CVE-2025-63842
MEDIUM
NVD
CVSS Score
5.4
Severity
MEDIUM
Published
Sep 14, 2026
Vendor
unknown
Description
A Cross-Site Scripting (XSS) vulnerability in the web backend for the Repetico app 1.9.7.31 for Android allows a remote authenticated user to execute arbitrary JavaScript code in the app's context via crafted input in the multiple-choice question text field.