The Enano team is pleased to announce the immediate release of Enano 1.0.6 patch level 1. This release addresses a critical bug in the wikitext HTML parser as well as a SQL injection vulnerability we found in Enano's comment submission code. We recommend that all administrators upgrade immediately.
This vulnerability also affects Enano 1.1.6, for which there is a patch available.
Release notes are here, and downloads are in the usual place.