CVE-2025-40642
Reflected Cross-Site Scripting (XSS) vulnerability in WebWork, which allows remote attackers to execute arbitrary code through the ‘q’ and ‘engine’ request parameters in /search.
More information : https://www.incibe.es/en/incibe-cert/notices/aviso/reflected-cross-site-scripting-xss-webwork
