← Back to CVE List
Vulnerability Intelligence Report
ColdFusion | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)

CVE-2025-54261

ColdFusion versions 2025.3, 2023.15, 2021.21 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary code execution by an attacker. The victim must have optional configurations enabled. Scope is changed.

No Active Exploit Signals
CVSS Base Score
10.0
CRITICAL
Exploitability:3.9
Impact Score:6.1
Temporal Score:10.0
EPSS Probability:19.93%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
Authentication
Weaponization
SSVC Action

Weaknesses (CWE)

CWE-22 ↗Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)

Affected Products & Versions

Vendor Product Affected Versions
Adobe ColdFusion 0 <= 2021.21 (affected)

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

EPSS Score
19.934%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityAdobe Systems Incorporated · Vendor · USA
Reserved2025-07-17T21:15:02
Published2025-09-09T16:58:42
Patch Date2025-09-09
Last Updated2025-10-08T15:55:34

LINK COPIED TO CLIPBOARD