Contao Open Source CMS 4.13.55

Contao 4.13.55, a new version of the Contao open source CMS, has been released.

This release was necessary due to a fixed security vulnerability in a third-party package. The affected package is enshrined/svg-sanitize and is used in Contao to remove malicious code from SVG files. A security vulnerability was found in this package, which was fixed in version 0.22 of the package. Unfortunately, this was released as a new 0 version. 0 versions are treated specially in Composer. This allows developers to release packages and inform users of this package that they are not yet entirely sure about the final API of the package and that further 0 versions with API breaks may follow. As a precaution, Composer will never automatically update from 0.21 to 0.22, as would be the case from version 1.0 to 1.1, for example. Releasing the bug fix for the security vulnerability as a new 0 version is therefore an unfortunate decision, as it now forces projects such as Contao to update the dependencies in composer.json and release new versions themselves so that all users have the opportunity to close this security vulnerability.

Changelog of the fixed issues in Contao 4.13.55:

About Contao 4.13 LTS

The first stable version of Contao 4.13 has been released on February 17, 2022, replacing Contao 4.9 as the long term support version. As an LTS version, 4.13 has been provided with bug fixes until February 14, 2025 and security-related updates until February 14, 2026. Contao 5.3 has been the next LTS version of Contao and has been released in February 2024, ensuring a stress-free transition.

Bjarke Ammann

Bjarke takes care of the website and support. If you like reading, you might have come across his Contao Two Month Review or found an answer to your question in the official Contao user manual. He also makes sure that Contao enthusiasts from Switzerland meet regularly to exchange ideas. He loves culinary delights, good music and exercise in the fresh air.

Add a comment

What is the sum of 2 and 7?