For more details see SA-CONTRIB-2012-029 - Taxonomy Views Integrator - Cross Site Scripting (XSS)
Fixes a potential SQL injection vulnerability (SA-CONTRIB-2011-048).
Fixed Issue #1109164: Cumulus flashvars security vulnerability.
See SA-CONTRIB-2011-049 for additional information.
Commons 2.2 includes an updated version of the OG_Features and Homebox modules that address critical security issues: http://drupal.org/node/1300642 http://drupal.org/node/1300552
Update steps are relatively straighforrward and users are strongly encouraged to apply this update.
SA-CONTRIB-2011-044 - Homebox for Organic Groups Cross Site Scripting http://drupal.org/node/1300552