CVE-2026-75993 PUBLISHED

ColdFusion | Cross-site Scripting (Reflected XSS) (CWE-79)

Assigner: adobe
Reserved: 18.08.2026 Published: 08.09.2026 Updated: 08.09.2026

ColdFusion is affected by a reflected Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this vulnerability to inject malicious scripts into a web page, potentially gaining elevated access or control over the victim's account or session. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.

Metrics

CVSS Vector: CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N
CVSS Score: 8.5

Product Status

Vendor Adobe
Product ColdFusion 2025
Versions Default: unaffected
  • affected from 0 to 12 (incl.)
  • Version 13 is unaffected
Vendor Adobe
Product ColdFusion 2023
Versions Default: unaffected
  • affected from 0 to 23 (incl.)
  • Version 24 is unaffected

References

Problem Types

  • Cross-site Scripting (Reflected XSS) (CWE-79) CWE