See CiviCRM private report - Moderately Critical - Cross Site Request Forgery (CSRF) - SA-CONTRIB-2015-094
See Ubercart Webform Checkout Pane - Moderately Critical - Cross Site Scripting (XSS) - SA-CONTRIB-2015-087
Added admin configuration so that you could turn off the rewrite of the subject and the explanation in the body. Both of those got to be annoying.
Fixed improper From: header reported in #2330901
This version addresses the security issues mentioned in SA-CONTRIB-2015-65. See #2446157: SA-CONTRIB-2015-065 - Fix
See User Import - Moderately Critical - Cross Site Request Forgery (CSRF) - SA-CONTRIB-2015-093