Skip to content

Security Release 2.10.0

Choose a tag to compare

@boldgriddev boldgriddev released this 24 Jun 17:53
e28405f
  • Security: Hardened authorization, capability, and request-verification (nonce/CSRF) checks across admin and AJAX endpoints
  • Security: Improved input validation and output escaping to prevent cross-site scripting (XSS)
  • Security: Strengthened protections against code, command, and file-inclusion injection
  • Security: Hardened processing of dynamic and cached content, including data serialization
  • Security: Restricted outbound server-side requests to mitigate server-side request forgery (SSRF)
  • Security: Restricted configuration changes to prevent unauthorized modification
  • Security: Improved handling of stored credentials, cookies, and generated server-configuration files
  • Security: Reduced potential information disclosure and improved security logging