helpers.py in Flask-Admin 1.5.2 has Reflected XSS via a crafted URL.
"https://github.com/pypa/advisory-database/blob/main/vulns/flask-admin/PYSEC-2018-54.yaml"