ColdFusion Posts Around the World
Ben Nadel
Ben Nadel looks at how to reflectively access built-in functions in ColdFusion; and, warns against trying to do it....
Lucee Blog
Key Updates to GitHub Copilot AI (Late June–Early July 2025)
...
Adobe ColdFusion Community Blog
CFMail will throw error after update 15 applied. Java version: 17.0.15+9-LTS-24 "Error","ajp-nio-127.0.0.1-8022-exec-3","07/11/25","13:24:45","","Bad type on operand stackException Details:Location:coldfusion/mail/mod/MailImpl.signMail(Ljavax...
Adobe ColdFusion Community Blog
I am observing an outbound connection initiated by the process coldfusion.exe over the SSH port. The destination IP is not flagged as malicious on VirusTotal. Could you please advise if this is a legitimate process behavior by coldfusion, or should I investigate this activity fur...
Lucee Blog
Has anyone run into a situation where scheduled tasks run for a random period of time and then just stop.
I have 2 tasks scheduled; 1 every 5 minutes and 1 every hour. They will run for a day to a week or longer and then just stop.
When stopped, I can run both from the ...
Adobe ColdFusion Community Blog
Hi everyone,I've been working with the Adobe ColdFusion 2021 AMI on AWS (Windows) and noticed that Docker is installed by default. However, the ColdFusion documentation and AWS Marketplace listing don't mention Docker as a requirement or dependency....
Lucee Blog
Just a quick heads up, I just noticed and fixed a bug when installing extensions via an ENV var without a version was returning not the latest extension version, due to not using an ordered struct.
Adobe ColdFusion Community Blog
Trying to wrap my head around this new error I have popping up trying to send an email. This seems to have worked through update 19. I cannot speak for Update 20 because we updated to 20 and then 21 within a few days of each other. I am running the latest approved JVM 11.0.27 from Adobe's site, o...
Adobe ColdFusion Community Blog
For excel files, we use Apache POI. It worked fine until we applied the latest CF Security patch to our CF2023 server. It must have updated POI to the latest version which deprecated some of the functions. I was able to fix one issue, but am not able to see how I can create XSSF...
ColdFusion
CFMAIL has been working up until update 21 and now I receive this error when an email is trying to be sent. I have updated the JVM to the latest version supported for CF21 as well to see if that resolved the issue, but it doesn’t. This is CF21 Update 21 running on Server 2019. Any though...
Lucee Blog
I tried the last snapshot for the query performance and the pdf extension is throwing an error:
"ERROR","http-nio-80-exec-9","07/10/2025","12:49:37","94218EDE359E41E1C2DB41D04DCFA1A2","class org.lucee.extension.pdf.tag.DocumentSection cannot be cast to class org.lucee.extensio...
Adobe ColdFusion Community Blog
Hello, I would like to know if I have coldfusion 2021 can i upgrade to 2023 without additional cost or a new license is required?
Charlie Arehart - Server Troubleshooting
An update for ColdFusion has been released, July 8 2025, for each of cf2025 (update 3), cf2023 (update 15) and cf2021 (update 21). In brief, it addresses a number of P1 (Priority 1, "Critical") security vulnerabilities and more, including bug fixes ...
[More]
...
Ben Nadel
Ben Nadel customizes the CFWheels router / mapper by creating a wrapper component in ColdFusion....
Ben Nadel
Ben Nadel creates a sequence generator utility for generating incrementing values using a JavaScript template literal....
Lucee Blog
I have legacy website that was running on ColdFusion, I am shifting it lucee and facing the issue like most of the includes using CFC files and in CF admin, we were adding allowed extension as cfc also. But in Lucee, I didn't find any settings or not even found this thing in server x...
Adobe ColdFusion Community Blog
After applying latest security update the file pathfilter.json is totaly empty!Result: logfiles defined in scheduled tasks cannot be written.The message is:"Warning","main","07/09/25","08:55:31","","The specified path: D:/ScheduleLogs/solr_index_docum...
Adobe ColdFusion Community Blog
I'm updating a ColdFusion 2021 installation from V.13 to V.14 when V.14 installed the administrator came up except for the pakage manager page, it throws an error, when I look at the exception log I see the following: "Error","http-nio-8544-exec-7","07/08/25","16:33:29",...
