CVE-2025-54234: Adobe ColdFusion
Low severity, CVSS 2.7. EPSS: 0.8% chance of exploitation in the next 30 days.
ColdFusion versions 2025.1, 2023.13, 2021.19 and earlier are affected by a Server-Side Request Forgery (SSRF) vulnerability that could lead to limited file system read. A high-privilege authenticated attacker can force the application to make arbitrary requests via injection of arbitrary URLs. Exploitation of this issue does not require user interaction.
Affected products
- Adobe ColdFusion: version 2021 only; version 2023 only; version 2025 only
Published 2025-08-18. Last modified 2026-06-17.