Joomla 3.9.2 has been released that resolves 4 security vulnerabilities and includes over 50 bug fixes and improvements.
Joomla 3.9.2 Security Issues Fixed
Low Priority - Core - Stored XSS in mod_banners (affecting Joomla 2.5.0 through 3.9.1) More information »
Low Priority - Core - Stored XSS in com_contact (affecting Joomla 2.5.0 through 3.9.1) More information »
Low Priority - Core - Stored XSS issue in the Global Configuration textfilter settings (affecting Joomla 2.5.0 through 3.9.1) More information »
Low Priority - Core - Stored XSS issue in the Global Configuration help url (affecting Joomla 2.5.0 through 3.9.1) More information...