Okay
  Public Ticket #1449252
XSS is possible by abusing the contact form
Closed