Fixed in this release:

General:

  • XSS in the macro ID parameter