CVE-2014-2868: Paperthin Commonspot Content Server
High severity, CVSS 7.5. EPSS: 3.4% chance of exploitation in the next 30 days.
PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 allows remote attackers to modify the flow of execution of ColdFusion code by using an HTTP GET request to set a ColdFusion variable.
Affected products
- Paperthin Commonspot Content Server: up to and including 7.0.1; version 8.0.0 only; version 8.0.1 only; version 8.0.2 only
Published 2014-04-15. Last modified 2026-06-17.