Stored Cross-Site Scripting Vulnerability in Adobe ColdFusion
CVE-2025-49540

4.3MEDIUM

Key Information:

Vendor

Adobe

Vendor
CVE Published:
8 July 2025

What is CVE-2025-49540?

Adobe ColdFusion versions 2025.2, 2023.14, 2021.20, and earlier releases are susceptible to a stored Cross-Site Scripting (XSS) vulnerability. A malicious actor with elevated privileges can exploit this weakness to inject harmful scripts into form fields. If a victim interacts with the compromised form field and accesses the corresponding page, the injected malicious JavaScript can be executed in their browser. It is important to note that this issue is limited to internal IP addresses, which confines the potential attack surface.

Affected Version(s)

ColdFusion 0 <= 2021.20

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-49540 : Stored Cross-Site Scripting Vulnerability in Adobe ColdFusion