Add basic validation for content proxied by the css proxy Fix SSRF bypass via specific local address URLs using 100.64.0.0/10 and fe80::/10 nets, Fix SSRF filter bypass via various forms of nip.io/sslip.io hostnames evading islocalurl() check Fix remote content blocking bypass via unclosed url() in a FuncIRI attribute Fix LDAP filter injection via unescaped %u/%fu/%d substitution into the searchfilter Fix arbitrary Sieve script injection via a filter rule name bypassing managesievedisabledactions Fix RCE via cmdlearn driver of markasjunk plugin Fix IMAP command injection via mail search and LITERAL+ byte-count desynchronization Fix password's modoboa driver leak of an authentication token to a user-controlled host Fix stored XSS in "Add to address book" action Fix HTML/CSS sanitization bypass via SVG animate by attribute