We don't want to do a full upgrade because, for one, we have tons of customizations, and two we don't use the shipping and payment modules that the uprade features. But I am wondering about the Low Risk XSS vulnerability and can i fix that without having to do the upgrade?

thanks a bunch.
k