Some issues with field title and several other field attributes have been fixed.
SA-CONTRIB-2014-112 - Node Field - Cross Site Scripting (XSS).
See SA-CONTRIB-2015-073 - Trick Question - Cross Site Scripting (XSS)
Security release, see SA-CONTRIB-2014-109 - Freelinking - Cross Site Scripting (XSS).
Additional issues addressed in this release:
Additional issue addressed in this release:
SA-CONTRIB-2014-104 - Addressfield Tokens - Cross Site Scripting
Release to address some filtering issues and a minor bug report.