Adobe ColdFusion Community Blog
Problem Description: DateFormat is returning a 9 character date instead of an 8 character one.Steps to Reproduce:1. Add the following to any Cold Fusion page:<cfset testDate = DateFormat(Now(),"YYYYMMDD")><cfoutput>Current Now(): #Now()#<br>T...
Adobe ColdFusion Community Blog
I'm trying to submit a bug report for ColdFusion using the Adobe Bug Tracker ( https://tracker.adobe.com/#/add_bug ) and when I select ColdFusion from the dropdown, the progress indicator just spins and spi...
ColdFusion
We are pleased to inform you that we’ve released security updates for ColdFusion 2025, 2023, and 2021 releases. For more information, see the respective tech notes: ColdFusion (2025 release) Update 3 ColdFusion (2023 release) Update 15 ColdFusion (2021 release) Update 21 The updates include a ...
Adobe ColdFusion Community Blog
We are pleased to inform you that we've released security updates for ColdFusion 2025, 2023, and 2021 releases. For more information, see the respective tech notes:
FusionReactor
If you're running an older version of Adobe ColdFusion, it might feel like migrating to a newer version is risky, complicated, or simply not worth the hassle. We get it. Many teams stick with what's “working” because the idea of …
Adobe ColdFusion Community Blog
Good morning, all. I have code that has been in place for at least 6 or 7 years that generates Excel files. Depending upon the app, the Excel file is either A) made available to the user via download, or B) emailed to a pre-determined email address, possibly CC'ing others...
Lucee Blog
Hi
So I recently discovered that Lucee revived an LSP (Language Server Protocol (LSP) for Lucee :: Lucee Documentation). So I setup a docker container to use the...
Ortus Solutions
June was a transformative month at Ortus Solutions as we crossed the halfway point of the year. With major product updates, powerful community engagements, and continued improvements across the BoxLang ecosystem, our mission to modernize development and empower engineers took center stage. Whether y...
Lucee Blog
Hello,
I think I have an encoding problem on the lines of code below because the value of the "DecimalValue" variable is 65533, whereas it should be 168 for a hex with a value of A8.
Can you help me, or is this a bug?
Thank you.
Sincerely,
The decimal val...
Lucee Blog
Hello,
I think I have an encoding problem on the lines of code below because the value of the "DecimalValue" variable is 65533, whereas it should be 168 for a hex with a value of A8.
Can you help me, or is this a bug?
Thank you.
Sincerely,
Ortus Solutions
Ortus Solutions had the honor of participating in the prestigious 10th América Digital Congress Mexico 2025, one of the most important technology events in Latin America. Invited by INVEST in El Salvador as part of the official national delegation, our team proudly represented El Salvador's gro...
Lucee Blog
Single Mode, when I click in the left menu on "Search" - the overview is loaded, not a search page.
When I click on "AI (experimental)":
Message
The key [values] doesn't exist in the arguments scope. The existing key...
Ortus Solutions
We're excited to announce the release of the BoxLang TextMate Bundle — a comprehensive development toolkit that brings world-class IDE support to BoxLang developers using TextMate, VS Code, Sublime Text, and other TextMate-compatible editors. With BoxLang 1.0 now stable and rapidly gaining mom...
FusionReactor
Imagine this: It’s the middle of the workday, and your application server suddenly crashes. Services are offline, users are frustrated, and you’re under intense pressure to find out what went wrong—and fast. This is where FusionReactor Cloud becomes an invaluable …
Adobe ColdFusion Community Blog
On my server, I've got a few scheduled tasks set up. Yesterday, after a while, I wanted one of the tasks to run at a different time. After doing the edits and clicking the "Submit Changes" button, I got this error:Invalid extension of the file name. Valid extensions are :log,txt
Lucee Blog
In my mail account in OUTLOOK (loacal) , my email is declared
sender : pierre@pl-arts.com and a name as alias
"Arpille Pierre LARDE Gandi"
That name is what is seeen by the reader in the "from" field.
followed by the equiva...
Lucee Blog
I upgraded my local stack to lucee 6.2.2 / jdk 21 / tomcat 11.
