https://github.com/ether/etherpad-lite/releases/tag/1.6.3 mentions three security issues:
"SECURITY: Update ejs"
"SECURITY: xss vulnerability when reading window.location.href" is https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-6834
"SECURITY: sanitize jsonp" is https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-6835