authentication vulnerability that could result in privilege escalation. An attacker could exploit this vulnerability to gain unauthorized access and affect the integrity of the application. Exploitation of this issue does not require user interaction.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-45113">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-41874 – ColdFusion versions 2023.9, 2021.15 and earlier are affected by a Deserializatio...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-41874</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-41874</guid>
    <pubDate>Fri, 13 Sep 2024 10:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-41874</strong></p>
  <p>ColdFusion versions 2023.9, 2021.15 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability by providing crafted input to the application, which when deserialized, leads to execution of malicious code. Exploitation of this issue does not require user…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-41874">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-34113 – ColdFusion versions 2023u7, 2021u13 and earlier are affected by a Weak Cryptogra...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-34113</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-34113</guid>
    <pubDate>Thu, 13 Jun 2024 12:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-34113</strong></p>
  <p>ColdFusion versions 2023u7, 2021u13 and earlier are affected by a Weak Cryptography for Passwords vulnerability that could result in a security feature bypass. This vulnerability arises due to the use of insufficiently strong cryptographic algorithms or flawed implementation that compromises the confidentiality of password data. An attacker could exploit this weakness to decrypt or guess password…</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-261</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-34113">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-34112 – ColdFusion versions 2023u7, 2021u13 and earlier are affected by an Improper Acce...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-34112</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-34112</guid>
    <pubDate>Thu, 13 Jun 2024 12:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-34112</strong></p>
  <p>ColdFusion versions 2023u7, 2021u13 and earlier are affected by an Improper Access Control vulnerability that could result in arbitrary file system read. An attacker could exploit this vulnerability to gain unauthorized access to sensitive files or data. Exploitation of this issue does not require user interaction.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-34112">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-20767 – ColdFusion versions 2023.6, 2021.12 and earlier are affected by an Improper Acce...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-20767</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-20767</guid>
    <pubDate>Mon, 18 Mar 2024 12:15:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-20767</strong></p>
  <p>ColdFusion versions 2023.6, 2021.12 and earlier are affected by an Improper Access Control vulnerability that could result in arbitrary file system read. An attacker could leverage this vulnerability to access or modify restricted files. Exploitation of this issue does not require user interaction. Exploitation of this issue requires the admin panel be exposed to the internet.</p>
  <p><strong>CVSS:</strong> 7.4 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-20767">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-44355 – Adobe ColdFusion versions 2023.5 (and earlier) and 2021.11 (and earlier) are aff...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-44355</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-44355</guid>
    <pubDate>Fri, 17 Nov 2023 14:15:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-44355</strong></p>
  <p>Adobe ColdFusion versions 2023.5 (and earlier) and 2021.11 (and earlier) are affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. An unauthenticated attacker could leverage this vulnerability to impact a minor integrity feature. Exploitation of this issue does require user interaction.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-44355">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2023-44353 – Adobe ColdFusion versions 2023.5 (and earlier) and 2021.11 (and earlier) are aff...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-44353</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-44353</guid>
    <pubDate>Fri, 17 Nov 2023 14:15:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2023-44353</strong></p>
  <p>Adobe ColdFusion versions 2023.5 (and earlier) and 2021.11 (and earlier) are affected by an Deserialization of Untrusted Data vulnerability that could result in Arbitrary code execution. Exploitation of this issue does not require user interaction.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-44353">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-44352 – Adobe ColdFusion versions 2023.5 (and earlier) and 2021.11 (and earlier) are aff...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-44352</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-44352</guid>
    <pubDate>Fri, 17 Nov 2023 14:15:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-44352</strong></p>
  <p>Adobe ColdFusion versions 2023.5 (and earlier) and 2021.11 (and earlier) are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an unauthenticated attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-44352">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2023-44351 – Adobe ColdFusion versions 2023.5 (and earlier) and 2021.11 (and earlier) are aff...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-44351</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-44351</guid>
    <pubDate>Fri, 17 Nov 2023 14:15:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2023-44351</strong></p>
  <p>Adobe ColdFusion versions 2023.5 (and earlier) and 2021.11 (and earlier) are affected by an Deserialization of Untrusted Data vulnerability that could result in Arbitrary code execution. Exploitation of this issue does not require user interaction.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-44351">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2023-44350 – Adobe ColdFusion versions 2023.5 (and earlier) and 2021.11 (and earlier) are aff...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-44350</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-44350</guid>
    <pubDate>Fri, 17 Nov 2023 14:15:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2023-44350</strong></p>
  <p>Adobe ColdFusion versions 2023.5 (and earlier) and 2021.11 (and earlier) are affected by an Deserialization of Untrusted Data vulnerability that could result in Arbitrary code execution. Exploitation of this issue does not require user interaction.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-44350">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-26347 – Adobe ColdFusion versions 2023.5 (and earlier) and 2021.11 (and earlier) are aff...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-26347</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-26347</guid>
