CVE-2025-40642EPSS p41.8%

CVE-2025-40642CVE-2025-40642

Description

Reflected Cross-Site Scripting (XSS) vulnerability in WebWork, which allows remote attackers to execute arbitrary code through the 'q' and 'engine' request parameters in /search.

Scoring

EPSS0.52% probability of exploitation · percentile 41.8% · 2026-10-05T12:00:23Z
Last modified2026-09-30
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.