Reflected Cross-Site Scripting Vulnerability in ColdFusion by Adobe
CVE-2026-48307

8.8HIGH

Key Information:

Vendor

Adobe

Vendor
CVE Published:
30 June 2026

What is CVE-2026-48307?

A reflected Cross-Site Scripting (XSS) vulnerability exists in ColdFusion versions 2025.9, 2023.20, and earlier. This security flaw allows attackers to inject malicious scripts into web pages. The exploitation of this vulnerability necessitates user interaction, as the targeted user must open a specially crafted link. When successfully exploited, it can lead to arbitrary code execution in the context of the victim’s browser session, which could have serious consequences for user data and application integrity.

Affected Version(s)

ColdFusion 0 <= 2023.20

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.