v4.6.4
What's Changed
- security fix for CVE-2026-46670 (critical sql injection)
- no more # at the end of urls in dynamic bazar
- experimental admincontent action that uses htmx
- fix api bugs limiting to 20 results
- fix rss and csv url exports
- fix send page as mail problem
- fix(aceditor): make leaflet send HTTP Referer header that is required by OSM tile usage policy by @lilasra in #1334
- Text and textarea input placeholder by @acheype in #1337
- build(deps): bump twig/twig from 3.24.0 to 3.26.0 by @dependabot[bot] in #1338
- build(deps): bump mermaid from 11.14.0 to 11.15.0 by @dependabot[bot] in #1336
New Contributors
Full Changelog: v4.6.3...v4.6.4