We have had a XSS issue reported in a template (thanks Thrivikram Gujarathi).

The fix is available on github at

The XSS requires the user be logged in and click a malicious link sent by a third party.

Apologies for any inconvenience.


