Impact
ColdFusion versions 2023.19, 2025.8 and earlier contain a stored Cross‑Site Scripting (XSS) vulnerability that could be abused by a low‑privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. The vulnerable component is restricted to an administrative network zone by default, and the scope is changed. This weakness is a classic input validation flaw (CWE‑79).
Affected Systems
Adobe ColdFusion versions 2023.19, 2025.8 and earlier are affected; the flaw is present in all installations of these versions that expose form input to the internet.
Risk and Exploitability
The CVSS score of 4.8 indicates a low‑to‑moderate severity, and the EPSS score is less than 1% but the vulnerability is not listed in the CISA KEV catalog. A likely attack vector, inferred from the description, involves a low‑privileged attacker embedding JavaScript into a form field that is then stored and served to end users; the default administrative network restriction reduces exposure, but the changed scope means that compromised credentials could affect all users with access to the affected system.
OpenCVE Enrichment