Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

ColdFusion — Vulnerabilities & Security Advisories 110

All 110 CVE vulnerabilities found in ColdFusion, with AI-generated Chinese analysis, references, and POCs.

This page aggregates security vulnerabilities associated with Adobe ColdFusion, categorized by specific weakness types and vendor advisories. It collects known defects in the product, covering a historical time range that spans from early releases through recent patches issued by Adobe. Here, you can track the vendor's advisory releases, analyze the recurring weakness classes affecting the application server, and review the complete vulnerability history for ColdFusion. The data highlights common issues such as remote code execution, cross-site scripting, and information disclosure, providing a structured view of how the product’s security posture has evolved over time. This resource is intended for security analysts and developers who need to assess risk, prioritize patching, or audit the stability of systems running this software. By consolidating these records, the page offers a clear reference for understanding the patterns of failure in ColdFusion and the corresponding fixes released by the vendor. No individual CVE identifiers are listed, allowing focus on the broader trends rather than isolated incidents. This aggregation serves as a neutral reference for compliance and security planning.

Vendor: Adobe

CVE ID Title CVSS Severity Published
CVE-2025-61808 ColdFusion | Unrestricted Upload of File with Dangerous Type (CWE-434) CWE-434 9.1 Critical 2025-12-09
CVE-2025-61813 ColdFusion | Improper Restriction of XML External Entity Reference ('XXE') (CWE-611) CWE-611 7.4 High 2025-12-09
CVE-2025-61812 ColdFusion | Improper Input Validation (CWE-20) CWE-20 8.4 High 2025-12-09
CVE-2025-64898 ColdFusion | Insufficiently Protected Credentials (CWE-522) CWE-522 5.3 Medium 2025-12-09
CVE-2025-61821 ColdFusion | Improper Restriction of XML External Entity Reference ('XXE') (CWE-611) CWE-611 6.8 Medium 2025-12-09
CVE-2025-61810 ColdFusion | Deserialization of Untrusted Data (CWE-502) CWE-502 8.4 High 2025-12-09
CVE-2025-61809 ColdFusion | Improper Input Validation (CWE-20) CWE-20 9.1 Critical 2025-12-09
CVE-2025-61822 ColdFusion | Improper Input Validation (CWE-20) CWE-20 6.2 Medium 2025-12-09
CVE-2025-64897 ColdFusion | Improper Access Control (CWE-284) CWE-284 5.6 Medium 2025-12-09
CVE-2025-61823 ColdFusion | Improper Restriction of XML External Entity Reference ('XXE') (CWE-611) CWE-611 6.2 Medium 2025-12-09
CVE-2025-61811 ColdFusion | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) CWE-22 9.1 Critical 2025-12-09
CVE-2025-54261 ColdFusion | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) CWE-22 10.0 Critical 2025-09-09
CVE-2025-54234 ColdFusion | Server-Side Request Forgery (SSRF) (CWE-918) CWE-918 2.7 Low 2025-08-18
CVE-2025-49535 ColdFusion | Improper Restriction of XML External Entity Reference ('XXE') (CWE-611) CWE-611 9.3 Critical 2025-07-08
CVE-2025-49542 ColdFusion | Cross-site Scripting (Reflected XSS) (CWE-79) CWE-79 5.2 Medium 2025-07-08
CVE-2025-49539 ColdFusion | Improper Restriction of XML External Entity Reference ('XXE') (CWE-611) CWE-611 4.5 Medium 2025-07-08
CVE-2025-49536 ColdFusion | Incorrect Authorization (CWE-863) CWE-863 7.3 High 2025-07-08
CVE-2025-49545 ColdFusion | Server-Side Request Forgery (SSRF) (CWE-918) CWE-918 6.2 Medium 2025-07-08
CVE-2025-49541 ColdFusion | Cross-site Scripting (Stored XSS) (CWE-79) CWE-79 4.3 Medium 2025-07-08
CVE-2025-49537 ColdFusion | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') (CWE-78) CWE-78 7.9 High 2025-07-08
CVE-2025-49551 ColdFusion | Use of Hard-coded Credentials (CWE-798) CWE-798 8.8 High 2025-07-08
CVE-2025-49546 ColdFusion | Improper Access Control (CWE-284) CWE-284 2.4 Low 2025-07-08
CVE-2025-49544 ColdFusion | Improper Restriction of XML External Entity Reference ('XXE') (CWE-611) CWE-611 6.8 Medium 2025-07-08
CVE-2025-49543 ColdFusion | Cross-site Scripting (Stored XSS) (CWE-79) CWE-79 4.3 Medium 2025-07-08
CVE-2025-49540 ColdFusion | Cross-site Scripting (Stored XSS) (CWE-79) CWE-79 4.3 Medium 2025-07-08
CVE-2025-49538 ColdFusion | XML Injection (aka Blind XPath Injection) (CWE-91) CWE-91 7.4 High 2025-07-08
CVE-2025-43565 ColdFusion | Incorrect Authorization (CWE-863) CWE-863 8.4 High 2025-05-13
CVE-2025-43559 ColdFusion | Improper Input Validation (CWE-20) CWE-20 9.1 Critical 2025-05-13
CVE-2025-43562 ColdFusion | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') (CWE-78) CWE-78 9.1 Critical 2025-05-13
CVE-2025-43566 ColdFusion | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) CWE-22 6.8 Medium 2025-05-13

All 110 known CVE vulnerabilities affecting ColdFusion with full Chinese analysis, references, and POCs where available.