The HAProxy package before 0.5916 for pfSense has XSS via the desc (aka Description) or tableactionsaclN parameter, related to haproxylisteners.php and haproxylisteners_edit.php.
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2019-8953.json"