CVE-2025-61809 is an Improper Input Validation vulnerability affecting Adobe ColdFusion versions 2025.4, 2023.16, and 2021.22 and earlier. This critical vulnerability, with a CVSS score of 9.1, allows an unauthenticated attacker to bypass security features and gain unauthorized read and write access without user interaction. While there is no known active exploitation or publicly available exploit code in Metasploit, Nuclei, or ExploitDB, the vulnerability has garnered significant community attention with 11 mentions and one media article, indicating awareness and potential future exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2021CPE matchmatch criteria | cpe:2.3:a:adobe:coldfusion:2021:-:*:*:*:*:*:* | ||
2021CPE matchmatch criteria | cpe:2.3:a:adobe:coldfusion:2021:update1:*:*:*:*:*:* | ||
2021CPE matchmatch criteria | cpe:2.3:a:adobe:coldfusion:2021:update10:*:*:*:*:*:* | ||
2021CPE matchmatch criteria | cpe:2.3:a:adobe:coldfusion:2021:update11:*:*:*:*:*:* | ||
2021CPE matchmatch criteria | cpe:2.3:a:adobe:coldfusion:2021:update12:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.