{"id":"CVE-2025-43955","details":"TwsCachedXPathAPI in Convertigo versions before 8.3.11 did not restrict commons-jxpath functions, which could allow expression injection in contexts where an attacker can influence an evaluated XPath expression. Convertigo 8.3.11 fixes the issue by assigning an empty FunctionLibrary to JXPath contexts.","modified":"2026-08-30T08:17:12.402855Z","published":"2025-04-20T00:00:00Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/43xxx/CVE-2025-43955.json","cna_assigner":"mitre","cwe_ids":["CWE-749"]},"references":[{"type":"WEB","url":"https://github.com/convertigo/convertigo/blob/8.3.11/CHANGELOG.md#8311"},{"type":"WEB","url":"https://github.com/convertigo/convertigo/releases/tag/8.3.11"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/43xxx/CVE-2025-43955.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-43955"},{"type":"REPORT","url":"https://github.com/convertigo/convertigo/issues/898"},{"type":"FIX","url":"https://github.com/convertigo/convertigo/commit/431d1bfeb360a55f4ed299cc3aa287cc5c6357e1"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/convertigo/convertigo","events":[{"introduced":"0"},{"fixed":"572cb7d16425ea66304d4143aae25a0bc8a2ae3e"},{"fixed":"431d1bfeb360a55f4ed299cc3aa287cc5c6357e1"}],"database_specific":{"cpe":"cpe:2.3:a:convertigo:convertigo:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"fixed":"8.3.11"}],"source":["CPE_RANGE","REFERENCES"]}}],"versions":["8.3.10","8.3.9","8.3.8","8.3.7","8.3.6","8.3.5","8.3.4","8.3.3","8.3.2","8.3.0","8.2.0","8.1.0","8.0.2","8.0.1","8.0.0","7.6.0","7.5.0","7.4.2","7.4.1","7.4.0","7.3.0","7.2.0","7.1.0","7.0.0","6.1.2","6.1.1","6.1.0","6.0.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-43955.json","vanir_signatures_modified":"2026-08-30T08:17:12Z","vanir_signatures":[{"signature_version":"v1","source":"https://github.com/convertigo/convertigo/commit/431d1bfeb360a55f4ed299cc3aa287cc5c6357e1","target":{"file":"engine/src/com/twinsoft/convertigo/engine/util/TwsCachedXPathAPI.java","function":"selectList"},"deprecated":false,"digest":{"function_hash":"138300023471986760477911939568397762320","length":781},"id":"CVE-2025-43955-0333db59","signature_type":"Function"},{"deprecated":false,"digest":{"threshold":0.9,"line_hashes":["91494106475595540842734059106022339183","213500837413335527599825861845672538238","37507489785685358008319893804181226723","59615455652915057957081413890134043375","287144529836118375281032324385704380973","272765437824718992674471073254842038960","308810885826372392752763486772828910811","237867893688906094959923546508019524252","303393777598709252326304638141137586209","286777339210556384980026288057692439673","297635343074234071327959549494770805483","310614783231285301527021970509101338977","177961231800585469473464212457998640444","62535345461186410189354148395563459220","238029080806377923246794379426720765526"]},"id":"CVE-2025-43955-aacdff33","signature_type":"Line","signature_version":"v1","source":"https://github.com/convertigo/convertigo/commit/431d1bfeb360a55f4ed299cc3aa287cc5c6357e1","target":{"file":"engine/src/com/twinsoft/convertigo/engine/util/TwsCachedXPathAPI.java"}},{"signature_type":"Function","signature_version":"v1","source":"https://github.com/convertigo/convertigo/commit/431d1bfeb360a55f4ed299cc3aa287cc5c6357e1","target":{"file":"engine/src/com/twinsoft/convertigo/engine/util/TwsCachedXPathAPI.java","function":"selectNode"},"deprecated":false,"digest":{"function_hash":"197516100857935510878643529302702056255","length":194},"id":"CVE-2025-43955-de7be021"}]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:L/A:N"}]}