Low Priority - Core - ACL violation in access levels
Low Priority - Core - Add phar files to the upload blacklist
Moderate Priority - Core - Information Disclosure about unpublished tags
Low Priority - Core - Installer leaks plain text password to local user
Moderate Priority - Core - XSS Vulnerabilities & additional hardening
Low Priority - Core - Filter field in com_fields allows remote code execution
Low Priority - Core - Session deletion race condition
Low Priority - Core - Possible XSS attack in the redirect method
Low Priority - Core - XSS vulnerability in the media manager