216.73.217.22

CVE-2025-70844

· Published 07/04/2026 17:16 · Modified 08/04/2026 21:27

Labels: CVE-2025-70844 2026-04-07CVE-2025-70844[email protected]

Essential information

Published
07/04/2026 17:16
Modified
08/04/2026 21:27
Author
Creator
CISA KEV
No
CWE

Description

yaffa v2.0.0 is vulnerable to Cross Site Scripting (XSS). An attacker can inject malicious JavaScript into the "Add Account Group" function on the account-group page, allowing execution of arbitrary script in the context of users who view the affected page.

NVD status

Status
Awaiting Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
yaffa / yaffa cpe:2.3:a:yaffa:yaffa:2.0.0:*:*:*:*:*:*:*

References