The latest release of CiviCRM 5.3.1 and 4.6.38 includes security fixes. This is a critical security release, we recommend upgrading to 5.3.1 and 4.6.38 to ensure the security of your site and data as soon as possible.
- CIVI-SA-2018-07 Remote code execution in QuickForm
- CIVI-SA-2018-06 Reflected XSS in context parameter
- CIVI-SA-2018-05 Reflected XSS in contact merge screen
- CIVI-SA-2018-04 SQL injection in custom groups
- CIVI-SA-2018-03 Reflected...