[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"all-banners":3,"FooterNav_JsYsxvLufb1W12aeknKZ89on0MD0bNDTiB5EYxyxmU":43,"SkipToContent_34xgpJIRRkpiT6ls6jE4NHf7VpvQCQBEwi69exi4oT0":50,"FooterSocial_u16tCafBUeGMoDrdLfTINytP2JB5msc6iB3VDUutAoU":56,"vulnerability-29502":63},[4,15,23,28],{"title":5,"slug":6,"text":7,"link":8,"external":9,"targets":10,"cta":12,"variant":13,"campaign_id":14},"wp2shell (Vuln DB homepage)","wp2shell-vuln-db","Emergency CVE response: detection & exploitation now available for *wp2shell*, the critical WP RCE chain","https://pentest-tools.com/vulnerabilities-exploits/wordpress-core-69-701-pre-auth-blind-sql-injection-batch-route-confusion_29451",false,[11],"/vulnerabilities-exploits/","See CVE details","secondary","wp2shell",{"title":16,"slug":17,"text":18,"link":19,"external":9,"targets":20,"cta":22,"variant":13,"campaign_id":14},"wp2shell (CVE page - exploitation)","wp2shell-cve-page-exploit","Validate wp2shell exposure & mitigation! Detect with any plan. Exploit with Pentest Suite.","https://pentest-tools.com/pricing",[21],"/vulnerabilities-exploits/wp2shell-wordpress-core-690-694-and-700-701-pre-auth-batch-route-confusion-leading-to-sql-injection_29452","Explore plans",{"title":24,"slug":25,"text":18,"link":19,"external":9,"targets":26,"cta":22,"variant":13,"campaign_id":14},"wp2shell (CVE page - detection)","wp2shell-cve-page",[27],"/vulnerabilities-exploits/wordpress-core-69-701-pre-auth-blind-sql-injection-batch-route-confusion_29451",{"title":29,"slug":30,"text":31,"link":32,"external":9,"targets":33,"cta":42,"variant":13,"campaign_id":30},"DEF CON AI pentests launch","def-con-ai-pentests","We’re launching AI Pentests at DEF CON 34","https://pentest-tools.com/events/defcon-34-2026",[34,35,36,37,38,39,40,41],"/","/website-vulnerability-scanning/website-scanner","/network-vulnerability-scanning/network-security-scanner-online","/information-gathering/find-subdomains-of-domain","/network-vulnerability-scanning/port-scanner-online-nmap","/product","/website-vulnerability-scanning/discover-hidden-directories-and-files","/insights","See you there",["Island",44],{"key":45,"params":46,"result":48},"FooterNav_JsYsxvLufb1W12aeknKZ89on0MD0bNDTiB5EYxyxmU",{"props":47},"{}",{"head":49},{},["Island",51],{"key":52,"params":53,"result":54},"SkipToContent_34xgpJIRRkpiT6ls6jE4NHf7VpvQCQBEwi69exi4oT0",{"props":47},{"head":55},{},["Island",57],{"key":58,"params":59,"result":61},"FooterSocial_u16tCafBUeGMoDrdLfTINytP2JB5msc6iB3VDUutAoU",{"props":60},"{\"text-color\":\"gray\"}",{"head":62},{},{"id":64,"detectable_with":65,"vuln_details":71,"vuln_id":94,"name":95,"published":96,"updated":96},29502,{"tool":66,"engine":69},{"id":67,"name":68},1,"Network Scanner",{"id":67,"name":70},"Sniper",{"id":64,"codename":72,"description":73,"severity":74,"risk_description":75,"public_description":76,"public_recommendation":77,"recommendation":78,"references":79,"cvssv3":82,"epss_score":83,"epss_percentile":84,"cve":85,"in_cisa_catalog":87,"date":88,"software_type":89,"vendor":90,"product":91,"ptt_exploit_capabilities":92},null,"We found that the target ColdFusion server, version 2025.9, 2023.20 or earlier, is vulnerable to CVE-2026-48282, a path traversal vulnerability (CWE-22) in the RDS (Remote Development Services) FILEIO WRITE operation exposed at /CFIDE/main/ide.cfm?ACTION=FILEIO. When RDS is enabled with authentication disabled, an unauthenticated remote attacker can invoke the FILEIO WRITE operation to write arbitrary files anywhere on the filesystem, including a CFML webshell under the web root, resulting in remote code execution in the context of the ColdFusion process. Exploitation does not require user interaction.\nWe have detected this by sending the RDS FILEIO WRITE request to write a CFML webshell into the CFIDE webroot, then executing the whoami command through it and fetching the output back over HTTP.","critical","The risk exists that a remote unauthenticated attacker can fully compromise the server to steal confidential information, install ransomware, or pivot to the internal network.","Adobe ColdFusion, versions 2025.9, 2023.20 and earlier, is vulnerable to CVE-2026-48282, a path traversal vulnerability in the RDS (Remote Development Services) FILEIO WRITE operation. When RDS is enabled with authentication disabled, an unauthenticated remote attacker can write arbitrary files to the server filesystem, including CFML webshells under the web root, leading to remote code execution in the context of the ColdFusion process.","Update to ColdFusion 2025 Update 10 or ColdFusion 2023 Update 21 or later.","We recommend updating the Adobe ColdFusion server to ColdFusion 2025 Update 10 or ColdFusion 2023 Update 21 or later, and ensuring RDS is disabled or secured with authentication if not required.",[80,81],"https://helpx.adobe.com/security/products/coldfusion/apsb26-68.html","https://labs.watchtowr.com/its-37oc-and-all-we-can-think-about-is-coldfusion-adobe-coldfusion-security-bulletin-apsb26-68-cve-bonanza/",10,0.99197,0.99931,[86],"CVE-2026-48282",true,"2026-06-30T00:00:00Z","Web server","Adobe","ColdFusion",[93],"RCE","NETSCAN-SNIPER-CVE-2026-48282","Adobe ColdFusion - RDS Arbitrary File Write","2026-07-22T00:00:00Z"]