Vulnerability Database

296,855

Total vulnerabilities in the database

CVE-2025-54234

ColdFusion versions 2025.1, 2023.13, 2021.19 and earlier are affected by a Server-Side Request Forgery (SSRF) vulnerability that could lead to limited file system read. A high-privilege authenticated attacker can force the application to make arbitrary requests via injection of arbitrary URLs. Exploitation of this issue does not require user interaction.

  • Published: Aug 18, 2025
  • Updated: Aug 19, 2025
  • CVE: CVE-2025-54234
  • Severity: Low
  • Exploit:

CVSS v3:

  • Severity: Low
  • Score: 2.2
  • AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:N

CWEs: