GHSA-pq95-94c9-j987

Suggest an improvement
Source
https://github.com/advisories/GHSA-pq95-94c9-j987
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/04/GHSA-pq95-94c9-j987/GHSA-pq95-94c9-j987.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-pq95-94c9-j987
Aliases
Published
2026-04-07T18:31:37Z
Modified
2026-04-10T14:26:22Z
Severity
  • 6.1 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N CVSS Calculator
Summary
yaffa vulnerable to Cross Site Scripting
Details

yaffa v2.0.0 is vulnerable to Cross Site Scripting (XSS). An attacker can inject malicious JavaScript into the "Add Account Group" function on the account-group page, allowing execution of arbitrary script in the context of users who view the affected page.

Database specific
{
    "cwe_ids":  [
        "CWE-79"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2026-04-10T14:10:56Z",
    "nvd_published_at":  "2026-04-07T17:16:26Z",
    "severity":  "MODERATE"
}
References

Affected packages

Packagist / kantorge/yaffa

Package

Name
kantorge/yaffa
Purl
pkg:composer/kantorge/yaffa

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Last Affected
2.0.0

Affected versions

0.*
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.4.0
0.5.0
0.5.1
1.*
1.0.0
1.0.1
1.0.2
1.1.0
1.1.1
1.1.2
1.2.0
1.2.1
1.2.2
1.3.0
1.4.0
1.5.0
1.5.1
1.6.0
1.6.1
1.9.0
1.10.0
1.10.1
1.11.0
1.12.0
1.12.1
1.12.2
1.12.3
1.13.0
1.13.1
1.13.2
1.13.3
1.13.4
1.13.5
1.13.6
1.13.7
1.13.8
1.13.9
1.13.10
1.14.0
1.15.0
1.15.1
2.*
2.0.0

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/04/GHSA-pq95-94c9-j987/GHSA-pq95-94c9-j987.json"