Adobe ColdFusion
cpe:2.3:a:adobe:coldfusion:*:*:*:*:*:*:*
- <= 2025.1
- <= 2023.13
- <= 2021.19
A vulnerability allowing arbitrary code execution has been identified in Adobe ColdFusion versions 2025.1, 2023.13, and 2021.19 and earlier. This issue arises from improper input validation, which could enable a high-privileged attacker to bypass security mechanisms and execute code in the context of the current user. Notably, exploitation of this vulnerability does not require user interaction, and it alters the scope of the attack.
Successful exploitation allows for arbitrary code execution in the context of the current user.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.