← Back to browse · API

CVE-2025-30281

Severity
CRITICAL
CVSS
9.1
EPSS
0.20264
Risk score
43.49
CISA KEV
No
PoC
No
Published
2025-04-08
Modified
2025-06-24
First seen
2026-08-07
Aliases
EUVD-2025-14807, GHSA-R3M2-P27F-8635
Products
Adobe:ColdFusion 0 ≤2025.0
Sources
euvd EUVD-2025-14807

Description

ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by an Improper Access Control vulnerability that could result in arbitrary code execution. A high-privileged attacker could leverage this vulnerability to access or modify sensitive data without proper authorization. Exploitation of this issue does not require user interaction, and scope is changed.

References