{"id":"CVE-2025-40642","title":"Reflected Cross-Site Scripting (XSS) vulnerability in WebWork, which allows remote attackers to execute arbitrary code through the 'q' and 'engine' request parameters in /search.","summary":"Reflected Cross-Site Scripting (XSS) vulnerability in WebWork, which allows remote attackers to execute arbitrary code through the 'q' and 'engine' request parameters in /search.","severity":"none","cwe":["CWE-79"],"published":"2025-09-08","updated":"2026-09-30","sourceUpdated":"2026-09-30T23:10:00.237","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-40642","references":[{"url":"https://www.incibe.es/en/incibe-cert/notices/aviso/reflected-cross-site-scripting-xss-webwork","label":"cve-coordination@incibe.es"}],"tags":["nvd"],"epss":0.00515,"epssPercentile":0.41614,"ingestedAt":"2026-09-30T23:29:32.372Z","slug":"CVE-2025-40642","body":"## Overview\n\nReflected Cross-Site Scripting (XSS) vulnerability in WebWork, which allows remote attackers to execute arbitrary code through the 'q' and 'engine' request parameters in /search.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}