Stored XSS Vulnerability in Adobe ColdFusion
CVE-2026-21269

4.6MEDIUM

Key Information:

Vendor

Adobe

Vendor
CVE Published:
11 August 2026

What is CVE-2026-21269?

Adobe ColdFusion is vulnerable to a stored Cross-Site Scripting (XSS) issue that may allow low-privileged attackers to inject harmful scripts into designated form fields. If exploited, malicious JavaScript could run in the browsers of users who visit the affected pages, leading to potential data theft or session hijacking. Organizations are advised to review and apply security updates to mitigate this risk.

Affected Version(s)

ColdFusion 2023 0 <= 2023.0.22

ColdFusion 2023 0 <= 2023.0.22

ColdFusion 2025 0 <= 2025.0.11

References

CVSS V3.1

Score:
4.6
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.