CVE-2025-70846: A Stored Cross-Site Scripting (XSS) Vulnerability in Aidigu v1.9.1 Description Aidigu version v1.9.1 contains a stored Cross-Site Scripting (XSS) vulnerability in the where the "password" field is not properly sanitized or escaped. This vulnerability allows an attacker to inject malicious scripts into the web application, which can be executed in the context of the user's browser. This vulnerability has been fixed in a subsequent release of Aidigu. Affected Versions Aidigu v1.9.1 (and potentially earlier versions) Discovery Discovered by J4cky1028, Feb 2026. References https://nvd.nist.gov/vuln/detail/CVE-2025-70846 https://www.cve.org/CVERecord?id=CVE-2025-70846 https://github.com/lty628/aidigu