Coldfusion
This hub aggregates every CVE we track for Coldfusion, a product in the consumer software space. Use it to gauge the current risk picture and drill into individual advisories.
283
CVEs tracked
75
Critical
90
High
17
In CISA KEV
Severity distribution
MEDIUM106HIGH90CRITICAL75LOW12
Monthly trend
2
0
0
1
0
0
0
15
8
0
13
1
1
0
0
11
0
0
0
7
0
17
16
16
2024-092026-08
Latest CVEs
The 15 most recently published vulnerabilities affecting Coldfusion.
- CVE-2026-71387ColdFusion | Incorrect Authorization (CWE-863)8.8
- CVE-2026-48385ColdFusion | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') (CWE-78)7.7
- CVE-2026-71383ColdFusion | Incorrect Authorization (CWE-863)7.3
- CVE-2026-21279ColdFusion | Improper Input Validation (CWE-20)8.2
- CVE-2026-48375ColdFusion | Incorrect Authorization (CWE-863)6.5
- CVE-2026-48384ColdFusion | Improper Input Validation (CWE-20)4.9
- CVE-2026-21269ColdFusion | Cross-site Scripting (Stored XSS) (CWE-79)4.6
- CVE-2026-48376ColdFusion | Improper Encoding or Escaping of Output (CWE-116)5.4
- CVE-2026-48440ColdFusion | Heap-based Buffer Overflow (CWE-122)8.1
- CVE-2026-34635ColdFusion | Use of Hard-coded Cryptographic Key (CWE-321)8.4
- CVE-2026-48386ColdFusion | Use of a Broken or Risky Cryptographic Algorithm (CWE-327)7.5
- CVE-2026-48362ColdFusion | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') (CWE-78)10.0
- CVE-2026-71384ColdFusion | Incorrect Authorization (CWE-863)9.6
- CVE-2026-71386ColdFusion | Cross-site Scripting (XSS) (CWE-79)8.8
- CVE-2026-25652ColdFusion | Incorrect Authorization (CWE-863)7.8
Product normalization is registry-driven with AI assist and human review. How it works