Known vulnerabilities in ColdFusion 2021 Update 20 - page 4

Vendor: Adobe
Software: ColdFusion
Version: 2021 Update 20
Software CPE: cpe:2.3:a:adobe:coldfusion:*:*:*:*:*:*:*:*
Total vulnerabilities: 66
Public exploits: 0
Known exploited (KEV): 1
Highest CVSSv4 Score: 9.3

Vulnerabilities by Severity

Severity distribution of vulnerabilities affecting ColdFusion version 2021 Update 20 ColdFusion 2021 Update 20 is affected by 66 vulnerabilities: 6 critical, 16 high, 21 medium, 23 low Critical High Medium Low

Vulnerabilities (66)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU112614 - Improper Access Control
CVE-2025-49546
CWE-284 Low
No
No
2021 Update 21, 2023 Update 15, 2025 Update 3 09.07.2025 SB2025070955
#VU112613 - Server-Side Request Forgery (SSRF)
CVE-2025-49545
CWE-918 Medium
No
No
2021 Update 21, 2023 Update 15, 2025 Update 3 09.07.2025 SB2025070955
#VU112612 - Improper Restriction of XML External Entity Reference ('XXE')
CVE-2025-49544
CWE-611 Medium
No
No
2021 Update 21, 2023 Update 15, 2025 Update 3 09.07.2025 SB2025070955
#VU112610 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2025-49542
CWE-79 Low
No
No
2021 Update 21, 2023 Update 15, 2025 Update 3 09.07.2025 SB2025070955
#VU112611 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2025-49543
CWE-79 Low
No
No
2021 Update 21, 2023 Update 15, 2025 Update 3 09.07.2025 SB2025070955
#VU112593 - Improper Restriction of XML External Entity Reference ('XXE')
CVE-2025-49535
CWE-611 High
No
No
2021 Update 21, 2023 Update 15, 2025 Update 3 09.07.2025 SB2025070955


Showing elements 61 - 80 out of 66