Already a customer?
Log in now
You would like to become a customer?
Test trakked now
This release primarily focuses on security and reliability improvements. It addresses a vulnerability in the Contao crawler that could expose authentication credentials to external hosts and further tightens the execution scope of web-triggered cron jobs and workers. In addition, image search results have been improved, HTML-to-text conversion has been refined by excluding style and script content, and several issues related to authentication workflows have been resolved, including the handling of two-factor authentication during impersonation.
Security vulnerability closed:
form attribute in widgets
( aschempp )
ptable conditions to $strWhere
( lukasbableck )
panel in DC_Folder before adding messages
( lukasbableck )
ptable when fetching child records
( lukasbableck )
dev
( fritzmg )
spatie/schema-org
( leofeyer )
<style> and <script> content when converting HTML to plain text
( lukasbableck )
Input::stripAttributes() method
( leofeyer )
--time-limit for messenger workers
( fritzmg )
player.html.twig template
( fritzmg )
PlayerController
( leofeyer )
sizes=auto in images
( ausi )
getBaseUrl() and getBasePath()
( Toflar )
Already a customer?
Log in now
You would like to become a customer?
Test trakked now
The first stable version of Contao 5.3 has been released on February 16, 2024, replacing Contao 4.13 as the long term support version. As an LTS version, 5.3 will be provided with bug fixes until February 14, 2027 and security-related updates until February 14, 2028. Contao 5.7 is the next LTS version of Contao and was released in February 2026, ensuring a smooth transition.
Add a comment