CVE-2026-76002 PUBLISHED

ColdFusion | Cross-site Scripting (Reflected XSS) (CWE-79)

Assigner: adobe
Reserved: 18.08.2026 Published: 08.09.2026 Updated: 08.09.2026

ColdFusion is affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser. Scope is changed.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CVSS Score: 6.1

Product Status

Vendor Adobe
Product ColdFusion 2025
Versions Default: unaffected
  • affected from 0 to 12 (incl.)
  • Version 13 is unaffected
Vendor Adobe
Product ColdFusion 2023
Versions Default: unaffected
  • affected from 0 to 23 (incl.)
  • Version 24 is unaffected

References

Problem Types

  • Cross-site Scripting (Reflected XSS) (CWE-79) CWE