I have a small script, uploading a csv file (6 columns), parse each data field (e.g. validate) and then i collect the rows in an array. If the array length is 100, I create one "INSERT INTO" sql statement with 100 ...
Ortus Solutions
We had an incredible time at Open South Code 2025, held in the vibrant city of Málaga, Spain. As one of the most important Open Source events in Europe, it was an honor for Ortus Solutions to participate as Gold Sponsors, showcasing the power and potential of BoxLang, our new dynamic language f...
Ortus Solutions
We're excited to announce the first release of the BoxLang Monaco Editor Support - a comprehensive language support package that brings BoxLang syntax highlighting, IntelliSense, and custom theming to Monaco Editor, the powerful code editor that powers Visual Studio Code....
Lucee Blog
Yeah, so alas, the last RC didn't end up being the last RC after all
Security update for CVE with commons-fileupload Library
updated Postgres JDBC to 42.7.7 (42.7.5 caused problems for many users)
Lucee Blog
Method getOpenConnections in Class DatasourceManagerImpl does not work in Lucee 6. With Lucee 5 works fine. Was this method deprecated on a version higher than 5?
1 post - 1 participant
Ortus Solutions
We're thrilled to announce the release of BVM (BoxLang Version Manager) v1.15.0! This release focuses on three critical areas: security, visibility, and reliability. With SHA-256 integrity verification, comprehensive installation statistics, and enhanced system resilience, BVM v1.15.0 continues to m...
Lucee Blog
This is for @Zackster - ran into a parsing issue this morning, seems that Lucee can't parse Lambda inside a ternary expression. Example:
var operation = true
? () => "foo",
: ...
Ben Nadel
Ben Nadel illustrates a bug in the way closures work (or rather, don't work) in Adobe ColdFusion custom tags....
ColdFusion
In 1995, when the internet was still finding its footing and building dynamic websites required complex programming gymnastics, a revolutionary platform emerged with a simple yet powerful promise: “Making hard things easy.” Three decades later, Adobe ColdFusion continues to deliver on th...
Lucee Blog
Hi. We've ran into an edge-case in Lucee, caused by pentesters querying random URLs.
If someone requests test.cfm?p=hello&p.ico, on Adobe that'd result in URL={"p"="hello","p.ico"=""}. Whereas on Lucee it results in URL={"p"={"ico":""},"p.ico"=""}.
For more background ...
Lucee Blog
Hi. We've ran into an edge-case in Lucee, caused by pentesters querying random URLs.
If someone requests test.cfm?p=hello&p.ico, on Adobe that'd result in URL={"p"="hello","p.ico"=""}. Whereas on Lucee it results in URL={"p"={"ico":""},"p.ico"=""}.
For more background ...
Ortus Solutions
If you're attending the Adobe ColdFusion Summit 2025 and are looking to extend your learning with hands-on, practical skills, the "Building Reactive UIs with CBWire!" workshop is the perfect next step. Led by Grant Copley (creator of CBWire) and Luis Majano (creator of ColdBox and CEO of Ortus Solut...
Ortus Solutions
Discover the Future of JVM Development at DevBCN 2025 with Ortus Solutions
Ortus Solutions is proud to announce its participation as a sponsor at DevBCN 2025, one of Europe's premier software development conferences. We'll be showcasing BoxLang, our next-generation JVM language designed to empower d...
Ben Nadel
Ben Nadel looks at one way to use ColdFusion custom tags and CFModules in a CFWheels application....
Lucee Blog
I have a usual website and created a folder "api". You login and get a JWT Bearer-Token to access the (jsons-) endpoints A,B,C,... Nothing special so far.
But for each request to the endpoints, there will be a new session created, as we only get the JWT Bearer Token and not th...
FusionReactor
Imagine this: you’re in the middle of a packed workday when your server suddenly crashes. Everything grinds to a halt. You’re now racing against the clock to find out what happened—and get your systems back online as quickly as possible. …
FusionReactor
Every ColdFusion developer has inherited “that” application. You know the one – it was built in 2008, has grown organically over the years, and now takes 30 seconds to load a simple report. The original developer left years ago, and …
Gregory's Blog
Galaxie Blog 4.07 supports Azure static maps and direction routing as well as fixing many bugs due to the most recent Adobe ColdFusion update.
