CVE-2014-2868: Paperthin Commonspot Content Server

High severity, CVSS 7.5. EPSS: 3.4% chance of exploitation in the next 30 days.

PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 allows remote attackers to modify the flow of execution of ColdFusion code by using an HTTP GET request to set a ColdFusion variable.

Affected products

  • Paperthin Commonspot Content Server: up to and including 7.0.1; version 8.0.0 only; version 8.0.1 only; version 8.0.2 only

Published 2014-04-15. Last modified 2026-06-17.