← Back

Allaire

allaire

24 CVEs • 5 products

Products (5)

Click to collapse
Toggle
Spectra
spectra
Forums
forums
Clustercats
clustercats
Coldfusion
coldfusion

CVEs (24)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Allaire
1Spectra
Apr 16, 2026
Jan 1, 2000
N/A· v4
N/A· v3
7.5 HIGH· v2
The Remote Access Service invoke.cfm template in Allaire Spectra 1.0 allows users to bypass authentication via the bAuthenticated parameter.
1Allaire
1Coldfusion
Apr 16, 2026
Dec 31, 1999
N/A· v4
N/A· v3
7.5 HIGH· v2
HTTP Client application in ColdFusion allows remote attackers to bypass access restrictions for web pages on other ports by providing the target page to the mainframeset.cfm application, which requests the page from the...Show more
HTTP Client application in ColdFusion allows remote attackers to bypass access restrictions for web pages on other ports by providing the target page to the mainframeset.cfm application, which requests the page from the server, making it look like the request is coming from the local host.Show less
1Allaire
1Coldfusion Server
Apr 16, 2026
Dec 25, 1999
N/A· v4
N/A· v3
7.5 HIGH· v2
The Expression Evaluator in the ColdFusion Application Server allows a remote attacker to upload files to the server via openfile.cfm, which does not restrict access to the server properly.
1Allaire
1Coldfusion Server
Apr 16, 2026
Dec 25, 1999
N/A· v4
N/A· v3
7.5 HIGH· v2
The Expression Evaluator sample application in ColdFusion allows remote attackers to read or delete files on the server via exprcalc.cfm, which does not restrict access to the server properly.