🔐 CVE Alert

CVE-2026-59660

UNKNOWN 0.0

Multiple vulnerabilities in the Repasat application

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Cross-Site Scripting vulnerability in the Repasat application. Successful exploitation of this vulnerability could allow an attacker to trick a user into executing arbitrary code in the victim’s browser. The “nomTransportista” parameter is affected – endpoint “/es/carriers/update”.

CWE CWE-79
Vendor repasat
Product repasat application
Published Oct 2, 2026
Stay Ahead of the Next One

Get instant alerts for repasat repasat application

Be the first to know when new unknown vulnerabilities affecting repasat repasat application are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

Affected Versions

Repasat / Repasat application
0 < Abril patch "20260402"

References

NVD ↗ CVE.org ↗ EPSS Data ↗
incibe.es: https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-repasat-application

Credits

David Padilla Alvarado