CVE-2025-70844Disclosure(kantorge / yaffa)

LOWCVSS 6.1 · MEDIUM

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

yaffa v2.0.0 is vulnerable to Cross Site Scripting (XSS). An attacker can inject malicious JavaScript into the "Add Account Group" function on the account-group page, allowing execution of arbitrary script in the context of users who view the affected page.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-94

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • yaffa

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • 2 total mentions across 1 day

Affected systems

Vendors
Products
yaffa

1 version affected across 1 product

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-04-20: 2Technical Details · 2026-04-20: 204-20
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
By indicator
Full discourse2 posts
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2025-70844 yaffa v2.0.0 is vulnerable to Cross Site Scripting (XSS). An attacker can inject malicious JavaScript into the "Add Account Group" function on the account-group page,… https://www.cve.org/CVERecord?id=CVE-2025-70844 ----- Traducción: CVE-2025-70844 yaf… http://infoflow.cloud`

    Post summary

    The tweet announces CVE‑2025‑70844, a Cross‑Site Scripting flaw in Yaffa v2.0.0 affecting the "Add Account Group" page, without providing PoC, exploit code, or patch details.

    00000204
    72 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2025-70844 yaffa v2.0.0 is vulnerable to Cross Site Scripting (XSS). An attacker can inject malicious JavaScript into the "Add Account Group" function on the account-group page,… https://www.cve.org/CVERecord?id=CVE-2025-70844

    Post summary

    The post is an initial disclosure noting that yaffa v2.0.0 contains an XSS flaw in the Add Account Group function.

    00000223
    57.2K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appkantorgeyaffa2.0.0--

Explore more