CVE-2025-63842: Repetico Web Backend

Medium severity, CVSS 5.4. EPSS: 0.2% chance of exploitation in the next 30 days.

A Cross-Site Scripting (XSS) vulnerability in the web backend for the Repetico app 1.9.7.31 for Android allows a remote authenticated user to execute arbitrary JavaScript code in the app's context via crafted input in the multiple-choice question text field.

Affected products

  • Repetico Web Backend: up to and including 2026-06-30

Published 2026-09-14. Last modified 2026-09-22.