Medium severity6.1OSV Advisory· Published Jan 15, 2026· Updated Jun 17, 2026
CVE-2025-65368
CVE-2025-65368
Description
SparkyFitness v0.15.8.2 is vulnerable to Cross Site Scripting (XSS) via user input and LLM output.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3v0.01, v0.02, v0.03, …+ 2 more
- (no CPE)range: v0.01, v0.02, v0.03, …
- cpe:2.3:a:codewithcj:sparkyfitness:*:*:*:*:*:*:*:*range: <=0.15.8.2
- (no CPE)range: =0.15.8.2
Patches
Vulnerability mechanics
References
1- github.com/CodeWithCJ/SparkyFitness/security/advisories/GHSA-j7x6-6678-2xqpnvdExploitVendor Advisory
News mentions
0No linked articles in our index yet.