#448 (bug) - SQL Injection possible via widget filters on CMS listings