Adobe ColdFusion Community Blog
Ortus Solutions
Smarter Software Starts Here
In today's fast-moving digital landscape, efficiency and data-driven decision-making aren't just advantages — they're essential.
That's why Ortus Solutions is proud to launch Ortus AI, a new line of AI consulting and development services designed to help you:
Elimi...
Ben Nadel
Ben Nadel looks at how to implement Service objects in the CFWheels ColdFusion framework....
Ben Nadel
Ben Nadel creates an Alpine.js pixel art exploration....
Lucee Blog
Hi, I'm trying to debug some application errors, but the cgi.referer is always listed as a http-nio-8888-exec-x (x= a number) I am not able to see the actual referring page.
Anything I can do to get the actual referrer?
Don't forget to tell us about your stack!...
ColdFusion
Hello, I can’t connect to SQL Server Express in CF Admin. I’m on SQL Server login and I’ve enabled TCP/IP in the Configurator. Are other people having issues with SQL Server Express? Pete...
Adobe ColdFusion Community Blog
Hello - Developer edition of CF 2025 running locally on a Mac (OS = Sequoia 15.5). DMG installer. A CFQuery to an MS SQL Server datasource produces this error message: 'Error Executing Database Query. The sqlserver package is not installed. You can install the package through the CLI package ...
Lucee Blog
Debugger (or monitoring) in this version is adding results to response of functions that have returnformat="JSON" and access="remote"; and that is breaking that return format JSON resulting in many errors. This makes debugger useless, as it can't be used (in comparison to the version...
FusionReactor
We’re thrilled to announce that FusionReactor has once again dominated the G2 Summer 2025 rankings, earning an impressive 38 awards across multiple categories. This achievement continues our remarkable track record of excellence, building upon similar recognitions we’ve received over ...
Lucee Blog
I've got tired of being asking about long running controller threads, so I've added in some additional logging
https://luceeserver.atlassian.net/browse/LDEV-5670
...
Lucee Blog
Firstly, what's the controller thread? It's a background process in Lucee which
cleans up temp files
validates pooled jdbc and http connections
expires sessions and applications
polls the deploy directory
and a range of other things
Lucee Blog
We're seeing
"INFO","Controller","06/25/2025","20:07:07","controller","controller took 28481ms to execute successfully."
every few hours in the combined application log.
I'm fairly sure we don't have an application named "contr...
Hoya Haxa: A Security Research Blog
IntroductionIn this post I'm going to cover the technical details of a security sandbox escape technique that affects Adobe ColdFusion and Lucee Server. These vulnerabilities are tracked as
Hoya Haxa: A Security Research Blog
In May I had the pleasure of attending my first CFCamp, where I spoke about CFML security.
Lucee Blog
I'm using Docker in development, on a Mac (base image lucee/lucee:6.2-nginx).
When I load the Lucee admin page, the browser is consistently taking over 20 seconds to load any request to /lucee/admin/server.cfm. This includes the main page, as well as any xhr reque...
Lucee Blog
I've run into an issue in Lucee 5-7 which differs from ACF and seems like a bug to me related to how safe operators are working.
In the following code, I would expect the call to shouldThrowError() to return an exception, because throwError() will alw...
FusionReactor
Adobe's ColdFusion 2025 Update 2 introduces not only security fixes and bug resolutions, but also two new JVM flags that provide developers with more control over remote method behavior and system probe execution. In this post, we'll explain what these …
Adobe ColdFusion Community Blog
Hi Experts,We recently upgraded our ColdFusion 2023 environment from Update 10 to Update 12. After the upgrade, we encountered an issue in one of our applications that handles PDF uploads and validation.Previously, we used the IsPDFObject(mytempPDFObj)
Ortus Solutions
We're excited to announce the release of BVM (BoxLang Version Manager) v1.14, bringing significant enhancements that make BoxLang development even more seamless and productive. What's crazy is that we have already released 14 minor versions of this amazing little version manager. This release introd...
Lucee Blog
For anyone testing their Coldbox app on Lucee 7, you will likely encounter an invalid syntax, variables are not supported error on boot. This is due to this breaking change in Lu...
