Improper Restriction of XML External Entity Reference in Adobe ColdFusion
CVE-2025-61821

6.8MEDIUM

Key Information:

Vendor

Adobe

Vendor
CVE Published:
9 December 2025

What is CVE-2025-61821?

Adobe ColdFusion versions 2025.4, 2023.16, 2021.22, and earlier versions are susceptible to an Improper Restriction of XML External Entity Reference vulnerability. This flaw could enable an attacker to exploit the system, potentially leading to unauthorized access to sensitive files and data stored on the server. The exploitation of this vulnerability does not require any user interaction, making it a significant risk for server integrity and data confidentiality.

Affected Version(s)

ColdFusion 0 <= 2021.22

References

CVSS V3.1

Score:
6.8
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-61821 : Improper Restriction of XML External Entity Reference in Adobe ColdFusion