CVE-2026-48307
Severity CVSS v4.0:
Pending analysis
Type:
CWE-79
Cross-Site Scripting (XSS)
Publication date:
30/06/2026
Last modified:
01/07/2026
Description
ColdFusion versions 2025.9, 2023.20 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this vulnerability to inject malicious scripts into a web page, potentially resulting in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious link. Scope is changed.
Impact
Base Score 3.x
8.80
Severity 3.x
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:adobe:coldfusion:2023:-:*:*:*:*:*:* | ||
| cpe:2.3:a:adobe:coldfusion:2023:update1:*:*:*:*:*:* | ||
| cpe:2.3:a:adobe:coldfusion:2023:update10:*:*:*:*:*:* | ||
| cpe:2.3:a:adobe:coldfusion:2023:update11:*:*:*:*:*:* | ||
| cpe:2.3:a:adobe:coldfusion:2023:update12:*:*:*:*:*:* | ||
| cpe:2.3:a:adobe:coldfusion:2023:update13:*:*:*:*:*:* | ||
| cpe:2.3:a:adobe:coldfusion:2023:update14:*:*:*:*:*:* | ||
| cpe:2.3:a:adobe:coldfusion:2023:update15:*:*:*:*:*:* | ||
| cpe:2.3:a:adobe:coldfusion:2023:update16:*:*:*:*:*:* | ||
| cpe:2.3:a:adobe:coldfusion:2023:update17:*:*:*:*:*:* | ||
| cpe:2.3:a:adobe:coldfusion:2023:update18:*:*:*:*:*:* | ||
| cpe:2.3:a:adobe:coldfusion:2023:update19:*:*:*:*:*:* | ||
| cpe:2.3:a:adobe:coldfusion:2023:update2:*:*:*:*:*:* | ||
| cpe:2.3:a:adobe:coldfusion:2023:update20:*:*:*:*:*:* | ||
| cpe:2.3:a:adobe:coldfusion:2023:update3:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page


