See SA-CONTRIB-2015-002 - Course - Cross Site Scripting (XSS)
There are no other changes in this release.
SA-CONTRIB-2015-013 - Field Display Label - Cross Site Scripting (XSS).
See SA-CONTRIB-2015-011 - Todo Filter - Cross Site Request Forgery (CSRF)
Also includes earlier fix: #803224: Checking an item off the list doesn't make it permanent
See SA-CONTRIB-2015-005 - WikiWiki - SQL injection.