See SA-CONTRIB-2015-025 - Patterns - Cross Site Request Forgery (CSRF).
This is a security release which includes no changes to the release tagged as 6.x-1.2, other than a fix for the security issue: SA-CONTRIB-2015-024 - Alfresco - Cross Site Request Forgery (CSRF)
See DRUPAL-SA-CONTRIB-2015-028
See SA-CONTRIB-2015-027 - Quizzler - Cross Site Scripting (XSS)
See SA-CONTRIB-2015-026 - Taxonews - Cross Site Scripting (XSS)