CVE-2026-47933EPSS p28.1%

CVE-2026-47933CVE-2026-47933

adobe / coldfusion

Description

ColdFusion versions 2023.19, 2025.8 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. The vulnerable component is restricted to an administrative network zone by default. Scope is changed.

Scoring

CVSS 4.8 ()
VectorCVSS:3.1/AV:A/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
EPSS0.36% probability of exploitation · percentile 28.1% · 2026-10-05T12:00:23Z
Last modified2026-08-28

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

CVE
CVE-2026-47931
CVE
CVE-2026-47930
CVE
CVE-2026-47928
CVE
CVE-2026-47929
CVE
CVE-2026-47973
CVE
CVE-2026-47943
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.