3.2.8.3 - August 14th, 2026
·
339 commits
to main
since this release
Immutable
release. Only release title and notes can be modified.
This is a major security hardening release covering multiple areas of the plugin. We recommend updating as soon as possible.
Additional releases with these security fixes have been backported to each major version of Pods from Pods 2.7 and above.
- Security: Further restrictions on error handling and fallbacks. (Nhien Pham @nhienit - GalaxyOne, @thevietronin - GalaxyOne, @sc0ttkclark)
- Security: General hardening improvements to how data queries are built and validated. (HaoNH @haoit, @onebitious, @sc0ttkclark)
- Security: Additional restrictions on how certain values are processed when displayed. (@sc0ttkclark)
- Security: Improved safety when handling previously stored data. (@sc0ttkclark)
- Security: Removed a legacy request-handling path that is no longer needed. (HaoNH @haoit, @sc0ttkclark)
- Security: Tightened access requirements for certain background requests. (HaoNH @haoit, @sc0ttkclark)
- Security: Improved consistency and enforcement of access and validation checks. (Youness HFA from AGBS Pentest Team @YounesHfa, HaoNH @haoit, @onebitious, @sc0ttkclark)
- Security: Hardening improvements to file and media handling. (@sc0ttkclark)
- Security: Additional safeguards for file and template handling. (@sc0ttkclark)
- Security: Improved handling of displayed content. (@sc0ttkclark)
- Security: Added extra verification for admin forms and actions. (@sc0ttkclark)
- Security: Additional validation for imported content. (@sc0ttkclark)
- Security: Improved handling of content based on user permissions. (@sc0ttkclark)