Reinforced import-export security, closing a gap that could let malicious files or data pass through the import/export feature undetected.
Patched potential SQL injection vulnerabilities in the Media Manager that could let attackers inject SQL commands and access or alter database content.
Improved input sanitization across input fields, stripping out dangerous characters and scripts before they get processed.
Improved authorization checks for Dynamic Content, preventing users from accessing or manipulating content beyond their access level.
Improved security for Form Builder and Contact Form addons, adding stronger validation and handling against injection and spam attacks.
Version 1.0.0
15 July 2026
Fixes
Security vulnerability in the custom icon uploader (CVE-2026-48908) fixed