yaffa vulnerable to Cross Site Scripting
Moderate severity
GitHub Reviewed
Published
Apr 7, 2026
to the GitHub Advisory Database
•
Updated Apr 10, 2026
Description
Published by the National Vulnerability Database
Apr 7, 2026
Published to the GitHub Advisory Database
Apr 7, 2026
Reviewed
Apr 10, 2026
Last updated
Apr 10, 2026
yaffa v2.0.0 is vulnerable to Cross Site Scripting (XSS). An attacker can inject malicious JavaScript into the "Add Account Group" function on the account-group page, allowing execution of arbitrary script in the context of users who view the affected page.
References