SA-CONTRIB-2014-103 - Passwordless - Cross Site Scripting (XSS)
Fixes SA-CONTRIB-2014-101 - Ubercart - Cross Site Request Forgery
Changes since 6.x-2.13:
Fixes SA-CONTRIB-2014-100 - Bad Behavior - Information Disclosure
Patching for SA-CORE-2014-005 - Drupal core - SQL injection.
Note that this release only patches the SA above and may not include other bug fixes from previous Drupal 7 releases.