CVE-2025-61809: ColdFusion | Improper Input Validation (CWE-20)
ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized read and write access. Exploitation of this issue does not require user interaction and scope is unchanged.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-61809?
CVE-2025-61809 is classified as a medium severity vulnerability.
How do I fix CVE-2025-61809?
To fix CVE-2025-61809, update your Adobe ColdFusion to the latest version available.
Which versions are affected by CVE-2025-61809?
CVE-2025-61809 affects Adobe ColdFusion versions 2025.4, 2023.16, and 2021.22 and earlier.
What kind of vulnerability is CVE-2025-61809?
CVE-2025-61809 is an Improper Input Validation vulnerability that can lead to security feature bypass.
What is the potential impact of CVE-2025-61809?
Exploiting CVE-2025-61809 could allow an attacker to gain unauthorized read and write access.