Known Vulnerabilities for products from Fava Project
Listed below are 3 of the newest known vulnerabilities associated with the vendor "Fava Project".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2022-2589 json | Cross-site Scripting (XSS) - Reflected in GitHub repository beancount/fava prior to 1.22.3. | 6.1 - MEDIUM | 2022-08-01 | 2022-08-04 |
| CVE-2022-2523 json | Cross-site Scripting (XSS) - Reflected in GitHub repository beancount/fava prior to 1.22.2. | 6.1 - MEDIUM | 2022-07-25 | 2022-07-27 |
| CVE-2022-2514 json | The time and filter parameters in Fava prior to v1.22 are vulnerable to reflected XSS due to the lack of escaping of error me... | 6.1 - MEDIUM | 2022-07-25 | 2022-07-27 |