Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2025-70844

22
FAUCET Score

CVE-2025-70844 is a Cross-Site Scripting (XSS) vulnerability in yaffa version 2.0.0 that allows attackers to inject malicious JavaScript through the "Add Account Group" function on the account-group page. When users view affected pages containing the injected script, the malicious code executes in their browser context, potentially compromising their session or stealing sensitive information. The vulnerability carries a Medium severity rating (CVSS 6.1) with a network-based attack vector requiring no authentication or special privileges. However, exploitation requires user interaction, as victims must view a page containing the injected payload. The impact is limited to low-level confidentiality and integrity compromise, with no availability impact. There is currently no evidence of active exploitation in the wild, and the vulnerability is not listed on the Known Exploited Vulnerabilities (KEV) catalog. The EPSS score of 0.0003 indicates minimal probability of exploitation, and community attention remains low. However, the vulnerability should still be addressed through patching to prevent potential abuse.

Impacted Technologies

VendorProductVersion(s)CPE
2.0.0CPE matchmatch criteria
cpe:2.3:a:kantorge:yaffa:2.0.0:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

6.1MEDIUM

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
CHANGED
Confidentiality Impact
LOW
Integrity Impact
LOW
Availability Impact
NONE
Exploitability Score
2.8
Impact Score
2.7
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.27%
Probability of exploitation in next 30 days
EPSS Percentile
19.3%
Percentile rank of EPSS score among Peer Group
As of 2026-07-26
Model: v2026.06.15
This CVE's current EPSS score of 0.0027 is in the 19th percentile among its peer group of 26,219 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Advisories (1)

composerGHSA-pq95-94c9-j987medium

yaffa vulnerable to Cross Site Scripting

Apr 7, 2026

References

github.com / J4cky1028/vulnerability-research/tree/main/CVE-2025-70844
Third Party Advisory
github.com / kantorge/yaffa
Product