I don't think the bug is extremely serious. The XSS code is cleaned out before it hits the database. That said, I don't want someone to prove me wrong. Go ahead and update.
The Base/Core update also has some fixes for the makeThumbnail function that was breaking PhotoAlbum (thanks Verdon).
The warning (besides the security one) is that the new code does not work with versions of php under 4.4.0. If are still running a version under 4.4.0 you will need to edit some files.
Open core/class/DBPager.php and mod/search/class/Search.php. Search for "\pL" and delete it. This is a regular expression modifier to allow foreign and accented characters. If you are running an English site, then no problem. If you are not, then you will need to upgrade to 4.4.0 or above or your umlauts may cause problems.
I hope everyone had a happy and safe holiday.
* Update - Calendar was just updated as well.

Anonymous
Liked your post ! ! keep up the Good work man..
Anonymous
Liked your post ! ! keep up the Good work man..
Free Online Games
Anonymous
Liked your post ! ! keep up the Good work man..
Anonymous
decorative flags
Anonymous
Re:Liked your post ! ! keep up the Good work man..
eve isk
Anonymous
good
Anonymous
game
eve isk
shaiya gold
seo
yule
Anonymous
new news
2moons copper argate
2moons silver argate
2moons
cheap 2moons
Anonymous
i like this
Anonymous
test
Anonymous
cheap 2moons
Anonymous
No subject
Anonymous wrote:
dofus kamas
eve isk
shaiya gold
seo
yule
2moons copper argate
2moons silver argate
2moons
cheap 2moons
Anonymous
Re:cheap 2moons
test2
Anonymous
No subject
Anonymous
No subject
Anonymous
No subject