Filters apply as you choose them.
Server-side request forgery (SSRF) vulnerability in feed-proxy.php in extjs 5.0.0.
Sencha Labs Connect has XSS with connect.methodOverride()