helpers.py in Flask-Admin 1.5.2 has Reflected XSS via a crafted URL.
flask-admin project flask-admin 1.5.2