← Back to browse · API

CVE-2025-30285

Severity
HIGH
CVSS
8.4
EPSS
0.26691
Risk score
42.94
CISA KEV
No
PoC
No
Published
2025-04-08
Modified
2025-04-18
First seen
2026-08-07
Aliases
EUVD-2025-11914, GHSA-86H2-47XR-3W77
Products
Adobe:ColdFusion 0 ≤2025.0
Sources
euvd EUVD-2025-11914

Description

ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could result in arbitrary code execution in the context of the current user. A high-privileged attacker could leverage this vulnerability to bypass security protections and execute code. Exploitation of this issue requires user interaction and scope is changed.

References