Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2025-43955

TwsCachedXPathAPI in Convertigo versions before 8.3.11 did not restrict commons-jxpath functions, which could allow expression injection in contexts where an attacker can influence an evaluated XPath expression. Convertigo 8.3.11 fixes the issue by assigning an empty FunctionLibrary to JXPath contexts.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.003
EPSS Ranking 26.2%
CVSS Severity
CVSS v3 Score 2.2
Products affected by CVE-2025-43955


Contact Us

Shodan ® - All rights reserved