Quick search:

fixes in 1.4.beta1

  • Many fixes to prevent cross site scripting, see changes.txt under "cross site scripting prevention"
  • PntSite::getFunkyRequestData now urlEncodes and adds slashes 
  • PntFilterFormPart::getInitializedAdvancedFilters no longer assigns cloned filter by reference ::advancedFilterCombine, ::advancedFilterOr now return reference