An XSS issue in the formula editor stemmed from inadequate filtering of user input in arithmetic expression fields. This could allow malicious script to run in the browsers of users viewing those expressions.