A number of security vulnerabilities have been fixed: CSRF, IDOR, unsafe deserialization, SQL injection, cross-site scripting (XSS), and debug information leakage
CSRF token validation and permissions for a specific task have been added when changing planned dates in the Dashboard component (change-task.php)
The task list and filter in AJAX handlers (tasks.list, tasks.iframe.popup) have been switched to an allowlist of permitted fields instead of accepting an arbitrary filter/sort structure from the request
One-time migration code (filling in the planned date) has been removed from the rendering of the tasks.list component — it was previously executed on every page view for any user
User data escaping has been added when outputting to Dashboard and task list templates (task titles, full names, department names, and work group names)
Deserialization of internal module settings has been switched to safe mode (allowed_classes=false)
Debug output (var_dump) has been removed from the module permissions settings page