Allaire's vulnerability profile centers on its web-application server and content-management platform portfolio, most notably ColdFusion, which maintained significant presence in enterprise and mid-market deployments. Despite a narrowly scoped product line, the vendor's disclosures are prominent in the landscape, reflecting the server's footprint and longevity across business-critical web infrastructure. The vendor's vulnerabilities frequently acquire public exploit code, underscoring the appeal of web-server attack surfaces and the persistence of its legacy products in networked environments. Defenders should treat Allaire and ColdFusion disclosures as relevant to inventory assessment and patch-cycle planning, particularly for organizations operating aging application servers; current exploitation and severity counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Allaire over time
Signals from CVEs in this vendor scope (24 CVEs).
24 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-1999-0477HIGH The Expression Evaluator in the ColdFusion Application Server allows a remote attacker to upload files to the server via openfile.cfm, which does not restrict access to the server | Dec 25, 1999 | 7.5 | 32 | NO | YES |
CVE-2000-0057HIGH Cold Fusion CFCACHE tag places temporary cache files within the web document root, allowing remote attackers to obtain sensitive system information. | Jan 4, 2000 | 7.5 | 30 | NO | YES |
CVE-1999-0455HIGH The Expression Evaluator sample application in ColdFusion allows remote attackers to read or delete files on the server via exprcalc.cfm, which does not restrict access to the serv | Dec 25, 1999 | 7.5 | 30 | NO | YES |
CVE-1999-0760HIGH Undocumented ColdFusion Markup Language (CFML) tags and functions in the ColdFusion Administrator allow users to gain additional privileges. | Mar 12, 2001 | 10.0 | 25 | NO | NO |
CVE-1999-0800MEDIUM The GetFile.cfm file in Allaire Forums allows remote attackers to read files through a parameter to GetFile.cfm. | Mar 12, 2001 | 5.0 | 25 | NO | YES |
CVE-2000-0538MEDIUM ColdFusion Administrator for ColdFusion 4.5.1 and earlier allows remote attackers to cause a denial of service via a long login password. | Jun 7, 2000 | 5.0 | 25 | NO | YES |
CVE-2001-1120MEDIUM Vulnerabilities in ColdFusion 2.0 through 4.5.1 SP 2 allow remote attackers to (1) read or delete arbitrary files, or (2) overwrite ColdFusion Server templates. | Jul 11, 2001 | 6.4 | 22 | NO | NO |
CVE-2002-0108HIGH Allaire Forums 2.0.4 and 2.0.5 and Forums! 3.0 and 3.1 allows remote authenticated users to spoof messages as other users by modifying the hidden form fields for the name and e-mai | Mar 25, 2002 | 7.5 | 20 | NO | NO |
CVE-2002-0576MEDIUM ColdFusion 5.0 and earlier on Windows systems allows remote attackers to determine the absolute pathname of .cfm or .dbm files via an HTTP request that contains an MS-DOS device na | Jun 18, 2002 | 5.0 | 19 | NO | NO |
CVE-1999-0923HIGH Sample runnable code snippets in ColdFusion Server 4.0 allow remote attackers to read files, conduct a denial of service, or use the server as a proxy for other HTTP calls. | Mar 12, 2001 | 7.5 | 19 | NO | NO |
Signals from CVEs in this vendor scope (24 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Allaire.
Media articles that mention a CVE ID that affects a product developed by Allaire — matched by CVE ID, not by vendor name.