Freeflow Core
by Xerox
CVEs (9)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-8356 | Cri | 0.65 | 9.8 | 0.15 | Aug 8, 2025 | In Xerox FreeFlow Core version 8.0.4, an attacker can exploit a Path Traversal vulnerability to access unauthorized files on the server. This can lead to Remote Code Execution (RCE), allowing the attacker to run arbitrary commands on the system. | ||
| CVE-2026-2251 | Cri | 0.64 | 9.8 | 0.00 | Feb 27, 2026 | Improper limitation of a pathname to a restricted directory (Path Traversal) vulnerability in Xerox FreeFlow Core allows unauthorized path traversal leading to RCE. This issue affects Xerox FreeFlow Core versions up to and including 8.0.7. Please consider upgrading to… | ||
| CVE-2024-47557 | Hig | 0.54 | 8.3 | 0.01 | Oct 7, 2024 | Pre-Auth RCE via Path Traversal | ||
| CVE-2024-47556 | Hig | 0.54 | 8.3 | 0.01 | Oct 7, 2024 | Pre-Auth RCE via Path Traversal | ||
| CVE-2024-47555 | Hig | 0.54 | 8.3 | 0.00 | Oct 7, 2024 | Missing Authentication - User & System Configuration | ||
| CVE-2026-2252 | Hig | 0.49 | 7.5 | 0.00 | Feb 27, 2026 | An XML External Entity (XXE) vulnerability allows malicious user to perform Server-Side Request Forgery (SSRF) via crafted XML input containing malicious external entity references. This issue affects Xerox FreeFlow Core versions up to and including 8.0.7. Please consider… | ||
| CVE-2025-8355 | Hig | 0.49 | 7.5 | 0.07 | Aug 8, 2025 | In Xerox FreeFlow Core version 8.0.4, improper handling of XML input allows injection of external entities. An attacker can craft malicious XML containing references to internal URLs, this results in a Server-Side Request Forgery (SSRF). | ||
| CVE-2024-47559 | Hig | 0.49 | 7.6 | 0.01 | Oct 7, 2024 | Authenticated RCE via Path Traversal | ||
| CVE-2024-47558 | Hig | 0.49 | 7.6 | 0.01 | Oct 7, 2024 | Authenticated RCE via Path Traversal |
- risk 0.65cvss 9.8epss 0.15
In Xerox FreeFlow Core version 8.0.4, an attacker can exploit a Path Traversal vulnerability to access unauthorized files on the server. This can lead to Remote Code Execution (RCE), allowing the attacker to run arbitrary commands on the system.
- risk 0.64cvss 9.8epss 0.00
Improper limitation of a pathname to a restricted directory (Path Traversal) vulnerability in Xerox FreeFlow Core allows unauthorized path traversal leading to RCE. This issue affects Xerox FreeFlow Core versions up to and including 8.0.7. Please consider upgrading to…
- risk 0.54cvss 8.3epss 0.01
Pre-Auth RCE via Path Traversal
- risk 0.54cvss 8.3epss 0.01
Pre-Auth RCE via Path Traversal
- risk 0.54cvss 8.3epss 0.00
Missing Authentication - User & System Configuration
- risk 0.49cvss 7.5epss 0.00
An XML External Entity (XXE) vulnerability allows malicious user to perform Server-Side Request Forgery (SSRF) via crafted XML input containing malicious external entity references. This issue affects Xerox FreeFlow Core versions up to and including 8.0.7. Please consider…
- risk 0.49cvss 7.5epss 0.07
In Xerox FreeFlow Core version 8.0.4, improper handling of XML input allows injection of external entities. An attacker can craft malicious XML containing references to internal URLs, this results in a Server-Side Request Forgery (SSRF).
- risk 0.49cvss 7.6epss 0.01
Authenticated RCE via Path Traversal
- risk 0.49cvss 7.6epss 0.01
Authenticated RCE via Path Traversal