Vulnerability Database

289,697

Total vulnerabilities in the database

CVE-2025-30288

ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. A low privileged attacker with local access could leverage this vulnerability to bypass security protections and execute code. Exploitation of this issue requires user interaction in that a victim must be coerced into performing actions within the application and scope is changed.

  • Published: Apr 8, 2025
  • Updated: Apr 30, 2025
  • CVE: CVE-2025-30288
  • Severity: High
  • Exploit:

CVSS v3:

  • Severity: High
  • Score: 8.2
  • AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H

No CWE or OWASP classifications available.

Software From Fixed in
adobe / coldfusion 2021 2021.x
adobe / coldfusion 2021-update1 2021-update1.x
adobe / coldfusion 2021-update2 2021-update2.x
adobe / coldfusion 2021-update3 2021-update3.x
adobe / coldfusion 2021-update4 2021-update4.x
adobe / coldfusion 2021-update5 2021-update5.x
adobe / coldfusion 2021-update10 2021-update10.x
adobe / coldfusion 2021-update11 2021-update11.x
adobe / coldfusion 2021-update6 2021-update6.x
adobe / coldfusion 2021-update7 2021-update7.x
adobe / coldfusion 2021-update8 2021-update8.x
adobe / coldfusion 2021-update9 2021-update9.x
adobe / coldfusion 2023 2023.x
adobe / coldfusion 2023-update1 2023-update1.x
adobe / coldfusion 2023-update2 2023-update2.x
adobe / coldfusion 2023-update3 2023-update3.x
adobe / coldfusion 2023-update4 2023-update4.x
adobe / coldfusion 2023-update5 2023-update5.x
adobe / coldfusion 2021-update12 2021-update12.x
adobe / coldfusion 2021-update13 2021-update13.x
adobe / coldfusion 2021-update14 2021-update14.x
adobe / coldfusion 2021-update15 2021-update15.x
adobe / coldfusion 2021-update16 2021-update16.x
adobe / coldfusion 2021-update17 2021-update17.x
adobe / coldfusion 2021-update18 2021-update18.x
adobe / coldfusion 2023-update10 2023-update10.x
adobe / coldfusion 2023-update11 2023-update11.x
adobe / coldfusion 2023-update12 2023-update12.x
adobe / coldfusion 2023-update6 2023-update6.x
adobe / coldfusion 2023-update7 2023-update7.x
adobe / coldfusion 2023-update8 2023-update8.x
adobe / coldfusion 2023-update9 2023-update9.x
adobe / coldfusion 2025 2025.x