Cfmsource maintains a focused suite of ColdFusion-based web applications including auction, calendar, forum, and blogging products, with recurring exposure centered on SQL injection vulnerabilities in query construction. These web-facing applications reflect a characteristic weakness in parameterization and input sanitization that is endemic to dynamic SQL contexts; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Cfmsource over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2008-6324HIGH SQL injection vulnerability in forummessages.cfm in CF_Forum allows remote attackers to execute arbitrary SQL commands via the categorynbr parameter. | Feb 27, 2009 | 7.5 | 34 | NO | YES |
CVE-2008-6322HIGH SQL injection vulnerability in index.cfm in CFMSource CFMBlog allows remote attackers to execute arbitrary SQL commands via the categorynbr parameter. | Feb 27, 2009 | 7.5 | 31 | NO | YES |
CVE-2008-6323HIGH SQL injection vulnerability in forummessages.cfm in CFMSource CF_Auction allows remote attackers to execute arbitrary SQL commands via the categorynbr parameter. | Feb 27, 2009 | 7.5 | 28 | NO | YES |
CVE-2008-6319HIGH SQL injection vulnerability in calendarevent.cfm in CF_Calendar allows remote attackers to execute arbitrary SQL commands via the calid parameter. | Feb 27, 2009 | 7.5 | 28 | NO | YES |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Cfmsource.
Media articles that mention a CVE ID that affects a product developed by Cfmsource — matched by CVE ID, not by vendor name.