Version 4.1.4
10 September 2026Security
- Fixed an unauthenticated SQL injection vulnerability in property search and map filter parameters. [CVE-2026-78082]
- Implemented CSRF token verification on property booking and agent contact forms. [CVE-2026-78083]
- Fixed JavaScript-context XSS vulnerability in property and agent view script blocks. [CVE-2026-78302]
- Added authorization checks and upload validation for gallery images. [CVE-2026-78084]
- Fixed an unvalidated email recipient vulnerability in property booking requests. [CVE-2026-78303]
Fixed
- Added contextual output escaping across agent and property templates to mitigate potential XSS.
- Fixed OpenStreetMap not displaying by adding automatic fallback to official OpenStreetMap tiles when no Mapbox token is provided.
- Corrected administrator asset loading paths for OpenStreetMap/Leaflet scripts and styles in property edit view.
- Upgraded legacy Mapbox v4 tile endpoint to modern Styles API in backend location picker.
- Corrected agent ID and category ID type casting in search and listing models.