CVE-2025-70845: A stored Cross-Site Scripting (XSS) vulnerability exists in aidiugu v1.9.1 Affected Versions: aidiugu v1.9.1 (and potentially earlier versions) Description: aidiugu version v1.9.1 contains a stored Cross-Site Scripting (XSS) vulnerability in the /setting/page where the "intro" field is not properly sanitized or escaped. This allows an attacker to inject malicious scripts into the web application, which can execute in the user's browser context. Discovery Date: February 2026 Discoverer: J4cky1028 Fixes: The vulnerability has been fixed in a subsequent release of aidiugu. References: - NVD Detail - CVE Record - aidiugu GitHub