PT-2025-50287 · Adobe · Coldfusion

Published

2025-12-09

·

Updated

2025-12-10

·

CVE-2025-61821

CVSS v3.1

8.6

High

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions ColdFusion versions 2025.4, 2023.16, and 2021.22 and earlier
Description ColdFusion is affected by an Improper Restriction of XML External Entity Reference ('XXE') issue that could allow an attacker to read arbitrary files from the system. An attacker could exploit this to access sensitive files and data on the server. Exploitation of this issue does not require user interaction.
Recommendations Update ColdFusion to a version later than 2021.22.

Fix

XXE

Weakness Enumeration

Related Identifiers

BDU:2025-15474
CVE-2025-61821

Affected Products

Coldfusion