Coldfusion
This hub aggregates every CVE we track for Coldfusion, a product in the consumer software space. Use it to gauge the current risk picture and drill into individual advisories.
292
CVEs tracked
77
Critical
95
High
17
In CISA KEV
Severity distribution
MEDIUM108HIGH95CRITICAL77LOW12
Monthly trend
0
0
1
0
0
0
15
8
0
13
1
1
0
0
11
0
0
0
7
0
17
16
16
9
2024-102026-09
Latest CVEs
The 15 most recently published vulnerabilities affecting Coldfusion.
- CVE-2026-75746ColdFusion | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') (CWE-89)9.1
- CVE-2026-76002ColdFusion | Cross-site Scripting (Reflected XSS) (CWE-79)6.1
- CVE-2026-76000ColdFusion | Uncontrolled Resource Consumption (CWE-400)6.5
- CVE-2026-75998ColdFusion | Improper Access Control (CWE-284)7.5
- CVE-2026-76190ColdFusion | Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') (CWE-95)8.6
- CVE-2026-48273ColdFusion | Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') (CWE-95)9.9
- CVE-2026-75999ColdFusion | Improper Input Validation (CWE-20)8.4
- CVE-2026-75993ColdFusion | Cross-site Scripting (Reflected XSS) (CWE-79)8.5
- CVE-2026-83961ColdFusion | Improper Authentication (CWE-287)7.1
- CVE-2026-71387ColdFusion | Incorrect Authorization (CWE-863)8.8
- CVE-2026-48385ColdFusion | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') (CWE-78)7.7
- CVE-2026-71383ColdFusion | Incorrect Authorization (CWE-863)7.3
- CVE-2026-21279ColdFusion | Improper Input Validation (CWE-20)8.2
- CVE-2026-48375ColdFusion | Incorrect Authorization (CWE-863)6.5
- CVE-2026-48384ColdFusion | Improper Input Validation (CWE-20)4.9
Product normalization is registry-driven with AI assist and human review. How it works