Medium severityNVD Advisory· Published Sep 8, 2025· Updated Jun 17, 2026
CVE-2025-40642
CVE-2025-40642
Description
Reflected Cross-Site Scripting (XSS) vulnerability in WebWork, which allows remote attackers to execute arbitrary code through the 'q' and 'engine' request parameters in /search.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.