This release prevents duplicate form submissions and corrects the handling of inherited back end user permissions. Failed undo operations now roll back all changes, and content elements can be moved between different parent types. Additional fixes improve file searches, pagination, redirects, and asset URLs, while the handling of template overrides and compatibility with older ICU versions have also been refined.
Changelog of the fixed issues in Contao 5.3.52:
-
#10427
Require
enshrined/svg-sanitizein version^1.0( zoglo ) - #10406 Ensure file extensions are checked in lowercase when searching for files ( qzminski )
- #10408 Fix division by zero in the pagination menu if no limit is set ( zoglo )
- #10368 Rollback all changes if an undo operation fails ( lukasbableck )
- #10372 Also use a file content hash in the combiner ( fritzmg )
- #10390 Keep an explicit link title on a figure with a lightbox ( developerjillur )
- #10385 CAPTCHA replay protection can be bypassed ( leofeyer )
- #10373 Correctly prepend the assets URL ( lukasbableck )
- #10336 Do not swallow the error responses of download requests ( bytehead )
- #10337 Fix a warning in the indexer when multiple types are specified in JSON-LD ( lukasbableck )
- #10327 Prevent forms from being submitted multiple times by sending the POST request again ( lukasbableck )
- #10352 Handle predefined image sizes without densities in the preview factory ( developerjillur )
- #10332 Remove the parameters of previous download URLs when generating new ones ( bytehead )
-
#10350
Fix the
CrawlCommandTestwhen console window is narrow ( fritzmg ) - #10320 Fix the regex boundary check ( ausi )
-
#10323
Remove an obsolete
$user->save()call ( aschempp ) -
#10290
Fix
LocaleUtilfor older ICU versions ( ausi ) - #10288 Check for pcre.jit in PCRE backtrack limit test ( ausi )
- #10268 Preserve stripped query parameters in redirects ( Toflar )
- #10264 Fix incorrectly removed tags in labels ( lukasbableck )
-
#10284
Validate the table name in
getCurrentRecord()( ausi ) - #10259 Add a table alias in the listing count query ( shoaib0300 )
- #10255 Remove known limitation for moving content elements into different parent types ( zoglo )
-
#10228
Do not unset the
$_FILESarray in theFormUploadclass ( leofeyer ) - #10198 Do not cast column values for aliases to binary ( lukasbableck )
- #10191 Suppress warnings from failed DNS lookups ( Toflar )
-
#10188
Add additional type checks in the
PickerConfigclass ( bytehead ) - #10189 Ignore the LinkedIn click identifier in the HTTP cache ( eki89 )
- #10183 Backport the HTML5-to-Twig template override order ( ausi )
-
#10185
Do not return from
finallyblocks ( ausi ) - #10181 Prevent saving inherited backend user permissions ( Toflar )
-
#10179
Remove the deprecated
xss_protectionoption ( leofeyer ) - #10172 Ignore dates that cannot be converted when loading a widget ( aschempp )
-
#10176
Exclude
+intl-icufrom being a Contao translation domain ( bytehead )
About Contao 5.3 LTS
The first stable version of Contao 5.3 has been released on February 16, 2024, replacing Contao 4.13 as the long term support version. As an LTS version, 5.3 will be provided with bug fixes until February 14, 2027 and security-related updates until February 14, 2028. Contao 5.7 is the next LTS version of Contao and was released in February 2026, ensuring a smooth transition.