Charlie Arehart - Server Troubleshooting
Today begins the first of several live hour-long presentations over the next few days as part of Adobe ColdFusion Dev Week, which I also blogged more about on the Adobe CF portal.
I want to announce here that I will be offering the first talk of t...
[More]
...
FusionReactor
Multi-Party Computation (MPC) servers are emerging as critical infrastructure for organizations that require collaborative analytics without compromising data privacy. In the observability space, these specialized servers enable a new paradigm: gaining collective insights from distributed systems...
FusionReactor
Multi-Party Computation (MPC) servers are emerging as critical infrastructure for organizations that require collaborative analytics without compromising data privacy. In the observability space, these specialized servers enable a new paradigm: gaining collective insights from distributed systems...
Ortus Solutions
We're thrilled to announce the release of BoxLang v1.3.0! This significant update brings exciting new features, substantial performance improvements, and critical bug fixes that will enhance your development workflow and application reliability....
Pete Freitag
The recent ColdFusion security hotfix that changed searchImplicitScopes defaults has been keeping developers busy fixing unscoped variables. This can be pretty tedious, and not all variables technically need a scope (such as...
ColdFusion
Adobe ColdFusion Devweek 2025 starts today, June 23 2025. While it has been announced in other places, I noticed there was no blog post here which is where some might seek it out. First up on today, June 23, is a free day-long online workshop, “ColdFusion: From Fundamentals to Advanced Develop...
Lucee Blog
Hi there!
We recently updated our dev environment to the latest version of Lucee. In this context, we've also updated the underlying JVM and Tomcat versions.
Setup now:
OS: Debian 6.1.0-22-amd64
Java Version: 21.0.7 (Eclipse ...
Lucee Blog
Hi there!
We recently updated our dev environment to the latest version of Lucee. In this context, we've also updated the underlying JVM and Tomcat versions.
Setup now:
OS: Debian 6.1.0-22-amd64
Java Version: 21.0.7 (Eclipse ...
Lucee Blog
Hi there!
We recently updated our dev environment to the latest version of Lucee. In this context, we've also updated the underlying JVM and Tomcat versions.
Setup now:
OS: Debian 6.1.0-22-amd64
Java Version: 21.0.7 (Eclipse ...
FusionReactor
In today's security-conscious environment, authentication isn't just a technical requirement—it's a core component of maintaining system integrity and trust. For the FusionReactor community, where reliability and control are paramount, our latest update brings meaningful improvements design...
FusionReactor
In today's security-conscious environment, authentication isn't just a technical requirement—it's a core component of maintaining system integrity and trust. For the FusionReactor community, where reliability and control are paramount, our latest update brings meaningful improvements design...
Adobe ColdFusion Community Blog
If I leave my page long enough for the user login session to timeout, then reload the page, I get an HTML rendering of the page. Then if I reload it again, the page renders normally. It happens on at least two pages I have tested so far. Firefox gives an engimatic error "Syntax...
Ben Nadel
Ben Nadel explores Sortable.js as a way to create effortless drag-and-drop experiences on the web....
Gregory's Blog
Hi all, I have found several bugs after the most recent Adobe updates and will try to address them in the next update.
Lucee Blog
Just letting people know that currently copilot paid versions (which is cheap as chips) have FREE overage. I'm clocking $10 a day in overage fees (for thousands of requests) that I dont have to pay while it's in preview (not really preview IMHO, but anyway.
In other words you ...
Lucee Blog
Just letting people know that currently copilot paid versions (which is cheap as chips) have FREE overage. I'm clocking $10 a day in overage fees (for thousands of requests) that I dont have to pay while it's in preview (not really preview IMHO, but anyway.
In other words you ...
Pete Freitag
Recently I was testing a client's rate limiting configuration, so I needed to send a bunch of requests to a URL within a short period of time to see if it was working properly. I wrote up a quick bash script to loop from 1 to 20 with curl requests and sleeping for a short period between each req...
Ortus Solutions
We're excited to announce the release of BoxLang AI v1.2, a major update to the BoxLang AI module that powers intelligent applications with a unified AI abstraction layer across even more providers: OpenAI, Claude, Grok, Gemini, and more. This release packs new features for providers, tools, debuggi...
|