LimeSurvey 4.3.2 allows reflected XSS because application/controllers/LSBaseController.php lacks code to validate parameters.
{
"cpes": [
"cpe:2.3:a:limesurvey:limesurvey:4.3.2:*:*:*:*:*:*:*",
"cpe:2.3:a:limesurvey:limesurvey:*:*:*:*:*:*:*:*"
],
"severity": "Medium"
}