Impact
ColdFusion is affected by a stored Cross‑Site Scripting (XSS) vulnerability that could be abused by a low‑privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. The scope of the vulnerability is changed.
Affected Systems
Adobe ColdFusion 2023 and Adobe ColdFusion 2025 are affected. The CVE entry does not list specific patch versions; therefore any installation of these major releases is considered at risk until a vendor patch is applied.
Risk and Exploitability
The CVSS score of 4.6 indicates moderate severity, and the EPSS score of less than 1% shows a low probability of exploitation. The vulnerability is not currently in CISA’s KEV catalog. Attackers can exploit the flaw by submitting malicious input through a form; the payload is stored and executed when a user visits the page. The impact is limited to the victim’s browser and does not provide remote code execution on the server.
OpenCVE Enrichment