pfSense CE through 2.6.0 and pfSense Plus before 22.05 allow XSS in the WebGUI via URL Table Alias URL parameters.
https://redmine.pfsense.org/issues/13060
https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-33616
https://docs.netgate.com/downloads/pfSense-SA-22_05.webgui.asc