Improper Input Validation in ColdFusion by Adobe
CVE-2025-61822

6.2MEDIUM

Key Information:

Vendor

Adobe

Vendor
CVE Published:
9 December 2025

What is CVE-2025-61822?

Adobe ColdFusion versions 2025.4, 2023.16, and 2021.22 and earlier contain an improper input validation flaw that allows an attacker to exploit this vulnerability to write malicious files to any arbitrary location in the file system. This can lead to significant security risks, as such exploitation does not necessitate any user interaction, thereby broadening the scope of potential attacks against systems running vulnerable versions of ColdFusion.

Affected Version(s)

ColdFusion 0 <= 2021.22

References

CVSS V3.1

Score:
6.2
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.