Sucuri reports an stored cross site scripting (XSS) vulnerability in Magento CE <1.9.2.3 and Magento EE <1.14.2.3. This vulnerability affects almost every install of these versions, time to upgrade your Magento webshop!

Read the full security advisory @Sucuri.

This may interest you:   SMTP over Hidden Services with postfix