Known Vulnerabilities for Coldfusion by Macromedia

Listed below are 10 of the newest known vulnerabilities associated with "Coldfusion" by "Macromedia".

These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.

Data on known vulnerable versions is also displayed based on information from known CPEs

Known Vulnerabilities

CVE Shortened Description Severity Publish Date Last Modified
CVE-2006-3979 The AdminAPI of ColdFusion MX 7 allows attackers to bypass authentication by using "programmatic access" to the adminAPI inst... 7.2 - HIGH 2006-08-09 2017-07-20
CVE-2006-2364 Cross-site scripting (XSS) vulnerability in the validation feature in Macromedia ColdFusion 5 and earlier allows remote attac... 5.8 - MEDIUM 2006-05-15 2017-07-20
CVE-2005-4345 Adobe (formerly Macromedia) ColdFusion MX 7.0 exposes the password hash of the Administrator in an API call, which allows loc... 7.2 - HIGH 2005-12-19 2011-03-08
CVE-2005-4344 Adobe (formerly Macromedia) ColdFusion MX 7.0 does not honor when the CFOBJECT /CreateObject(Java) setting is disabled, which... 2.1 - LOW 2005-12-19 2011-03-08
CVE-2005-4343 Adobe (formerly Macromedia) ColdFusion MX 6.0, 6.1, 6.1 with JRun, and 7.0 allows remote attackers to attach arbitrary files ... 5 - MEDIUM 2005-12-19 2011-03-08
CVE-2005-4342 ColdFusion Sandbox on Adobe (formerly Macromedia) ColdFusion MX 6.0, 6.1, 6.1 with JRun, and 7.0 does not throw an exception ... 7.5 - HIGH 2005-12-19 2011-03-08
CVE-2005-2306 Race condition in Macromedia JRun 4.0, ColdFusion MX 6.1 and 7.0, when under heavy load, causes JRun to assign a duplicate au... 3.7 - LOW 2005-07-19 2008-09-05
CVE-2005-1555 Cross-site scripting (XSS) vulnerability in the JRun Web Server in ColdFusion MX 7.0 allows remote attackers to inject arbitr... 4.3 - MEDIUM 2005-05-10 2017-07-11
CVE-2005-1022 ColdFusion 6.1 Updater 1 places Java .class files under the web root in the /WEB-INF/cfclasses directory, which allows remote... 5 - MEDIUM 2005-05-02 2016-10-18
CVE-2004-0407 The HTML form upload capability in ColdFusion MX 6.1 does not reclaim disk space if an upload is interrupted, which allows re... 2.6 - LOW 2004-06-01 2017-07-11

Known Affected Configurations (CPE V2.3)

Type Vendor Product Version Update Edition Language
ApplicationMacromediaColdfusion7.02AllAllAll
ApplicationMacromediaColdfusion7.0AllAllAll
ApplicationMacromediaColdfusion6.1AllAllAll
ApplicationMacromediaColdfusion6.0AllAllAll
ApplicationMacromediaColdfusion5.0AllAllAll
ApplicationMacromediaColdfusion4.5.1sp2AllAll
ApplicationMacromediaColdfusion4.5.1sp1AllAll
ApplicationMacromediaColdfusion4.5.1AllAllAll
ApplicationMacromediaColdfusion4.5AllAllAll
ApplicationMacromediaColdfusion4.0.1AllAllAll
ApplicationMacromediaColdfusion4.0AllAllAll
ApplicationMacromediaColdfusion3.1.2AllAllAll
ApplicationMacromediaColdfusion3.1.1AllAllAll
ApplicationMacromediaColdfusion3.1AllAllAll
ApplicationMacromediaColdfusion3.0.1AllAllAll
ApplicationMacromediaColdfusion3.0AllAllAll
ApplicationMacromediaColdfusion2.0AllAllAll
ApplicationMacromediaColdfusion-AllAllAll
© CVE.report 2026 |

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

CVE.report and Source URL Uptime Status status.cve.report