CVE-2025-8356
critical · 9.8In Xerox FreeFlow Core version 8.0.4, an attacker can exploit a Path Traversal vulnerability to access unauthorized files on the server. This can lead to Remote Code Execution (RCE), allowing the attacker to run arbitrary commands on the system.
9.8
CVSS
17.7%
EPSS (exploit prob.)
97th
EPSS percentile
2025-08-08
Published
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weaknesses
CWE-22CWE-94
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| xerox | freeflow_core | 8.0.4 |
Check a specific version with /api/v1/cve/match.
References
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2025-8356