An XSS issue was discovered in pfSense through 2.4.4-p3. In servicescaptiveportalmac.php, the username and delmac parameters are displayed without sanitization.
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2019-16914.json"