← Back

Coldfusion

coldfusion

Vendor: Adobe • 241 CVEs

CVEs (241)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Adobe
1Coldfusion
Jun 17, 2026
Jun 12, 2019
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
ColdFusion versions Update 3 and earlier, Update 10 and earlier, and Update 18 and earlier have a deserialization of untrusted data vulnerability. Successful exploitation could lead to arbitrary code execution.
1Adobe
1Coldfusion
Jun 17, 2026
Jun 12, 2019
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
ColdFusion versions Update 3 and earlier, Update 10 and earlier, and Update 18 and earlier have a command injection vulnerability. Successful exploitation could lead to arbitrary code execution.
1Adobe
1Coldfusion
Jun 17, 2026
Jun 12, 2019
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
ColdFusion versions Update 3 and earlier, Update 10 and earlier, and Update 18 and earlier have a file extension blacklist bypass vulnerability. Successful exploitation could lead to arbitrary code execution.
1Adobe
1Coldfusion
Jun 17, 2026
May 24, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
ColdFusion versions Update 1 and earlier, Update 7 and earlier, and Update 15 and earlier have a cross site scripting vulnerability. Successful exploitation could lead to information disclosure .
1Adobe
1Coldfusion
Jun 17, 2026
May 24, 2019
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
ColdFusion versions Update 1 and earlier, Update 7 and earlier, and Update 15 and earlier have a deserialization of untrusted data vulnerability. Successful exploitation could lead to arbitrary code execution.
1Adobe
1Coldfusion
Jun 17, 2026
May 24, 2019
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
ColdFusion versions Update 2 and earlier, Update 9 and earlier, and Update 17 and earlier have a file upload restriction bypass vulnerability. Successful exploitation could lead to arbitrary code execution.
1Adobe
1Coldfusion
May 6, 2025
Sep 25, 2018
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have a deserialization of untrusted data vulnerability. Successful exploitation could lead to arbitrary code ex...Show more
Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have a deserialization of untrusted data vulnerability. Successful exploitation could lead to arbitrary code execution.Show less
1Adobe
1Coldfusion
May 6, 2025
Sep 25, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have a use of a component with a known vulnerability vulnerability. Successful exploitation could lead to infor...Show more
Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have a use of a component with a known vulnerability vulnerability. Successful exploitation could lead to information disclosure.Show less
1Adobe
1Coldfusion
May 6, 2025
Sep 25, 2018
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have a security bypass vulnerability. Successful exploitation could lead to arbitrary folder creation.
1Adobe
1Coldfusion
May 6, 2025
Sep 25, 2018
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have a directory listing vulnerability. Successful exploitation could lead to information disclosure.
1Adobe
1Coldfusion
Oct 23, 2025
Sep 25, 2018
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have an unrestricted file upload vulnerability. Successful exploitation could lead to arbitrary code execution.
1Adobe
1Coldfusion
Nov 21, 2024
Sep 25, 2018
N/A· v4
7.5 HIGH· v3
6.4 MEDIUM· v2
Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have a use of a component with a known vulnerability vulnerability. Successful exploitation could lead to arbit...Show more
Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have a use of a component with a known vulnerability vulnerability. Successful exploitation could lead to arbitrary file overwrite.Show less
1Adobe
1Coldfusion
May 6, 2025
Sep 25, 2018
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have a deserialization of untrusted data vulnerability. Successful exploitation could lead to arbitrary code ex...Show more
Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have a deserialization of untrusted data vulnerability. Successful exploitation could lead to arbitrary code execution.Show less
1Adobe
1Coldfusion
May 6, 2025
Sep 25, 2018
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have a deserialization of untrusted data vulnerability. Successful exploitation could lead to arbitrary code ex...Show more
Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have a deserialization of untrusted data vulnerability. Successful exploitation could lead to arbitrary code execution.Show less
1Adobe
1Coldfusion
May 6, 2025
Sep 25, 2018
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have a deserialization of untrusted data vulnerability. Successful exploitation could lead to arbitrary code ex...Show more
Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have a deserialization of untrusted data vulnerability. Successful exploitation could lead to arbitrary code execution.Show less
1Adobe
1Coldfusion
May 6, 2025
May 19, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Adobe ColdFusion Update 5 and earlier versions, ColdFusion 11 Update 13 and earlier versions have an exploitable Unsafe XML External Entity Processing vulnerability. Successful exploitation could lead to information disc...Show more
Adobe ColdFusion Update 5 and earlier versions, ColdFusion 11 Update 13 and earlier versions have an exploitable Unsafe XML External Entity Processing vulnerability. Successful exploitation could lead to information disclosure.Show less
1Adobe
1Coldfusion
Nov 21, 2024
May 19, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Adobe ColdFusion Update 5 and earlier versions, ColdFusion 11 Update 13 and earlier versions have an exploitable Cross-Site Scripting vulnerability. Successful exploitation could lead to information disclosure.
1Adobe
1Coldfusion
Nov 21, 2024
May 19, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Adobe ColdFusion Update 5 and earlier versions, ColdFusion 11 Update 13 and earlier versions have an exploitable Cross-Site Scripting vulnerability. Successful exploitation could lead to information disclosure.
1Adobe
1Coldfusion
Oct 23, 2025
May 19, 2018
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Adobe ColdFusion Update 5 and earlier versions, ColdFusion 11 Update 13 and earlier versions have an exploitable Deserialization of Untrusted Data vulnerability. Successful exploitation could lead to arbitrary code execu...Show more
Adobe ColdFusion Update 5 and earlier versions, ColdFusion 11 Update 13 and earlier versions have an exploitable Deserialization of Untrusted Data vulnerability. Successful exploitation could lead to arbitrary code execution.Show less
1Adobe
1Coldfusion
May 6, 2025
May 19, 2018
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
Adobe ColdFusion Update 5 and earlier versions, ColdFusion 11 Update 13 and earlier versions have an exploitable Insecure Library Loading vulnerability. Successful exploitation could lead to local privilege escalation.