    <pubDate>Fri, 17 Nov 2023 14:15:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-26347</strong></p>
  <p>Adobe ColdFusion versions 2023.5 (and earlier) and 2021.11 (and earlier) are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. An unauthenticated attacker could leverage this vulnerability to access the administration CFM and CFC endpoints. Exploitation of this issue does not require user interaction.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-26347">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-38206 – Adobe ColdFusion versions 2018u18 (and earlier), 2021u8 (and earlier) and 2023u2...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-38206</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-38206</guid>
    <pubDate>Thu, 14 Sep 2023 08:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-38206</strong></p>
  <p>Adobe ColdFusion versions 2018u18 (and earlier), 2021u8 (and earlier) and 2023u2 (and earlier) are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to access the administration CFM and CFC endpoints resulting in a low-confidentiality impact. Exploitation of this issue does not require user interactio…</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-38206">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-38205 – Adobe ColdFusion versions 2018u18 (and earlier), 2021u8 (and earlier) and 2023u2...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-38205</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-38205</guid>
    <pubDate>Thu, 14 Sep 2023 08:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-38205</strong></p>
  <p>Adobe ColdFusion versions 2018u18 (and earlier), 2021u8 (and earlier) and 2023u2 (and earlier) are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to access the administration CFM and CFC endpoints. Exploitation of this issue does not require user interaction.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-38205">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2023-38204 – Adobe ColdFusion versions 2018u18 (and earlier), 2021u8 (and earlier) and 2023u2...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-38204</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-38204</guid>
    <pubDate>Thu, 14 Sep 2023 08:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2023-38204</strong></p>
  <p>Adobe ColdFusion versions 2018u18 (and earlier), 2021u8 (and earlier) and 2023u2 (and earlier) are affected by a Deserialization of Untrusted Data vulnerability that could result in Arbitrary code execution. Exploitation of this issue does not require user interaction.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-38204">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-40699 – ColdFusion version 2021 update 1 (and earlier) and versions 2018.10 (and earlier...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-40699</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-40699</guid>
    <pubDate>Thu, 07 Sep 2023 13:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-40699</strong></p>
  <p>ColdFusion version 2021 update 1 (and earlier) and versions 2018.10 (and earlier) are impacted by an improper access control vulnerability when checking permissions in the CFIDE path. An authenticated attacker could leverage this vulnerability to access and manipulate arbitrary data on the environment.</p>
  <p><strong>CVSS:</strong> 7.4 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-40699">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-40698 – ColdFusion version 2021 update 1 (and earlier) and versions 2018.10 (and earlier...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-40698</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-40698</guid>
    <pubDate>Thu, 07 Sep 2023 13:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-40698</strong></p>
  <p>ColdFusion version 2021 update 1 (and earlier) and versions 2018.10 (and earlier) are impacted by an Use of Inherently Dangerous Function vulnerability that can lead to a security feature bypass  . An authenticated attacker could leverage this vulnerability to access and manipulate arbitrary data on the environment.</p>
  <p><strong>CVSS:</strong> 7.4 · <strong>CWE:</strong> CWE-242</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-40698">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2023-38203 – Adobe ColdFusion versions 2018u17 (and earlier), 2021u7 (and earlier) and 2023u1...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-38203</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-38203</guid>
    <pubDate>Thu, 20 Jul 2023 16:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2023-38203</strong></p>
  <p>Adobe ColdFusion versions 2018u17 (and earlier), 2021u7 (and earlier) and 2023u1 (and earlier) are affected by a Deserialization of Untrusted Data vulnerability that could result in Arbitrary code execution. Exploitation of this issue does not require user interaction.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-38203">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-29301 – Adobe ColdFusion versions 2018u16 (and earlier), 2021u6 (and earlier) and 2023.0...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-29301</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-29301</guid>
    <pubDate>Wed, 12 Jul 2023 16:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-29301</strong></p>
  <p>Adobe ColdFusion versions 2018u16 (and earlier), 2021u6 (and earlier) and 2023.0.0.330468 (and earlier) are affected by an Improper Restriction of Excessive Authentication Attempts vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to impact the confidentiality of the user. Exploitation of this issue does not require user interaction.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-307</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-29301">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2023-29300 – Adobe ColdFusion versions 2018u16 (and earlier), 2021u6 (and earlier) and 2023.0...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-29300</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-29300</guid>
    <pubDate>Wed, 12 Jul 2023 16:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2023-29300</strong></p>
  <p>Adobe ColdFusion versions 2018u16 (and earlier), 2021u6 (and earlier) and 2023.0.0.330468 (and earlier) are affected by a Deserialization of Untrusted Data vulnerability that could result in Arbitrary code execution. Exploitation of this issue does not require user interaction.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-29300">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-29298 – Adobe ColdFusion versions 2018u16 (and earlier), 2021u6 (and earlier) and 2023.0...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-29298</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-29298</guid>
    <pubDate>Wed, 12 Jul 2023 16:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-29298</strong></p>
