CVE-2025-43955CRITICAL 2.2EPSS p26.5%
CVE-2025-43955CVE-2025-43955
convertigo / convertigo
Description
TwsCachedXPathAPI in Convertigo versions before 8.3.11 did not restrict commons-jxpath functions, which could allow expression injection in contexts where an attacker can influence an evaluated XPath expression. Convertigo 8.3.11 fixes the issue by assigning an empty FunctionLibrary to JXPath contexts.
Scoring
| CVSS 3.1 | 2.2 (CRITICAL) |
| Vector | CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:L/A:N |
| EPSS | 0.35% probability of exploitation · percentile 26.5% · 2026-10-06T12:00:23Z |
| Published | 2025-04-20 |
| Last modified | 2026-08-28 |
Underlying weaknesses· 2
References
2
| Type | Target | Confidence | Tier |
|---|---|---|---|
| Weakness | Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')cwe-74 | 0% | live |
| Weakness | Exposed Dangerous Method or Functioncwe-749 | 0% | live |
Related by meaning· 6
Nearest entities by semantic similarity across the cs-graph corpus.