Teampass 2.1.26 allows reflected XSS via the index.php PATH_INFO.
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-26980.json"