Product
xerox freeflow core
8 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2026-2252
CVE-2026-2251
CVE-2025-8356
CVE-2025-8355
CVE-2024-47559
CVE-2024-47558
CVE-2024-47557
CVE-2024-47556
< 8.1.0
An XML External Entity (XXE) vulnerability allows malicious user to perform Server-Side Request Forgery (SSRF) via crafted XML inp
< 8.1.0
Improper limitation of a pathname to a restricted directory (Path Traversal) vulnerability in Xerox FreeFlow Core allows unauthori
all versions
In Xerox FreeFlow Core version 8.0.4, an attacker can exploit a Path Traversal vulnerability to access unauthorized files on the s
all versions
In Xerox FreeFlow Core version 8.0.4, improper handling of XML input allows injection of external entities. An attacker can craft
all versions
Authenticated RCE via Path Traversal
all versions
Authenticated RCE via Path Traversal
>= 7.0 and < 7.0.11
Pre-Auth RCE via Path Traversal
>= 7.0 and < 7.0.11
Pre-Auth RCE via Path Traversal