CVE-2025-61812: ColdFusion | Improper Input Validation (CWE-20)
ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Improper Input Validation vulnerability that could allow a high privileged attacker to gain arbitrary code execution. Exploitation of this issue does not require user interaction.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-61812?
CVE-2025-61812 is classified as a high severity vulnerability due to its potential for arbitrary code execution by a privileged attacker.
How do I fix CVE-2025-61812?
To fix CVE-2025-61812, update Adobe ColdFusion to version 2025.5 or later, or follow patches provided by Adobe.
What versions of ColdFusion are affected by CVE-2025-61812?
CVE-2025-61812 affects Adobe ColdFusion versions 2025.4, 2023.16, 2021.22, and earlier.
What type of vulnerability is CVE-2025-61812?
CVE-2025-61812 is an Improper Input Validation vulnerability that can lead to arbitrary code execution.
Does exploitation of CVE-2025-61812 require user interaction?
No, exploitation of CVE-2025-61812 does not require user interaction.