Repasat has 16 CVEs on record. Disclosure cadence is accelerating: 16 in the last 90 days against 0 in the 90 before. The busiest recent month was October 2026 with 16. The median CVSS is 4.8 (medium). None have a confirmed exploitation report. The most common weakness class is CWE-79 (16).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 4.8
- Publish → KEV
- —
- Last 90 days
- 16 prev 0
Weakness classes
Products
- Repasat application 16
Worst active — by depth score
CVE-2026-95662Medium· 4.8Cross-Site Scripting vulnerability in the Repasat application26CVE-2026-59673Medium· 4.8Cross-Site Scripting vulnerability in the Repasat application26CVE-2026-59672Medium· 4.8Cross-Site Scripting vulnerability in the Repasat application26CVE-2026-59671Medium· 4.8Cross-Site Scripting vulnerability in the Repasat application26CVE-2026-59670Medium· 4.8Cross-Site Scripting vulnerability in the Repasat application26
Repasat vulnerabilities
CVEs affecting Repasat, newest first. Open any entry for full detail, references, and exploit status.
16 CVEsRSS
CVE-2026-59666Medium· 4.8Cross-Site Scripting vulnerability in the Repasat application
Cross-Site Scripting vulnerability in the Repasat application. Successful exploitation of this vulnerability could allow an attacker to trick a user into executing arbitrary code in the victim’s browser. The “nomOrigen” parameter is affe…
CVE-2026-59668Medium· 4.8Cross-Site Scripting vulnerability in the Repasat application
Cross-Site Scripting vulnerability in the Repasat application. Successful exploitation of this vulnerability could allow an attacker to trick a user into executing arbitrary code in the victim’s browser. The “nomTamano” parameter is affe…
CVE-2026-59667Medium· 4.8Cross-Site Scripting vulnerability in the Repasat application
Cross-Site Scripting vulnerability in the Repasat application. Successful exploitation of this vulnerability could allow an attacker to trick a user into executing arbitrary code in the victim’s browser. The “nomTamano” parameter is affe…
CVE-2026-59672Medium· 4.8Cross-Site Scripting vulnerability in the Repasat application
Cross-Site Scripting vulnerability in the Repasat application. Successful exploitation of this vulnerability could allow an attacker to trick a user into executing arbitrary code in the victim’s browser. The “nomGrupoEmpresarial” paramet…
CVE-2026-59673Medium· 4.8Cross-Site Scripting vulnerability in the Repasat application
Cross-Site Scripting vulnerability in the Repasat application. Successful exploitation of this vulnerability could allow an attacker to trick a user into executing arbitrary code in the victim’s browser. The “nomTipoCli” parameter is aff…
CVE-2026-59664Medium· 4.8Cross-Site Scripting vulnerability in the Repasat application
Cross-Site Scripting vulnerability in the Repasat application. Successful exploitation of this vulnerability could allow an attacker to trick a user into executing arbitrary code in the victim’s browser. The “nomServicioPrestado” paramet…
CVE-2026-59659Medium· 4.8Cross-Site Scripting vulnerability in the Repasat application
Cross-Site Scripting vulnerability in the Repasat application. Successful exploitation of this vulnerability could allow an attacker to trick a user into executing arbitrary code in the victim’s browser. The “nomZonaGeo” parameter is aff…
CVE-2026-59661Medium· 4.8Cross-Site Scripting vulnerability in the Repasat application
Cross-Site Scripting vulnerability in the Repasat application. Successful exploitation of this vulnerability could allow an attacker to trick a user into executing arbitrary code in the victim’s browser. The “nomRuta” parameter is affect…
CVE-2026-59660Medium· 4.8Cross-Site Scripting vulnerability in the Repasat application
Cross-Site Scripting vulnerability in the Repasat application. Successful exploitation of this vulnerability could allow an attacker to trick a user into executing arbitrary code in the victim’s browser. The “nomTransportista” parameter …
CVE-2026-59662Medium· 4.8Cross-Site Scripting vulnerability in the Repasat application
Cross-Site Scripting vulnerability in the Repasat application. Successful exploitation of this vulnerability could allow an attacker to trick a user into executing arbitrary code in the victim’s browser. The “nomCompetidor” parameter is …
CVE-2026-95662Medium· 4.8Cross-Site Scripting vulnerability in the Repasat application
Cross-Site Scripting vulnerability in the Repasat application. Successful exploitation of this vulnerability could allow an attacker to trick a user into executing arbitrary code in the victim’s browser. The “nomCompetidor” parameter is …
CVE-2026-59665Medium· 4.8Cross-Site Scripting vulnerability in the Repasat application
Cross-Site Scripting vulnerability in the Repasat application. Successful exploitation of this vulnerability could allow an attacker to trick a user into executing arbitrary code in the victim’s browser. The “nomMotivo” parameter is affe…
CVE-2026-59663Medium· 4.8Cross-Site Scripting vulnerability in the Repasat application
Cross-Site Scripting vulnerability in the Repasat application. Successful exploitation of this vulnerability could allow an attacker to trick a user into executing arbitrary code in the victim’s browser. The “nomDelegacion” parameter is …
CVE-2026-59669Medium· 4.8Cross-Site Scripting vulnerability in the Repasat application
Cross-Site Scripting vulnerability in the Repasat application. Successful exploitation of this vulnerability could allow an attacker to trick a user into executing arbitrary code in the victim’s browser. The “name” parameter is affected …
CVE-2026-59670Medium· 4.8Cross-Site Scripting vulnerability in the Repasat application
Cross-Site Scripting vulnerability in the Repasat application. Successful exploitation of this vulnerability could allow an attacker to trick a user into executing arbitrary code in the victim’s browser. The “nomListaValidacion” paramete…
CVE-2026-59671Medium· 4.8Cross-Site Scripting vulnerability in the Repasat application
Cross-Site Scripting vulnerability in the Repasat application. Successful exploitation of this vulnerability could allow an attacker to trick a user into executing arbitrary code in the victim’s browser. The endpoint “/es/datatables/gete…