yaffa v2.0.0 is vulnerable to Cross Site Scripting (XSS). An attacker can inject malicious JavaScript into the "Add Account Group" function on the account-group page, allowing execution of arbitrary script in the context of users who view the affected page.
References
| Link | Resource |
|---|---|
| https://github.com/J4cky1028/vulnerability-research/tree/main/CVE-2025-70844 | Third Party Advisory |
| https://github.com/kantorge/yaffa | Product |
Configurations
History
14 Apr 2026, 15:46
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Kantorge
Kantorge yaffa |
|
| References | () https://github.com/J4cky1028/vulnerability-research/tree/main/CVE-2025-70844 - Third Party Advisory | |
| References | () https://github.com/kantorge/yaffa - Product | |
| CPE | cpe:2.3:a:kantorge:yaffa:2.0.0:*:*:*:*:*:*:* |
09 Apr 2026, 14:16
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 6.1 |
| CWE | CWE-94 |
07 Apr 2026, 17:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-04-07 17:16
Updated : 2026-04-14 15:46
NVD link : CVE-2025-70844
Mitre link : CVE-2025-70844
CVE.ORG link : CVE-2025-70844
JSON object : View
Products Affected
kantorge
- yaffa
CWE
CWE-94
Improper Control of Generation of Code ('Code Injection')
