Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-pq95-94c9-j987 | yaffa vulnerable to Cross Site Scripting |
Wed, 15 Apr 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Cross‑Site Scripting Vulnerability in yaffa Add Account Group Function |
Tue, 14 Apr 2026 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:kantorge:yaffa:2.0.0:*:*:*:*:*:*:* |
Mon, 13 Apr 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Cross‑Site Scripting Vulnerability in yaffa Add Account Group Function |
Fri, 10 Apr 2026 10:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Cross Site Scripting in Yaffa "Add Account Group" Feature | |
| Weaknesses | CWE-79 |
Thu, 09 Apr 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-94 | |
| Metrics |
cvssV3_1
|
Thu, 09 Apr 2026 08:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Kantorge
Kantorge yaffa |
|
| Vendors & Products |
Kantorge
Kantorge yaffa |
Wed, 08 Apr 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Cross Site Scripting in Yaffa "Add Account Group" Feature | |
| Weaknesses | CWE-79 |
Tue, 07 Apr 2026 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | yaffa v2.0.0 is vulnerable to Cross Site Scripting (XSS). An attacker can inject malicious JavaScript into the "Add Account Group" function on the account-group page, allowing execution of arbitrary script in the context of users who view the affected page. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-04-09T13:59:20.267Z
Reserved: 2026-01-09T00:00:00.000Z
Link: CVE-2025-70844
Updated: 2026-04-09T13:58:43.232Z
Status : Analyzed
Published: 2026-04-07T17:16:26.297
Modified: 2026-04-14T15:46:12.757
Link: CVE-2025-70844
No data.
OpenCVE Enrichment
Updated: 2026-04-15T16:30:09Z
Github GHSA