Budget version v0.19.0-16-gd2ebb2b allows remote attackers to inject malicious scripts in line 44 TransactionController.php.
'label' => '<div class="row"><div class="row__column row__column--compact row__column--middle mr-1"><div style="width: 15px; height: 15px; border-radius: 2px; background: #' . $tag->color . ';"></div></div><div class="row__column row__column--middle">' . $tag->name . '</div></div>' // phpcs:ignore