CVE-2025-30292: ColdFusion | Cross-site Scripting (Reflected XSS) (CWE-79)
ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-30292?
CVE-2025-30292 has been classified as a medium severity reflected Cross-Site Scripting (XSS) vulnerability.
How do I fix CVE-2025-30292?
To fix CVE-2025-30292, update Adobe ColdFusion to version 2023.13, 2021.19, or a later version.
What versions of ColdFusion are affected by CVE-2025-30292?
CVE-2025-30292 affects Adobe ColdFusion versions 2023.12, 2021.18, and 2025.0 and earlier.
What kind of attack does CVE-2025-30292 allow?
CVE-2025-30292 allows attackers to execute malicious JavaScript content by convincing victims to visit a specially crafted URL.
What impact can CVE-2025-30292 have on users?
If exploited, CVE-2025-30292 can lead to unauthorized actions being performed on behalf of the user or the theft of sensitive information.