Vulnerabilities
Vulnerable Software
Adobe:  >> Coldfusion  >> 2025  Security Vulnerabilities
ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could result in arbitrary code execution in the context of the current user resulting in a High impact to Confidentiality and Integrity. Exploitation of this issue does not require user interaction.
CVSS Score
9.1
EPSS Score
0.019
Published
2025-04-08
Cross-site scripting (XSS) vulnerability in Adobe ColdFusion before 9.0.1 CHF1 allows remote attackers to inject arbitrary web script or HTML via the User-Agent HTTP header in an id=- query to a .cfm file.
CVSS Score
4.3
EPSS Score
0.041
Published
2011-02-01


Contact Us

Shodan ® - All rights reserved