4.6.2 (2026-03-05) Bug Fixes ssrf vulnerability on all test notifications endpoint (e8a5135) vulnerability allowed to delete avatars from other users (e8a5135) xss vulnerability on password reset page (e8a5135)