Releases67
Frequency1 month 3 weeks
Last Release
Stars2.46K
Fava - web interface for Beancount

CVE History

CVEPublishedCVSS v3CVSS v2
6.1 MEDIUM

Cross-site Scripting (XSS) - Reflected in GitHub repository beancount/fava prior to 1.22.3.

6.1 MEDIUM

The time and filter parameters in Fava prior to v1.22 are vulnerable to reflected XSS due to the lack of escaping of error messages which contained the parameters in verbatim.

6.1 MEDIUM

Cross-site Scripting (XSS) - Reflected in GitHub repository beancount/fava prior to 1.22.2.