ColdFusionX
15 exploits
Active since Apr 2019
Atlassian Jira Server/Data Center Path Traversal via /WEB-INF/web.xml
Atlassian Confluence Server <7.4.10, >7.5.0-7.12.2 - Info Disclosure
Casdoor < 1.13.1 - SQL Injection via Query API Parameters
Keycloak < 13.0.0 - Server-Side Request Forgery via OIDC request_uri Parameter
Atlassian Bitbucket Server/Data Center <7.6.17/<7.17.10/<7.21.4/<8....
Eclipse Jetty 9.4.37-9.4.42, 10.0.1-10.0.5, 11.0.1-11.0.5 - Directory Traversal & Security Bypass via Encoded URI
Apache Tomcat < 7.0.108 - Insecure Deserialization
Confluence - Remote Code Execution
Bludit 3.9.2 - Authentication Bruteforce Mitigation Bypass via X-Forwarded-For Header
CWP login.php Unauthenticated RCE
Tiki < 21.11 - Reflected Cross-Site Scripting via tiki-admin_system.php zipPath Parameter
CVSS 5.4
Tiki < 27.1 - Cross-Site Scripting via tiki-editpage.php Page Parameter
CVSS 5.4
CutePHP CuteNews 2.1.2 - Code Injection
CVSS 8.8
Log4Shell HTTP Header Injection
CVSS 10.0
Keycloak < 13.0.0 - Server-Side Request Forgery via OIDC request_uri Parameter
CVSS 5.3