CVE-2025-61821: ColdFusion | Improper Restriction of XML External Entity Reference ('XXE') (CWE-611)
ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to access sensitive files and data on the server. Exploit depends on conditions beyond the attacker's control. Exploitation of this issue does not require user interaction and scope is changed.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-61821?
CVE-2025-61821 is considered a critical vulnerability due to its potential to allow attackers to read arbitrary files on the affected system.
How do I fix CVE-2025-61821?
To remediate CVE-2025-61821, upgrade to ColdFusion version 2025.5 or later, which contains the necessary patches.
What versions of ColdFusion are affected by CVE-2025-61821?
ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by CVE-2025-61821.
What types of attacks are possible with CVE-2025-61821?
An attacker can exploit CVE-2025-61821 to perform XML External Entity (XXE) attacks that result in the unauthorized access of sensitive files.
Is there a workaround for CVE-2025-61821?
No official workarounds for CVE-2025-61821 are recommended; upgrading to a patched version is the best course of action.