CVE-2024-31573: Xmlunit For Java

Medium severity, CVSS 4.0. EPSS: 0.3% chance of exploitation in the next 30 days.

XMLUnit for Java before 2.10.0, in the default configuration, might allow code execution via an untrusted stylesheet (used for an XSLT transformation), because XSLT extension functions are enabled.

Affected products

  • Xmlunit Xmlunit For Java: from 2.0.0, before 2.10.0 (fixed in 2.10.0)

Published 2025-10-17. Last modified 2026-10-02.