  <p>Adobe ColdFusion versions 2018u16 (and earlier), 2021u6 (and earlier) and 2023.0.0.330468 (and earlier) are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to access the administration CFM and CFC endpoints. Exploitation of this issue does not require user interaction.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-29298">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-26361 – Adobe ColdFusion versions 2018 Update 15 (and earlier) and 2021 Update 5 (and ea...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-26361</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-26361</guid>
    <pubDate>Thu, 23 Mar 2023 20:15:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-26361</strong></p>
  <p>Adobe ColdFusion versions 2018 Update 15 (and earlier) and 2021 Update 5 (and earlier) are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in Arbitrary file system read. Exploitation of this issue does not require user interaction, but does require administrator privileges.</p>
  <p><strong>CVSS:</strong> 4.9 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-26361">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-26360 – Adobe ColdFusion versions 2018 Update 15 (and earlier) and 2021 Update 5 (and ea...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-26360</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-26360</guid>
    <pubDate>Thu, 23 Mar 2023 20:15:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-26360</strong></p>
  <p>Adobe ColdFusion versions 2018 Update 15 (and earlier) and 2021 Update 5 (and earlier) are affected by an Improper Access Control vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction.</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-26360">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2023-26359 – Adobe ColdFusion versions 2018 Update 15 (and earlier) and 2021 Update 5 (and ea...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-26359</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-26359</guid>
    <pubDate>Thu, 23 Mar 2023 20:15:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2023-26359</strong></p>
  <p>Adobe ColdFusion versions 2018 Update 15 (and earlier) and 2021 Update 5 (and earlier) are affected by a Deserialization of Untrusted Data vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-26359">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-42341 – Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-42341</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-42341</guid>
    <pubDate>Fri, 14 Oct 2022 20:15:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-42341</strong></p>
  <p>Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could result in arbitrary file system read. Exploitation of this issue does not require user interaction.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-42341">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-42340 – Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-42340</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-42340</guid>
    <pubDate>Fri, 14 Oct 2022 20:15:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-42340</strong></p>
  <p>Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are affected by an Improper Input Validation vulnerability that could result in arbitrary file system read. Exploitation of this issue does not require user interaction.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-42340">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-38424 – Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-38424</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-38424</guid>
    <pubDate>Fri, 14 Oct 2022 20:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-38424</strong></p>
  <p>Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in arbitrary file system write. Exploitation of this issue does not require user interaction, but does require administrator privileges.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-38424">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-38423 – Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-38423</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-38423</guid>
    <pubDate>Fri, 14 Oct 2022 20:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-38423</strong></p>
  <p>Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in information disclosure. Exploitation of this issue does not require user interaction, but does require administrator privileges.</p>
  <p><strong>CVSS:</strong> 4.9 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-38423">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-38422 – Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-38422</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-38422</guid>
    <pubDate>Fri, 14 Oct 2022 20:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-38422</strong></p>
  <p>Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in information disclosure. Exploitation of this issue does not require user interaction.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-38422">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-38421 – Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-38421</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-38421</guid>
    <pubDate>Fri, 14 Oct 2022 20:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-38421</strong></p>
  <p>Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction, but does require administrator privileges.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-38421">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-38420 – Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-38420</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-38420</guid>
    <pubDate>Fri, 14 Oct 2022 20:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-38420</strong></p>
  <p>Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are affected by a Use of Hard-coded Credentials vulnerability that could result in application denial-of-service by gaining access to start/stop arbitrary services. Exploitation of this issue does not require user interaction.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-798</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-38420">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-38419 – Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-38419</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-38419</guid>
    <pubDate>Fri, 14 Oct 2022 20:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-38419</strong></p>
  <p>Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could result in arbitrary file system read. Exploitation of this issue does not require user interaction.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-38419">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2022-38418 – Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-38418</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-38418</guid>
    <pubDate>Fri, 14 Oct 2022 20:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2022-38418</strong></p>
