Joomla security notice received from them today:
http://developer.joomla.org/security/news/541-20121001-core-xss-vulnerability.html?utm_source=feedburner&utm_medium=email&utm_campaign=Feed%3A+JoomlaSecurityNews+%28Joomla%21+Security+News%29 (http://developer.joomla.org/security/news/541-20121001-core-xss-vulnerability.html?utm_source=feedburner&utm_medium=email&utm_campaign=Feed%3A+JoomlaSecurityNews+%28Joomla%21+Security+News%29)
Quote
Joomla! Security News
[20121001] - Core - XSS Vulnerability
Posted: 10 Oct 2012 12:21 AM PDT
Project: Joomla!
SubProject: All
Severity: Low
Versions: 3.0.0
Exploit type: XSS Vulnerability
Reported Date: 2012-October-01
Fixed Date: 2012-October-09
Description
Typographical error leads to XSS vulnerability in language search component.
Affected Installs
Joomla! version 3.0.0.
Solution
Upgrade to version 3.0.1
Reported by Jeff Channell
Contact
The JSST at the Joomla! Security Center.