Debian 11 — fava — multiple vulnerabilities (3 CVEs) — patch and remediation guide
🟡 Medium ⏱ 10–30 min Last verified: 25 May 2026 Affected versions: Debian 11 (bullseye) 📖 ~4 min read • Source: Debian Security Tracker Related CVEs: CVE-2022-2514 CVE-2022-2523 CVE-2022-2589 Upstream summary: The time and filter parameters in Fava prior to v1.22 are vulnerable to reflected XSS due to the lack of escaping of error […]