In response to the XSS exploit (described here), I have updated the server UI to version 0.18.2-rc.2, which fixes the vulnerability.