Vulnerabilities > Fava Project
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2022-08-01 | CVE-2022-2589 | Unspecified vulnerability in Fava Project Fava Cross-site Scripting (XSS) - Reflected in GitHub repository beancount/fava prior to 1.22.3. | 6.1 |
2022-07-25 | CVE-2022-2514 | Unspecified vulnerability in Fava Project Fava The time and filter parameters in Fava prior to v1.22 are vulnerable to reflected XSS due to the lack of escaping of error messages which contained the parameters in verbatim. | 6.1 |
2022-07-25 | CVE-2022-2523 | Cross-site Scripting vulnerability in Fava Project Fava Cross-site Scripting (XSS) - Reflected in GitHub repository beancount/fava prior to 1.22.2. | 6.1 |