Vendor
Fava Project
Products
1
CVEs
3
Across products
3
Status
Private
Products
1- 3 CVEs
Recent CVEs
3| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-2589 | Med | 0.33 | 6.1 | 0.01 | Aug 1, 2022 | Cross-site Scripting (XSS) - Reflected in GitHub repository beancount/fava prior to 1.22.3. | ||
| CVE-2022-2523 | Med | 0.33 | 6.1 | 0.01 | Jul 25, 2022 | Cross-site Scripting (XSS) - Reflected in GitHub repository beancount/fava prior to 1.22.2. | ||
| CVE-2022-2514 | Med | 0.33 | 6.1 | 0.01 | Jul 25, 2022 | The time and filter parameters in Fava prior to v1.22 are vulnerable to reflected XSS due to the lack of escaping of error messages which contained the parameters in verbatim. |
- risk 0.33cvss 6.1epss 0.01
Cross-site Scripting (XSS) - Reflected in GitHub repository beancount/fava prior to 1.22.3.
- risk 0.33cvss 6.1epss 0.01
Cross-site Scripting (XSS) - Reflected in GitHub repository beancount/fava prior to 1.22.2.
- risk 0.33cvss 6.1epss 0.01
The time and filter parameters in Fava prior to v1.22 are vulnerable to reflected XSS due to the lack of escaping of error messages which contained the parameters in verbatim.