LimeSurvey 4.3.2 allows reflected XSS because application/controllers/LSBaseController.php lacks code to validate parameters.
{ "cpes": [ "cpe:2.3:a:limesurvey:limesurvey:4.3.2:*:*:*:*:*:*:*" ], "severity": "Medium" }