Coldfusion 2023
This hub aggregates every CVE we track for Coldfusion 2023, a product in the consumer software space. Use it to gauge the current risk picture and drill into individual advisories.
29
CVEs tracked
10
Critical
13
High
0
In CISA KEV
Severity distribution
HIGH13CRITICAL10MEDIUM5LOW1
Monthly trend
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
13
16
2024-092026-08
Latest CVEs
The 15 most recently published vulnerabilities affecting Coldfusion 2023.
- CVE-2026-71387ColdFusion | Incorrect Authorization (CWE-863)8.8
- CVE-2026-48385ColdFusion | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') (CWE-78)7.7
- CVE-2026-71383ColdFusion | Incorrect Authorization (CWE-863)7.3
- CVE-2026-21279ColdFusion | Improper Input Validation (CWE-20)8.2
- CVE-2026-48384ColdFusion | Improper Input Validation (CWE-20)4.9
- CVE-2026-48375ColdFusion | Incorrect Authorization (CWE-863)6.5
- CVE-2026-21269ColdFusion | Cross-site Scripting (Stored XSS) (CWE-79)4.6
- CVE-2026-48376ColdFusion | Improper Encoding or Escaping of Output (CWE-116)5.4
- CVE-2026-48440ColdFusion | Heap-based Buffer Overflow (CWE-122)8.1
- CVE-2026-34635ColdFusion | Use of Hard-coded Cryptographic Key (CWE-321)8.4
- CVE-2026-48386ColdFusion | Use of a Broken or Risky Cryptographic Algorithm (CWE-327)7.5
- CVE-2026-48362ColdFusion | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') (CWE-78)10.0
- CVE-2026-71386ColdFusion | Cross-site Scripting (XSS) (CWE-79)8.8
- CVE-2026-71384ColdFusion | Incorrect Authorization (CWE-863)9.6
- CVE-2026-25652ColdFusion | Incorrect Authorization (CWE-863)7.8
Product normalization is registry-driven with AI assist and human review. How it works