  <p>Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-38418">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2022-35712 – Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-35712</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-35712</guid>
    <pubDate>Fri, 14 Oct 2022 20:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2022-35712</strong></p>
  <p>Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction, the vulnerability is triggered when a crafted network packet is sent to the server.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-122</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-35712">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2022-35711 – Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-35711</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-35711</guid>
    <pubDate>Fri, 14 Oct 2022 20:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2022-35711</strong></p>
  <p>Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction, the vulnerability is triggered when a crafted network packet is sent to the server.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-122</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-35711">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2022-35710 – Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-35710</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-35710</guid>
    <pubDate>Fri, 14 Oct 2022 20:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2022-35710</strong></p>
  <p>Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction, the vulnerability is triggered when a crafted network packet is sent to the server.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-121</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-35710">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2022-35690 – Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-35690</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-35690</guid>
    <pubDate>Fri, 14 Oct 2022 20:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2022-35690</strong></p>
  <p>Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction, the vulnerability is triggered when a crafted network packet is sent to the server.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-121</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-35690">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-28818 – ColdFusion versions CF2021U3 (and earlier) and CF2018U13 are affected by a refle...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-28818</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-28818</guid>
    <pubDate>Thu, 12 May 2022 19:15:49 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-28818</strong></p>
  <p>ColdFusion versions CF2021U3 (and earlier) and CF2018U13 are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-28818">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-10145 – The Adobe ColdFusion installer fails to set a secure access-control list (ACL) o...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-10145</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-10145</guid>
    <pubDate>Thu, 27 May 2021 21:15:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-10145</strong></p>
  <p>The Adobe ColdFusion installer fails to set a secure access-control list (ACL) on the default installation directory, such as C:\ColdFusion2021\. By default, unprivileged users can create files in this directory structure, which creates a privilege-escalation vulnerability.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-10145">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-21087 – Adobe Coldfusion versions 2016 (update 16 and earlier), 2018 (update 10 and earl...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-21087</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-21087</guid>
    <pubDate>Thu, 15 Apr 2021 14:15:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-21087</strong></p>
  <p>Adobe Coldfusion versions 2016 (update 16 and earlier), 2018 (update 10 and earlier) and 2021.0.0.323925 are affected by an Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability. An attacker could abuse this vulnerability to execute arbitrary JavaScript code in context of the current user. Exploitation of this issue requires user interaction.</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-21087">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-9673 – Adobe ColdFusion 2016 update 15 and earlier versions, and ColdFusion 2018 update...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-9673</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-9673</guid>
    <pubDate>Fri, 17 Jul 2020 00:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-9673</strong></p>
  <p>Adobe ColdFusion 2016 update 15 and earlier versions, and ColdFusion 2018 update 9 and earlier versions have a dll search-order hijacking vulnerability. Successful exploitation could lead to privilege escalation.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-426</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-9673">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-9672 – Adobe ColdFusion 2016 update 15 and earlier versions, and ColdFusion 2018 update...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-9672</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-9672</guid>
    <pubDate>Fri, 17 Jul 2020 00:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-9672</strong></p>
  <p>Adobe ColdFusion 2016 update 15 and earlier versions, and ColdFusion 2018 update 9 and earlier versions have a dll search-order hijacking vulnerability. Successful exploitation could lead to privilege escalation.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-426</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-9672">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2020-3796 – ColdFusion versions ColdFusion 2016, and ColdFusion 2018 have an improper access...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-3796</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-3796</guid>
    <pubDate>Fri, 26 Jun 2020 21:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2020-3796</strong></p>
  <p>ColdFusion versions ColdFusion 2016, and ColdFusion 2018 have an improper access control vulnerability. Successful exploitation could lead to system file structure disclosure.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-3796">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-3768 – ColdFusion versions ColdFusion 2016, and ColdFusion 2018 have a dll search-order...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-3768</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-3768</guid>
    <pubDate>Fri, 26 Jun 2020 21:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-3768</strong></p>
  <p>ColdFusion versions ColdFusion 2016, and ColdFusion 2018 have a dll search-order hijacking vulnerability. Successful exploitation could lead to privilege escalation.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-426</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-3768">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
