Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

ColdFusion — Vulnerabilities & Security Advisories 110

All 110 CVE vulnerabilities found in ColdFusion, with AI-generated Chinese analysis, references, and POCs.

This page aggregates security vulnerabilities associated with Adobe ColdFusion, categorized by specific weakness types and vendor advisories. It collects known defects in the product, covering a historical time range that spans from early releases through recent patches issued by Adobe. Here, you can track the vendor's advisory releases, analyze the recurring weakness classes affecting the application server, and review the complete vulnerability history for ColdFusion. The data highlights common issues such as remote code execution, cross-site scripting, and information disclosure, providing a structured view of how the product’s security posture has evolved over time. This resource is intended for security analysts and developers who need to assess risk, prioritize patching, or audit the stability of systems running this software. By consolidating these records, the page offers a clear reference for understanding the patterns of failure in ColdFusion and the corresponding fixes released by the vendor. No individual CVE identifiers are listed, allowing focus on the broader trends rather than isolated incidents. This aggregation serves as a neutral reference for compliance and security planning.

Vendor: Adobe

CVE ID Title CVSS Severity Published
CVE-2025-43564 ColdFusion | Incorrect Authorization (CWE-863) CWE-863 9.1 Critical 2025-05-13
CVE-2025-43563 ColdFusion | Improper Access Control (CWE-284) CWE-284 9.1 Critical 2025-05-13
CVE-2025-43560 ColdFusion | Improper Input Validation (CWE-20) CWE-20 9.1 Critical 2025-05-13
CVE-2025-43561 ColdFusion | Incorrect Authorization (CWE-863) CWE-863 9.1 Critical 2025-05-13
CVE-2025-30293 ColdFusion | Improper Input Validation (CWE-20) CWE-20 6.8 Medium 2025-04-08
CVE-2025-30287 ColdFusion | Improper Authentication (CWE-287) CWE-287 8.2 High 2025-04-08
CVE-2025-30292 ColdFusion | Cross-site Scripting (Reflected XSS) (CWE-79) CWE-79 6.1 Medium 2025-04-08
CVE-2025-30290 ColdFusion | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) CWE-22 8.7 High 2025-04-08
CVE-2025-30282 ColdFusion | Improper Authentication (CWE-287) CWE-287 9.1 Critical 2025-04-08
CVE-2025-30284 ColdFusion | Deserialization of Untrusted Data (CWE-502) CWE-502 8.4 High 2025-04-08
CVE-2025-30294 ColdFusion | Improper Input Validation (CWE-20) CWE-20 6.8 Medium 2025-04-08
CVE-2025-30289 ColdFusion | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') (CWE-78) CWE-78 8.2 High 2025-04-08
CVE-2025-30288 ColdFusion | Improper Access Control (CWE-284) CWE-284 8.2 High 2025-04-08
CVE-2025-24446 ColdFusion | Improper Input Validation (CWE-20) CWE-20 9.1 Critical 2025-04-08
CVE-2025-24447 ColdFusion | Deserialization of Untrusted Data (CWE-502) CWE-502 9.1 Critical 2025-04-08
CVE-2025-30281 ColdFusion | Improper Access Control (CWE-284) CWE-284 9.1 Critical 2025-04-08
CVE-2025-30291 ColdFusion | Information Exposure (CWE-200) CWE-200 5.5 Medium 2025-04-08
CVE-2025-30285 ColdFusion | Deserialization of Untrusted Data (CWE-502) CWE-502 8.4 High 2025-04-08
CVE-2025-30286 ColdFusion | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') (CWE-78) CWE-78 8.4 High 2025-04-08
CVE-2024-53961 ColdFusion | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) CWE-22 8.1 High 2024-12-23
CVE-2024-41874 ColdFusion | Deserialization of Untrusted Data (CWE-502) CWE-502 9.8 Critical 2024-09-13
CVE-2024-45113 ColdFusion | Improper Authentication (CWE-287) CWE-287 7.5 High 2024-09-13
CVE-2024-34112 ColdFusion CFDOCUMENT file retrieval / access control bypass CWE-284 7.5 High 2024-06-13
CVE-2024-34113 ColdFusion | Weak Cryptography for Passwords (CWE-261) CWE-261 5.5 Medium 2024-06-13
CVE-2024-20767 ColdFusion | Improper Access Control (CWE-284) CWE-284 7.4 High 2024-03-18
CVE-2023-44351 Adobe ColdFusion RCE Security Vulnerability CWE-502 9.8 Critical 2023-11-17
CVE-2023-44355 ColdFusion | Improper Input Validation (CWE-20) CWE-20 4.3 Medium 2023-11-17
CVE-2023-26347 CVE-2023-38205 issues | ColdFusion Admin Panel Access CWE-284 7.5 High 2023-11-17
CVE-2023-44352 Unauthenticate Reflected XSS on Adobe Coldfusion 2018 - 2021 - 2023 last version CWE-79 6.1 Medium 2023-11-17
CVE-2023-44353 ColdFusion WDDX Deserialization Gadgets CWE-502 9.8 Critical 2023-11-17

All 110 known CVE vulnerabilities affecting ColdFusion with full Chinese analysis, references, and POCs where available.