Vulnerabilities

    GMS-2013-18 Possible XSS via is_safe_url

    GMS-2013-17 XSS in admin interface

    GMS-2013-16 Open Redirect attacks

    OSVDB-96425 Flaw in the method_missing implementation

    OSVDB-114435 CSRF token fixation attacks

    CVE-2013-4170 Potential XSS Exploit When Binding tagName to User-Supplied Data

    GMS-2013-15 Denial of Service

    CVE-2013-2115 Remote command execution due to flaw in the includeParams attribute of URL and Anchor tags

    GMS-2013-14 XSS Filter Bypass

    CVE-2013-4660 Deserialization Code Execution