CVE-2026-40500EPSS p30.5%

CVE-2026-40500CVE-2026-40500

Description

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. The "Add Module from URL" feature requires superuser privileges (root-equivalent in ProcessWire) who already has unrestricted arbitrary code execution via standard module upload, making the SSRF vector incapable of providing incremental attack surface. The feature is also disabled by default and requires direct filesystem access to enable.

Scoring

EPSS0.39% probability of exploitation · percentile 30.5% · 2026-07-09T12:03:07Z
Last modified2026-07-09
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.