Since 7.x-2.10:
Backwards incompatible changes: 0 Bug fixes: 8 Enhancements: 8 New features: 1 Documentation changes: 0 Other changes: 0
by ojohansson: Fixed CSRF + Open Redirect issues. See DRUPAL-SA-CONTRIB-2015-016 - Tadaa! - Multiple vulnerabilities by Erik.Johansson: Fixed parse error. by Erik.Johansson: Added Tadaa toolbar submodule.
A XSS vulnerability is fixed in this release. See SA-CONTRIB-2015-015 - Term Merge - Cross Site Scripting (XSS)
SA-CONTRIB-2015-017 - Room Reservations - Cross Site Scripting (XSS)
also includes everything in -dev not previously captured in 1.0 rel; this includes numerous feature additions and bug fixes.
Addresses XSS and CSRF vulnerabilities. For more information see SA-CONTRIB-2015-014 - Wishlist - Multiple vulnerabilities