Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

ColdFusion — Vulnerabilities & Security Advisories 137

All 137 CVE vulnerabilities found in ColdFusion, with AI-generated Chinese analysis, references, and POCs.

This page documents Common Weakness Enumerations associated with Adobe ColdFusion, covering various vulnerability categories such as code injection, cross-site scripting, and privilege escalation. It aggregates historical security data to provide a comprehensive view of the product's exposure to known flaws. The collection spans from the early 2000s to the present, capturing the evolution of security issues as the platform underwent significant architectural changes and version updates. By consolidating these records, the page offers a unified repository for analysts, developers, and security researchers who need to understand the historical context of ColdFusion's security posture. Here, you can track vendor advisories issued by Adobe over time, allowing you to see how the company addressed specific classes of weaknesses in different releases. You can also explore detailed reports on specific weakness types to understand the root causes and remediation strategies applied to ColdFusion. Additionally, the page serves as a lookup tool for the vulnerability history of the product, helping users assess the risk profile of legacy or current installations. This structured approach facilitates better risk management by providing clear insights into past incidents and their resolutions, enabling informed decisions regarding patching and security hardening for environments relying on this application server.

Vendor: Adobe

CVE IDTitleCVSSSeverityPublished
CVE-2026-48363 ColdFusion | Uncontrolled Search Path Element (CWE-427) CWE-427 8.2 High2026-07-13
CVE-2026-48364 ColdFusion | Uncontrolled Search Path Element (CWE-427) CWE-427 8.2 High2026-07-13
CVE-2026-48316 ColdFusion | Improper Input Validation (CWE-20) CWE-20 10.0 Critical2026-07-06
CVE-2026-48315 ColdFusion | Improper Input Validation (CWE-20) CWE-20 9.3 Critical2026-06-30
CVE-2026-48281 ColdFusion | Improper Input Validation (CWE-20) CWE-20 10.0 Critical2026-06-30
CVE-2026-48277 ColdFusion | Improper Input Validation (CWE-20) CWE-20 10.0 Critical2026-06-30
CVE-2026-48285 ColdFusion | Server-Side Request Forgery (SSRF) (CWE-918) CWE-918 8.6 High2026-06-30
CVE-2026-48313 ColdFusion | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) CWE-22 9.3 Critical2026-06-30
CVE-2026-48314 ColdFusion | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) CWE-22 6.5 Medium2026-06-30
CVE-2026-48307 ColdFusion | Cross-site Scripting (Reflected XSS) (CWE-79) CWE-79 8.8 High2026-06-30
CVE-2026-48276 ColdFusion | Unrestricted Upload of File with Dangerous Type (CWE-434) CWE-434 10.0 Critical2026-06-30
CVE-2026-48282 ColdFusion | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) CWE-22 10.0 Critical2026-06-30
CVE-2026-48283 ColdFusion | Unrestricted Upload of File with Dangerous Type (CWE-434) CWE-434 10.0 Critical2026-06-30
CVE-2026-47929 ColdFusion | Incorrect Authorization (CWE-863) CWE-863 8.4 High2026-06-09
CVE-2026-47932 ColdFusion | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) CWE-22 8.8 High2026-06-09
CVE-2026-47960 ColdFusion | Improper Restriction of XML External Entity Reference ('XXE') (CWE-611) CWE-611 7.4 High2026-06-09
CVE-2026-47928 ColdFusion | Improper Input Validation (CWE-20) CWE-20 9.6 Critical2026-06-09
CVE-2026-47931 ColdFusion | Improper Input Validation (CWE-20) CWE-20 8.4 High2026-06-09
CVE-2026-47930 ColdFusion | Improper Input Validation (CWE-20) CWE-20 8.1 High2026-06-09
CVE-2026-47933 ColdFusion | Cross-site Scripting (Stored XSS) (CWE-79) CWE-79 4.8 Medium2026-06-09
CVE-2026-34619 ColdFusion | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) CWE-22 7.7 High2026-04-14
CVE-2026-27308 ColdFusion | Uncontrolled Resource Consumption (CWE-400) CWE-400 2.4 Low2026-04-14
CVE-2026-27282 ColdFusion | Improper Input Validation (CWE-20) CWE-20 7.5 High2026-04-14
CVE-2026-27305 ColdFusion | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) CWE-22 8.6 High2026-04-14
CVE-2026-27304 ColdFusion | Improper Input Validation (CWE-20) CWE-20 9.3 Critical2026-04-14
CVE-2026-27306 ColdFusion | Improper Input Validation (CWE-20) CWE-20 8.4 High2026-04-14
CVE-2026-27307 ColdFusion | Uncontrolled Resource Consumption (CWE-400) CWE-400 2.4 Low2026-04-14
CVE-2025-61808 ColdFusion | Unrestricted Upload of File with Dangerous Type (CWE-434) CWE-434 9.1 Critical2025-12-09
CVE-2025-61813 ColdFusion | Improper Restriction of XML External Entity Reference ('XXE') (CWE-611) CWE-611 7.4 High2025-12-09
CVE-2025-61812 ColdFusion | Improper Input Validation (CWE-20) CWE-20 8.4 High2025-12-09

All 137 known CVE vulnerabilities affecting ColdFusion with full Chinese analysis, references, and POCs where available.