Fix order state
https://security.drupal.org/node/183304
This is a security update fix. Before the fix, the user could input any html tags on the title/alt of an image, allowing inputs with scripts.
Improved the way how files are downloaded
This release contains an error that is triggered when you click on a button to generate zip archive
#3524688: Getting error on clicking Download as a zip with all assets
Please upgrade to 1.4.13 that includes the fix
Fix authentication bypass through replay attack Fix authentication bypass via core rest routes Fix authentication bypass via one time login links