CVE-2026-48307: ColdFusion | Cross-site Scripting (Reflected XSS) (CWE-79)
ColdFusion versions 2025.9, 2023.20 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this vulnerability to inject malicious scripts into a web page, potentially resulting in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious link. Scope is changed.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-48307?
The severity of CVE-2026-48307 is rated as high with a CVSS score of 8.8.
What is CVE-2026-48307?
CVE-2026-48307 refers to a reflected Cross-Site Scripting (XSS) vulnerability in Adobe ColdFusion that allows attackers to inject malicious scripts.
How do I fix CVE-2026-48307?
To fix CVE-2026-48307, update Adobe ColdFusion to the latest version that addresses this vulnerability.
Which versions of Adobe ColdFusion are affected by CVE-2026-48307?
CVE-2026-48307 affects Adobe ColdFusion versions 2025.9, 2023.20, and earlier.
What are the potential impacts of exploiting CVE-2026-48307?
Exploiting CVE-2026-48307 could lead to arbitrary code execution in the context of the current user, posing significant security risks.