PT-2025-50286 · Adobe · Coldfusion

Published

2025-12-09

·

Updated

2026-04-28

·

CVE-2025-61813

CVSS v3.1

8.6

High

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions ColdFusion versions 2025.4, 2023.16, and 2021.22 and earlier
Description ColdFusion is affected by an Improper Restriction of XML External Entity Reference ('XXE') issue that could allow an attacker to read arbitrary files from the system. Exploitation of this issue does not require user interaction. The scope of the issue has been changed.
Recommendations Update ColdFusion to a version later than 2021.22. Update ColdFusion to a version later than 2023.16. Update ColdFusion to a version later than 2025.4.

Fix

XXE

Weakness Enumeration

Related Identifiers

BDU:2025-15506
CVE-2025-61813

Affected Products

Coldfusion