Fava before 1.22.3 is vulnerable to reflected cross-site scripting due to improper validation on filter conversion.
References
https://nvd.nist.gov/vuln/detail/CVE-2022-2589
https://github.com/beancount/fava/commit/68bbb6e39319deb35ab9f18d0b6aa9fa7047…