Skip to content

1.16.4

Compare
Choose a tag to compare
@jenlampton jenlampton released this 30 Sep 21:09
· 1422 commits to 1.x since this release

Security release for Backdrop CMS. This release fixes 2 security vulnerabilities:

Notes for updating

  • No changes have been made to the .htaccess, robots.txt or default settings.php files in this release. Updating customized versions of those files is not necessary.
  • The database update script does not need to be run.

Changes since 1.16.3

  • BACKDROP-SA-CORE-2020-005: Sanitize AJAX URLs.
  • BACKDROP-SA-CORE-2020-006: Sanitize captions used within CKEditor.