<?xml version="1.0" encoding="utf-8"?>

<updates>
	<version>1.4.6</version>
		<hotfix id="hotfix_13rc_blind_password_recovery">PunBB 1.3 RC hotfix for blind password recovery.</hotfix>

		<hotfix id="hotfix_13rc_sql_injection_in_register">PunBB 1.3 RC hotfix for a potential SQL injection.</hotfix>

		<hotfix id="hotfix_13rc_smtp_command_injection">PunBB 1.3 RC hotfix for SMTP command injection.</hotfix>

		<hotfix id="hotfix_13rc_csrf_bypass">PunBB 1.3 RC hotfix for a potential CSRF bypass.</hotfix>

		<hotfix id="hotfix_13rc_check_for_versions">Migration hotfix (1.2.* =&gt; 1.3 RC only): adds missed o_check_for_versions field.</hotfix>

		<hotfix id="hotfix_13rc_remove_g_edit_subjects_interval">PunBB 1.3 RC hotfix for bug with g_edit_subjects_interval.</hotfix>

		<hotfix id="hotfix_13rc_exploit_in_report_system">PunBB 1.3 RC hotfix for XSS exploit in report system.</hotfix>

		<hotfix id="hotfix_13rc_pagination_xss">PunBB 1.3 RC hotfix for XSS exploit in pagination.</hotfix>

		<hotfix id="hotfix_13rc_avatar_info_change">PunBB 1.3 RC hotfix for the missed parameter 'Avatar info change'.</hotfix>
</updates>