
🚨*CVE* CVE-2025-70844 yaffa v2.0.0 is vulnerable to Cross Site Scripting (XSS). An attacker can inject malicious JavaScript into the "Add Account Group" function on the account-group page,… https://www.cve.org/CVERecord?id=CVE-2025-70844 ----- Traducción: CVE-2025-70844 yaf… http://infoflow.cloud`
Post summary
The tweet announces CVE‑2025‑70844, a Cross‑Site Scripting flaw in Yaffa v2.0.0 affecting the "Add Account Group" page, without providing PoC, exploit code, or patch details.

