CVE-2025-61808 is a critical unrestricted file upload vulnerability affecting Adobe ColdFusion versions 2025.4, 2023.16, 2021.22, and earlier. This flaw allows a high-privileged attacker to upload dangerous file types, leading to arbitrary code execution without user interaction. With a CVSS score of 9.1 (CRITICAL), it presents a significant risk due to its network-based attack vector and high impact on confidentiality, integrity, and availability. While there is no evidence of active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB), the vulnerability has garnered substantial community attention with 12 mentions, indicating high awareness and potential for future exploitation. Organizations are strongly advised to patch immediately.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2021CPE matchmatch criteria | cpe:2.3:a:adobe:coldfusion:2021:-:*:*:*:*:*:* | ||
2021CPE matchmatch criteria | cpe:2.3:a:adobe:coldfusion:2021:update1:*:*:*:*:*:* | ||
2021CPE matchmatch criteria | cpe:2.3:a:adobe:coldfusion:2021:update10:*:*:*:*:*:* | ||
2021CPE matchmatch criteria | cpe:2.3:a:adobe:coldfusion:2021:update11:*:*:*:*:*:* | ||
2021CPE matchmatch criteria | cpe:2.3:a:adobe:coldfusion:2021:update12:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.7 Bluesky, 0.4 Mastodon, and 1.7 GitHub mentions.
The average CVE in this peer group has 0.4 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.