Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 3

Количество 3

nvd логотип

CVE-2026-27305

4 месяца назад

ColdFusion versions 2023.18, 2025.6 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to access sensitive files and directories outside the intended access scope. Exploitation of this issue does not require user interaction.

CVSS3: 8.6
EPSS: Средний
github логотип

GHSA-ppfw-rp5w-2c9c

4 месяца назад

ColdFusion versions 2023.18, 2025.6 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to access sensitive files and directories outside the intended access scope. Exploitation of this issue does not require user interaction.

CVSS3: 8.6
EPSS: Средний
fstec логотип

BDU:2026-05603

4 месяца назад

Уязвимость интерпретатора ColdFusion, связанная с неверным ограничением имени пути к каталогу, позволяющая нарушителю осуществить чтение произвольных файлов

CVSS3: 8.6
EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2026-27305

ColdFusion versions 2023.18, 2025.6 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to access sensitive files and directories outside the intended access scope. Exploitation of this issue does not require user interaction.

CVSS3: 8.6
29%
Средний
4 месяца назад
github логотип
GHSA-ppfw-rp5w-2c9c

ColdFusion versions 2023.18, 2025.6 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to access sensitive files and directories outside the intended access scope. Exploitation of this issue does not require user interaction.

CVSS3: 8.6
29%
Средний
4 месяца назад
fstec логотип
BDU:2026-05603

Уязвимость интерпретатора ColdFusion, связанная с неверным ограничением имени пути к каталогу, позволяющая нарушителю осуществить чтение произвольных файлов

CVSS3: 8.6
29%
Средний
4 месяца назад

Уязвимостей на страницу