# CVE-2025-43955

## Summary

- **CVE ID:** CVE-2025-43955
- **Severity:** LOW
- **CVSS Score:** 2.2 (CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:L/A:N)
- **CWE:** CWE-749
- **Published:** Apr 20, 2025
- **Last Modified:** Aug 26, 2026

## Description

TwsCachedXPathAPI in Convertigo through 8.3.4 does not restrict the use of commons-jxpath APIs.

## Affected Products

- Convertigo — Convertigo (0)

## References

- [CNA](https://github.com/convertigo/convertigo/issues/898)
- [CNA](https://github.com/convertigo/convertigo/commit/431d1bfeb360a55f4ed299cc3aa287cc5c6357e1)
- [CNA](https://github.com/convertigo/convertigo/blob/8.3.11/CHANGELOG.md#8311)
- [CNA](https://github.com/convertigo/convertigo/releases/tag/8.3.11)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.35%
- **EPSS Percentile:** 28.5

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-17._