There is a critical point in FCKeditor, who was announced some time, when detected in connectors ASP and PHP.
PHP - GeekLog v1.4.0 FckEditor File Upload Security Vulnerability
ASP - Exploiting IIS via HTMLEncode (MS08-006)
Now this vulnerability was detected in the version 8.0.1 of ColdFusion, the version 8.0 apparently does not suffer of this failure, but it is worth check.
Many local are supplying information to prevent frights.
Problem safety serious in CF 8.01
CF8 and FCKEditor Security Threat
ColdFusion 8 FCKeditor Vulnerability
I recommend disable filemanager.

I'm Pedro Claudio, ColdFusion Developer based in Rio de Janeiro. 

