Description
is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. Scope is changed.
Published: 2026-08-11
Score: 4.6 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Adobe ColdFusion 2023 and 2025 contain a stored cross‑site scripting flaw that allows a low‑privileged attacker to inject malicious JavaScript via vulnerable form fields. When a victim or administrator views the affected page, the injected script runs in their browser, potentially enabling credential theft, session hijacking, or further web‑based attacks. The weakness is a stored XSS vulnerability (CWE‑79).

Affected Systems

Adobe ColdFusion 2023 and Adobe ColdFusion 2025 are affected. The CVE entry does not list specific patch versions; therefore any installation of these major releases is considered at risk until a vendor patch is applied.

Risk and Exploitability

The CVSS score of 4.6 indicates moderate severity, and the EPSS score of less than 1 % shows a low probability of exploitation. The vulnerability is not currently in CISA’s KEV catalog. Attackers can exploit the flaw by submitting malicious input through a form; the payload is stored and executed when a user visits the page. The impact is limited to the victim’s browser and does not provide remote code execution on the server.

Generated by OpenCVE AI on August 12, 2026 at 21:02 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Adobe ColdFusion security patch that addresses the stored XSS vulnerability (refer to Adobe Security Advisory APSB26‑90).
  • If a patch is not yet available, sanitize or encode the input on the vulnerable form fields to prevent JavaScript execution.
  • Configure a strict Content Security Policy (CSP) on the web server to restrict script execution from untrusted sources.

Generated by OpenCVE AI on August 12, 2026 at 21:02 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 13 Aug 2026 05:30:00 +0000

Type Values Removed Values Added
First Time appeared Adobe
Adobe coldfusion 2023
Adobe coldfusion 2025
Vendors & Products Adobe
Adobe coldfusion 2023
Adobe coldfusion 2025

Tue, 11 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 11 Aug 2026 17:00:00 +0000

Type Values Removed Values Added
Description is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. Scope is changed.
Title ColdFusion | Cross-site Scripting (Stored XSS) (CWE-79)
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 4.6, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'}


Subscriptions

Adobe Coldfusion 2023 Coldfusion 2025
cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2026-08-11T17:51:39.189Z

Reserved: 2025-12-12T22:01:18.187Z

Link: CVE-2026-21269

cve-icon Vulnrichment

Updated: 2026-08-11T17:51:33.903Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-11T17:17:55.020

Modified: 2026-08-12T21:03:43.743

Link: CVE-2026-21269

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T05:15:03Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')