Adobe ColdFusion
cpe:2.3:a:adobe:coldfusion:*:*:*:*:*:*:*
- <= 2025.6
- <= 2023.18
A vulnerability allowing arbitrary code execution has been identified in Adobe ColdFusion versions 2023.18, 2025.6 and earlier. This issue arises from improper input validation, and exploitation requires elevated privileges and user interaction, as a victim must open a malicious file.
Successful exploitation of this vulnerability could lead to arbitrary code execution in the context of the current user.
Users are advised to update to ColdFusion 2025 Update 7 or ColdFusion 2023 Update 19. For more information, refer to the Adobe ColdFusion downloads page and the respective ColdFusion Lockdown Guides.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.