Ortussolutions develops testing and application frameworks for the CFML ecosystem, with a modestly represented vulnerability footprint concentrated in products such as TestBox and ColdBox Elixir. The recurring exposure centers on path-traversal flaws and sensitive-information-disclosure weaknesses, reflecting input-validation and access-control concerns typical of web-facing testing and development tools. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Ortussolutions over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-15929CRITICAL In Ortus TestBox 2.4.0 through 4.1.0, unvalidated query string parameters passed to system/runners/HTMLRunner.cfm allow an attacker to write an arbitrary CFM file (within the appli | Nov 24, 2020 | 9.8 | 30 | NO | NO |
CVE-2021-4430HIGH A vulnerability classified as problematic has been found in Ortus Solutions ColdBox Elixir 3.1.6. This affects an unknown part of the file src/defaultConfig.js of the component ENV | Nov 6, 2023 | 7.5 | 25 | NO | NO |
CVE-2020-15928MEDIUM In Ortus TestBox 2.4.0 through 4.1.0, unvalidated query string parameters to test-browser/index.cfm allow directory traversal. | Nov 24, 2020 | 5.3 | 19 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Ortussolutions.
Media articles that mention a CVE ID that affects a product developed by Ortussolutions — matched by CVE ID, not by vendor name.