CVE-2025-63842
A Cross-Site Scripting (XSS) vulnerability in the web backend for the Repetico app 1.9.7.31 for Android allows a remote authenticated user to execute arbitrary JavaScript code in the app's context via crafted input in the multiple-choice question text field.
- Published Sep 14, 2026
- CVSS 5.4 medium
- 0.2% chance of exploitation in the next 30 days (EPSS)