See SA-CONTRIB-2015-051 - Term Queue - Cross Site Scripting (XSS)
Fixes SA-CONTRIB-2015-048 - Avatar Uploader - Arbitrary PHP code execution
See SA-CONTRIB-2015-044 - Taxonomy Path - Cross Site Scripting (XSS)
See SA-CONTRIB-2015-039 - Views - Multiple vulnerabilities
Changes since 7.x-3.8:
Changes since 6.x-2.16:
Changes since 6.x-3.0: