admin,
pls fix the XSS injectable in search.php
I have send you the details in a PM and email too.

And is there a possiblity that I could get an unencrypted version, so that i could fix this myself.

UPDATE: seems like its fixed in 2.5