CVE-2025-43955

Executive Summary

Convertigo versions prior to 8.3.11 expose a vulnerability in TwsCachedXPathAPI where commons-jxpath functions are not restricted, enabling attackers to inject arbitrary XPath expressions. This can lead to unauthorized data access or manipulation. The flaw is mitigated in 8.3.11 by assigning an empty FunctionLibrary to JXPath contexts.


Authoritative CVE Metadata - CVSS Base Score: 2.2 (LOW) - Published: 2025-04-20T20:15:13.553 - Last Modified: 2026-08-27T15:46:28.053

Original Description: TwsCachedXPathAPI in Convertigo versions before 8.3.11 did not restrict commons-jxpath functions, which could allow expression injection in contexts where an attacker can influence an evaluated XPath expression. Convertigo 8.3.11 fixes the issue by assigning an empty FunctionLibrary to JXPath contexts.

"If you love someone, set them free. If they come back they're yours; if they don't they never were."

— Richard Bach
Source: NVD