Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-11953 | TwsCachedXPathAPI in Convertigo through 8.3.4 does not restrict the use of commons-jxpath APIs. |
| Link | Providers |
|---|---|
| https://github.com/convertigo/convertigo/issues/898 |
|
Tue, 13 May 2025 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Convertigo
Convertigo convertigo |
|
| Weaknesses | CWE-74 | |
| CPEs | cpe:2.3:a:convertigo:convertigo:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Convertigo
Convertigo convertigo |
Mon, 21 Apr 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sun, 20 Apr 2025 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-749 | |
| Metrics |
cvssV3_1
|
Sun, 20 Apr 2025 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | TwsCachedXPathAPI in Convertigo through 8.3.4 does not restrict the use of commons-jxpath APIs. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-04-21T13:32:03.357Z
Reserved: 2025-04-20T00:00:00.000Z
Link: CVE-2025-43955
Updated: 2025-04-21T13:30:23.680Z
Status : Analyzed
Published: 2025-04-20T20:15:13.553
Modified: 2025-05-13T14:26:27.853
Link: CVE-2025-43955
No data.
OpenCVE Enrichment
No data.
EUVD