This security update fixes CSRF vulnerability. See SA-CONTRIB-2015-020 - Contact Form Fields - Cross Site Request Forgery (CSRF). This module works fine with PHP 5.4 now.
Security fix for Open Redirect vulnerability. See SA-CONTRIB-2015-019 - Ubercart Currency Conversion - Open Redirect
SA-CONTRIB-2015-033 - Certify - Access bypass and information disclosure Security fix for access bypass and information disclosure bugs.
Addresses XSS and CSRF vulnerabilities. For more information see SA-CONTRIB-2015-014 - Wishlist - Multiple vulnerabilities
See SA-CONTRIB-2015-002 - Course - Cross Site Scripting (XSS)
There are no other changes in this release.
See SA-CONTRIB-2015-011 - Todo Filter - Cross Site Request Forgery (CSRF)
Also includes earlier fix: #803224: Checking an item off the list doesn't make it permanent