Some field types do not properly sanitize data from non-form sources. This can lead to arbitrary PHP code execution in some cases. 

security advisory