Use confirmation forms to prevent CSRF in administrative areas. See SA-CONTRIB-2015-012 - Jammer - Cross Site Request Forgery (CSRF)
Security update: See SA-CONTRIB-2015-006 - Cloudwords for Multilingual Drupal - Multiple vulnerabilities
Features: Add in api hook on before node save on entity translation and node translation to allow alteration of imported data support for translatable field collections fields using entity translation
This release introduces security fixes, see SA-CONTRIB-2015-003
SA-CONTRIB-2015-001 - OPAC - Cross-Site Request Forgery (CSRF).
Fix for security issue SA-CONTRIB-2014-126 - Open Atrium - Multiple vulnerabilities
Content access will need to be rebuilt to solve one of the issues.