Reflected Cross-Site Scripting (XSS) vulnerability in IsMyGym by Zuinq Studio. This vulnerability allows an attacker to execute JavaScript code in the victim's browser by sending them a malicious URL with '/<PATH>.php/<XSS>'. This vulnerability can be exploited to steal sensitive user data, such as session cookies, or to perform actions on behalf of the user.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
The vulnerability has been fixed by Zuinq Studio's team in the latest version.
Workaround
No workaround given by the vendor.
References
History
Tue, 20 Jan 2026 12:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Reflected Cross-Site Scripting (XSS) vulnerability in IsMyGym by Zuinq Studio. This vulnerability allows an attacker to execute JavaScript code in the victim's browser by sending them a malicious URL with '/<PATH>.php/<XSS>'. This vulnerability can be exploited to steal sensitive user data, such as session cookies, or to perform actions on behalf of the user. | |
| Title | Reflected Cross-Site Scripting (XSS) in IsMyGym | |
| First Time appeared |
Zuinq Studio
Zuinq Studio ismygym |
|
| CPEs | cpe:2.3:a:zuinq_studio:ismygym:all_versions:*:*:*:*:*:*:* | |
| Vendors & Products |
Zuinq Studio
Zuinq Studio ismygym |
|
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: INCIBE
Published:
Updated: 2026-01-20T16:50:52.652Z
Reserved: 2025-04-16T09:09:35.597Z
Link: CVE-2025-41081
No data.
Status : Received
Published: 2026-01-20T13:16:02.623
Modified: 2026-01-20T13:16:02.623
Link: CVE-2025-41081
No data.
OpenCVE Enrichment
No data.
Weaknesses
No weakness.