Vulnerabilities
Vulnerable Software
Xerox:  >> Freeflow Core  Security Vulnerabilities
In Xerox FreeFlow Core version 8.0.4, an attacker can exploit a Path Traversal vulnerability to access unauthorized files on the server. This can lead to Remote Code Execution (RCE), allowing the attacker to run arbitrary commands on the system.
CVSS Score
9.8
EPSS Score
0.007
Published
2025-08-08
In Xerox FreeFlow Core version 8.0.4, improper handling of XML input allows injection of external entities. An attacker can craft malicious XML containing references to internal URLs, this results in a Server-Side Request Forgery (SSRF).
CVSS Score
7.5
EPSS Score
0.001
Published
2025-08-08
Pre-Auth RCE via Path Traversal
CVSS Score
8.3
EPSS Score
0.003
Published
2024-10-07
Pre-Auth RCE via Path Traversal
CVSS Score
8.3
EPSS Score
0.003
Published
2024-10-07
Authenticated RCE via Path Traversal
CVSS Score
7.6
EPSS Score
0.002
Published
2024-10-07
Authenticated RCE via Path Traversal
CVSS Score
7.6
EPSS Score
0.002
Published
2024-10-07


Contact Us

Shodan ® - All rights reserved