Under certain circumstances, a user who has "Create Entries" or "Manage Blog" pemissions may be able to read known files on the local file system.
That is bad, as it would allow a potential attacker to read things like configuration files etc. which may contain passwords or other sensitive information.
However, if you are the only author on the system and you haven't set up Movable Type to allow newly registered users to get these permissions anywhere, you should be pretty safe it seems.
They also make a reference to an issue in MT5.1x:
106303 Published URL was changed after upgrading to 5.1x
This link does not work for me, but I believe it is a reference to this issue discussed on the forums recently. In short, entries that had double dashes in their title were getting a different published URL under MT5.11, and this change seems to have been reverted in MT 5.12.
Tweet
There's a kindle ebook "Blogging with Movable Type" that gives a good introduction to Movable Type for beginners available on Amazon. Helped me to get some things sorted.
http://www.amazon.com/Blogging-with-Movable-Type-ebook/dp/B005VTB090/ref=sr_1_1?ie=UTF8&qid=1319209267&sr=8-1