Skip to content
This repository was archived by the owner on Feb 13, 2026. It is now read-only.

2.11.14

Choose a tag to compare

@leofeyer leofeyer released this 13 Feb 13:36
· 4706 commits to 3.5 since this release

Fixed

  • Do not pass POST data to the deserialize() function, so it is not vulnerable to PHP object injection. Thanks to Pedro Ribeiro for his input (see #6695).