The ColdFusion team has released updates for CF10 (update 16) and CF11 (update 5) to address a potential cross-site scripting attack. See

this security bulletin

for details and download links.