Impact
Adobe ColdFusion 2023 and 2025 contain a stored cross‑site scripting flaw that allows a low‑privileged attacker to inject malicious JavaScript via vulnerable form fields. When a victim or administrator views the affected page, the injected script runs in their browser, potentially enabling credential theft, session hijacking, or further web‑based attacks. The weakness is a stored XSS vulnerability (CWE‑79).
Affected Systems
Adobe ColdFusion 2023 and Adobe ColdFusion 2025 are affected. The CVE entry does not list specific patch versions; therefore any installation of these major releases is considered at risk until a vendor patch is applied.
Risk and Exploitability
The CVSS score of 4.6 indicates moderate severity, and the EPSS score of less than 1 % shows a low probability of exploitation. The vulnerability is not currently in CISA’s KEV catalog. Attackers can exploit the flaw by submitting malicious input through a form; the payload is stored and executed when a user visits the page. The impact is limited to the victim’s browser and does not provide remote code execution on the server.
OpenCVE Enrichment