ColdFusion <= 2025.8 Stored XSS in form fields
CVE-2026-47933 Published on June 9, 2026
ColdFusion | Cross-site Scripting (Stored XSS) (CWE-79)
ColdFusion versions 2023.19, 2025.8 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. The vulnerable component is restricted to an administrative network zone by default. Scope is changed.
Vulnerability Analysis
Weakness Type
What is a XSS Vulnerability?
The software does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
CVE-2026-47933 has been classified to as a XSS vulnerability or weakness.
Products Associated with CVE-2026-47933
Want to know whenever a new CVE is published for Adobe ColdFusion? stack.watch will email you.
Affected Versions
Adobe ColdFusion:- Before and including 2023.19 is affected.
- Before and including 2025.8 is affected.
Exploit Probability
EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.