Evidence-linked product lifecycle intelligenceSUPPORT · SECURITY · RETIREMENT
← Search results
CVE-LINKED INVENTORY118 SECURITY RECORDS

Adobe

ColdFusion

Affected and fixed version statements observed in the public BlackTree CVE catalogue. These statements describe vulnerability scope, not publisher support entitlement.

Lifecycle evidence status

This CVE identity is linked to the Lifecycle record Adobe ColdFusion. Use that record for publisher support phases and retirement dates.

A missing support date does not mean the product is supported. CVE publication dates and affected-version ranges must not be interpreted as EOL dates.

CVE-observed version history

CVEPublishedAffected versionsFixed version informationPublisher evidence
CVE-2024-53961 23 Dec 2024 ≤ 2021.17 No fixed version is explicitly recorded in the structured CVE data. Update reference ↗
CVE-2024-41874 13 Sep 2024 ≤ 2021.15 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2024-45113 13 Sep 2024 ≤ 2021.12 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2024-34112 13 Jun 2024 ≤ 2021u13 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2024-34113 13 Jun 2024 ≤ 2021u13 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2024-20767 18 Mar 2024 ColdFusion: ≤ 2021.12 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2023-44351 17 Nov 2023 ≤ 2021.11 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2023-44355 17 Nov 2023 ≤ 2021.11 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2023-26347 17 Nov 2023 ≤ 2021.11 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2023-44352 17 Nov 2023 ≤ 2021.11 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2023-44353 17 Nov 2023 ≤ 2021.11 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2023-44350 17 Nov 2023 ≤ 2021.11 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2023-38204 14 Sep 2023 ≤ cf2023U2 No fixed version is explicitly recorded in the structured CVE data. Update reference ↗
CVE-2023-38205 14 Sep 2023 ColdFusion: ≤ cf2023U2 No fixed version is explicitly recorded in the structured CVE data. Update reference ↗
CVE-2023-38206 14 Sep 2023 ≤ cf2023U2 No fixed version is explicitly recorded in the structured CVE data. Update reference ↗
CVE-2021-40699 7 Sep 2023 ≤ 2018.11 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2021-40698 7 Sep 2023 ≤ 2018.11 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2023-38203 20 Jul 2023 ColdFusion: ≤ cf2023U1 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2023-29300 12 Jul 2023 ColdFusion: ≤ 2023.0.0.330468 No fixed version is explicitly recorded in the structured CVE data. Update reference ↗
CVE-2023-29301 12 Jul 2023 ≤ 2023.0.0.330468 No fixed version is explicitly recorded in the structured CVE data. Update reference ↗
CVE-2023-29298 12 Jul 2023 ColdFusion: ≤ 2023.0.0.330468 No fixed version is explicitly recorded in the structured CVE data. Update reference ↗
CVE-2023-26361 23 Mar 2023 unspecified ≤ CF2018U15, CF2021U5; unspecified ≤ None An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2023-26360 23 Mar 2023 ColdFusion: unspecified ≤ CF2018U15, unspecified ≤ CF2021U5, unspecified ≤ None An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2023-26359 23 Mar 2023 ColdFusion: unspecified ≤ CF2018U15, CF2021U5, unspecified ≤ None An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2022-42341 14 Oct 2022 unspecified ≤ CF2021U4; unspecified ≤ CF2018u14; unspecified ≤ None No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2022-38424 14 Oct 2022 unspecified ≤ CF2021U4; unspecified ≤ CF2018u14; unspecified ≤ None No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2022-42340 14 Oct 2022 unspecified ≤ CF2021U4; unspecified ≤ CF2018u14; unspecified ≤ None No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2022-38423 14 Oct 2022 unspecified ≤ CF2021U4; unspecified ≤ CF2018u14; unspecified ≤ None No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2022-38422 14 Oct 2022 unspecified ≤ CF2021U4; unspecified ≤ CF2018u14; unspecified ≤ None No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2022-38421 14 Oct 2022 unspecified ≤ CF2021U4; unspecified ≤ CF2018u14; unspecified ≤ None An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2022-38419 14 Oct 2022 unspecified ≤ CF2021U4; unspecified ≤ CF2018u14; unspecified ≤ None An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2022-35711 14 Oct 2022 unspecified ≤ CF2021U4; unspecified ≤ CF2018u14; unspecified ≤ None An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2022-38420 14 Oct 2022 unspecified ≤ CF2021U4; unspecified ≤ CF2018u14; unspecified ≤ None An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2022-35690 14 Oct 2022 unspecified ≤ CF2021U4; unspecified ≤ CF2018u14; unspecified ≤ None An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2022-35712 14 Oct 2022 unspecified ≤ CF2021U4; unspecified ≤ CF2018u14; unspecified ≤ None An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2022-35710 14 Oct 2022 unspecified ≤ CF2021U4; unspecified ≤ CF2018u14; unspecified ≤ None An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2022-38418 14 Oct 2022 unspecified ≤ CF2021U4; unspecified ≤ CF2018u14; unspecified ≤ None An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2022-28818 12 May 2022 unspecified ≤ CF2021U3; unspecified ≤ CF2018U13; unspecified ≤ None No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2020-10145 27 May 2021 2021; 2018; 2016 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2021-21087 15 Apr 2021 unspecified ≤ 2016.16; unspecified ≤ 2018.10; unspecified ≤ 2021.0.0.323925; unspecified ≤ None An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2020-3796 26 Jun 2020 ColdFusion 2016, and ColdFusion 2018 versions No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2020-3768 26 Jun 2020 ColdFusion 2016, and ColdFusion 2018 versions No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2020-3767 26 Jun 2020 ColdFusion 2016, and ColdFusion 2018 versions No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2020-3794 25 Mar 2020 ColdFusion 2016, and ColdFusion 2018 versions No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2020-3761 25 Mar 2020 ColdFusion 2016, and ColdFusion 2018 versions No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2019-8256 19 Dec 2019 Update 6 and earlier versions No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2019-7840 12 Jun 2019 Update 3 and earlier, Update 10 and earlier, and Update 18 and earlier versions No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2019-7839 12 Jun 2019 Update 3 and earlier, Update 10 and earlier, and Update 18 and earlier versions No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2019-7838 12 Jun 2019 Update 3 and earlier, Update 10 and earlier, and Update 18 and earlier versions No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2019-7092 24 May 2019 Update 1 and earlier, Update 7 and earlier, and Update 15 and earlier versions No fixed version is explicitly recorded in the structured CVE data. Use CVE record

How this record is maintained

The CVE inventory is reconciled automatically from cve.blacktree.nl. Exact identity matches link to existing Lifecycle product or package histories. Unmatched products stay in a prioritised publisher-source research queue, and Lifecycle marks the date gap instead of inferring a support boundary from vulnerability data.