Fava is a lightweight web-based interface for the Beancount accounting system, and its vulnerability footprint concentrates on input-handling weaknesses characteristic of web applications, specifically cross-site scripting flaws in page-generation logic. Current exploitation activity, severity breakdown, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Fava Project over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-2589MEDIUM Cross-site Scripting (XSS) - Reflected in GitHub repository beancount/fava prior to 1.22.3. | Aug 1, 2022 | 6.1 | 21 | NO | NO |
CVE-2022-2523MEDIUM Cross-site Scripting (XSS) - Reflected in GitHub repository beancount/fava prior to 1.22.2. | Jul 25, 2022 | 6.1 | 21 | NO | NO |
CVE-2022-2514MEDIUM The time and filter parameters in Fava prior to v1.22 are vulnerable to reflected XSS due to the lack of escaping of error messages which contained the parameters in verbatim. | Jul 25, 2022 | 6.1 | 17 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Fava Project.
Media articles that mention a CVE ID that affects a product developed by Fava Project — matched by CVE ID, not by vendor name.