Contao 5.7.14 improves back end access controls and editing workflows. Fixes to filesystem permissions, search document permission checks, and paste actions help enforce the intended access rules, while an issue preventing passkey authentication has been resolved. Editors benefit from more reliable row wizard copying, filter panels, bulk updates in page and file trees, and theme selection in the Template Studio. The release also corrects back end job polling, database schema updates, and the language attribute in modern page layouts, while improving backup handling for virtual fields containing non-ASCII characters.
Changelog of the fixed issues in Contao 5.7.14:
-
#10403
Fix the database reference name for the
RenameFrontendModuleVariantOperation( zoglo ) - #10365 Introduce a template for the root page dependent modules fragment ( fritzmg )
- #10378 Fix the row wizard select and checkbox states on copy ( zoglo )
-
#10399
Remove the forward compatibility layer for
symfony/security-core( leofeyer ) - #10388 Add a comment regarding forward compatibility to the permission checking VFS ( leofeyer )
-
#10374
Use the
UserInterfaceto check search document permissions instead of the firewall token ( aschempp ) -
#10380
Fix clipboard
PASTE_AFTERwhen moving element groups into themselves ( zoglo ) - #10359 Fix the filesystem permission checks ( aschempp )
- #10351 Simplify the markup for passkey management ( fritzmg )
- #10349 Add a block for the passkey login button ( fritzmg )
- #10354 Add the missing backend search hit methods ( Toflar )
- #10341 Fix default labels with null references ( ausi )
- #10321 Check permissions on the paste buttons ( aschempp )
-
#10331
Fix the
ContaoCacheWarmerTeston Windows ( fritzmg ) -
#10322
Fix passkeys not working due to missing
rp( lukasbableck ) - #10307 Fix a Twig inspector cache race condition ( m-vo )
-
#10291
Fix minor issues with
WebauthnCredentials( fritzmg ) -
#10276
Fix invalid
ALTER TABLE ... ENGINE =when target has no explicit engine option ( rfay ) -
#10266
Move more Stimulus event handling into
data-actionattributes ( leofeyer ) - #10267 Fix the Template Studio theme context selection ( zoglo )
-
#10258
Dump inline file references in
CombinedFileDumper( aschempp ) - #10249 Fix several Stimulus issues ( leofeyer )
- #10254 Fix resolving the dynamic ptable when loading the DCA ( zoglo )
- #10253 Do not hide the app title between 600px and 767px ( leofeyer )
-
#10250
Deprecate
Backend.enableImageSizeWidgets()retroactively ( fritzmg ) - #10246 Do not use MooTools in the modal-selector-controller ( zoglo )
-
#9797
Allow
overrideAllupdates for page and file trees ( aschempp ) -
#10235
Dump origin file references in the
CombinedFileDumper( Toflar ) - #10233 Ensure string UUIDs recursively ( fritzmg )
- #10217 Correct the backend job polling time window ( Toflar )
-
#10229
Always decode entities in the
ContentRecordLabelListener( leofeyer ) - #10218 Stop backend job polling after controller disconnect ( Toflar )
-
#10225
Correctly output
targetattributes in event templates ( fritzmg ) - #10222 Fix wrong tag being used for link tags ( fritzmg )
- #10219 Enable the reset button in the side panel on an active sort or limit ( zoglo )
-
#10220
Set
'required' => 'false'on the legacy template type field callback ( zoglo ) -
#10207
Ensure that there is no whitespace before the
<DOCTYPE>tag ( leofeyer ) -
#10214
Fix the invalid HTML
langattribute format in modern page layouts ( ausi ) - #10146 Correctly resolve URLs of records with multiple parent tables in the same backend module ( zoglo )
- #10186 Cast arguments for string functions ( aschempp )
- #10187 Correctly load all filter panels ( aschempp )
- #10195 Consider non-ASCII characters in virtual fields when creating backups ( zoglo )
- #10168 Update the visibility of the backend passkey input field ( zoglo )
-
#10166
Fix the legacy template selection in
overrideAll( fritzmg ) - #10190 Use the existing close and chevron icons in the form stylesheets ( leofeyer )
- #10180 Do not check access twice when generating the backend navigation ( leofeyer )
- #10120 Do not add user permissions for job fields ( aschempp )
- #10174 Remove deprecated config values ( bytehead )
-
#10170
Restore the tooltip title before
AjaxRequest.toggleField()runs ( zoglo )
About Contao 5.7 LTS
The first stable version of Contao 5.7 has been released on February 18, 2026, replacing Contao 5.3 as the long term support version. As an LTS version, 5.7 will be provided with bug fixes until February 14, 2029 and security-related updates until February 14, 2030. Contao 6.3 is the next LTS version of Contao and is due to be released in February 2028, ensuring a smooth transition.