ColdFusion 存在“SQL 命令中特殊元素中和不当(即 SQL 注入)”的漏洞,该漏洞可能导致在当前用户上下文中执行任意代码。拥有高权限的攻击者可以利用此漏洞执行任意代码。利用该问题不需要用户交互。作用域已变更。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Adobe | ColdFusion 2023 | ≤ 23 |
affected |
24 |
unaffected | ||
| Adobe | ColdFusion 2025 | ≤ 12 |
affected |
13 |
unaffected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Adobe | ColdFusion 2025 | 0 ~ 12 | - |
|
| Adobe | ColdFusion 2023 | 0 ~ 23 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-82004 | 10.0 CRITICAL | Adobe Campaign Classic (ACC) | Improper Neutralization of Special Elements used in an OS C |
| CVE-2026-19232 | 9.9 CRITICAL | Adobe Experience Manager | Incorrect Authorization (CWE-863) |
| CVE-2026-48273 | 9.9 CRITICAL | ColdFusion | Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval In |
| CVE-2026-76201 | 9.3 CRITICAL | Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79) |
| CVE-2026-76200 | 9.3 CRITICAL | Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79) |
| CVE-2026-81996 | 8.8 HIGH | Acrobat Reader | Incorrect Authorization (CWE-863) |
| CVE-2026-77111 | 8.7 HIGH | Adobe Commerce | Incorrect Authorization (CWE-863) |
| CVE-2026-77774 | 8.6 HIGH | Adobe Commerce | Incorrect Authorization (CWE-863) |
| CVE-2026-77109 | 8.6 HIGH | Adobe Commerce | Incorrect Authorization (CWE-863) |
| CVE-2026-75990 | 8.6 HIGH | Illustrator | Incorrect Authorization (CWE-863) |
| CVE-2026-75991 | 8.6 HIGH | Illustrator | Improper Input Validation (CWE-20) |
| CVE-2026-76190 | 8.6 HIGH | ColdFusion | Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval In |
| CVE-2026-76199 | 8.6 HIGH | Photoshop Desktop | Uncontrolled Search Path Element (CWE-427) |
| CVE-2026-75993 | 8.5 HIGH | ColdFusion | Cross-site Scripting (Reflected XSS) (CWE-79) |
| CVE-2026-75999 | 8.4 HIGH | ColdFusion | Improper Input Validation (CWE-20) |
| CVE-2026-76191 | 8.2 HIGH | Animate | Improper Control of Generation of Code ('Code Injection') (CWE-94) |
| CVE-2026-81994 | 8.2 HIGH | Acrobat Reader | Improperly Controlled Modification of Object Prototype Attributes ('Proto |
| CVE-2026-76202 | 8.2 HIGH | Adobe Commerce | Incorrect Authorization (CWE-863) |
| CVE-2026-81983 | 7.8 HIGH | Acrobat Reader | Out-of-bounds Write (CWE-787) |
| CVE-2026-79908 | 7.8 HIGH | Acrobat Reader | Out-of-bounds Write (CWE-787) |
Showing top 20 of 167 CVEs. View all on vendor page → →
No comments yet