LimeSurvey before v5.0.4 was discovered to contain a SQL injection vulnerability via the component /application/views/themeOptions/update.php.
{ "severity": "High", "cpes": [ "cpe:2.3:a:limesurvey:limesurvey:5.4.4:*:*:*:*:*:*:*", "cpe:2.3:a:limesurvey:limesurvey:*:*:*:*:*:*:*:*" ] }