Last modified: 2009-07-19 19:42:26 UTC
Along with the other html filetypes, .xhtml uploads should be blacklisted by default, because they could be a threat on a WM site that uses application/xhtml+xml, or even one that doesn't.
.xhtml and .xht added in r53487