Make sure that user names and email addresses are sanitized before being displayed to the user. Security issue by hefox - see SA-CONTRIB-2012-119 - Excluded Users - Cross Site Scripting (XSS) for more details.
Making a release so can assign issues to it.
Drupal 6 update
This version is just updated to be compatible with Drupal-5