CVE 9.1 CRITICAL

ColdFusion | Improper Input Validation (CWE-20)_CVE-2025-61809

9.1 / 10
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Description

ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized read and write access. Exploitation of this issue does not require user interaction and scope is unchanged.

AI Analysis

Improper Input Validation vulnerability allowing security feature bypass and unauthorized access

Basic Information

ID CVE-2025-61809
Source adobe
Published Dec 9, 2025 at 23:41

Affected Product

Vendor Adobe
Product ColdFusion
Affected Versions Adobe ColdFusion 0

CWE Classification

AI Assessment

AI Score 9.1 / 10
AI Severity Critical
Vendor Adobe
Product ColdFusion
Version 2025.4, 2023.16, 2021.22 and earlier

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.