| Fix regression where it wasn't possible to hide a skin logo image anymore (#10254) |
alec
as Aleksander Machniak
|
More...
|
5 days ago
|
| Fix bug where dates could get displayed shifted back one day in some places (#9403) |
alec
as Aleksander Machniak
|
More...
|
5 days ago
|
| Remove redundant code, cleanup |
alec
as Aleksander Machniak
|
More...
|
6 days ago
|
| Update changelog |
alec
as Aleksander Machniak
|
More...
|
7 days ago
|
| Don't defeat session.lazy_write in the php session driver (#9885) (#10248) |
|
More...
|
7 days ago
|
| Update changelog |
alec
as Aleksander Machniak
|
More...
|
7 days ago
|
| Fix vCard import mis-detecting folded continuation lines as BEGIN/END:VCARD (#9593) (#10265) |
|
More...
|
7 days ago
|
| Update changelog |
alec
as Aleksander Machniak
|
More...
|
7 days ago
|
| OAuth: don't log an error when a refreshed token's TTL is below refresh_interval (#10213) (#10267) |
|
More...
|
7 days ago
|
| Inherit PHP interpreter during `installto.sh` (#10259) |
|
More...
|
7 days ago
|
| Update changelog |
alec
as Aleksander Machniak
|
More...
|
8 days ago
|
| Fix example_addressbook search() reporting zero results despite matches (#9022) (#10264) |
|
More...
|
8 days ago
|
| Update changelog |
alec
as Aleksander Machniak
|
More...
|
8 days ago
|
| Fix out-of-bounds string reads on truncated compressed-RTF in the TNEF decoder (#10269) |
|
More...
|
8 days ago
|
| Allow NULL input to html::quote(), fix some "undefined array key" warnings (#10257) |
alec
as Aleksander Machniak
|
More...
|
8 days ago
|
| Fix phpstan error |
alec
as Aleksander Machniak
|
More...
|
20 days ago
|
| Update changelog |
alec
as Aleksander Machniak
|
More...
|
20 days ago
|
| Revert redundant username sanitization |
alec
as Aleksander Machniak
|
More...
|
21 days ago
|
| Fix DoS via crafted compressed-RTF size in the TNEF (winmail.dat) file |
alec
as Aleksander Machniak
|
More...
|
21 days ago
|
| Fix zero-click stored XSS in plain-text rendering [CVE-2026-54433] |
alec
as Aleksander Machniak
|
More...
|
21 days ago
|
| Fix SSRF bypass via specific local address URLs - two new cases |
alec
as Aleksander Machniak
|
More...
|
21 days ago
|
| Fix stored XSS via unescaped attachment MIME type on the attachment-validation warning page [CVE-2026-54432] |
alec
as Aleksander Machniak
|
More...
|
21 days ago
|
| Fix various vulnerabilities in the password plugin using session-injected username |
alec
as Aleksander Machniak
|
More...
|
21 days ago
|
| Fix phpstan issues |
alec
as Aleksander Machniak
|
More...
|
21 days ago
|
| Fix "Creation of dynamic property rcube_message_header::$replaces is deprecated" warning (#10246) |
alec
as Aleksander Machniak
|
More...
|
21 days ago
|
| Update localization |
alec
as Aleksander Machniak
|
More...
|
26 days ago
|
| bugfix: typo in POST param (was: _curppasswd, changed to: _curpasswd) (#10244) |
|
More...
|
26 days ago
|
| Fix PHP deprecation warning (#10241) |
alec
as Aleksander Machniak
|
More...
|
about 1 month ago
|
| Fix support for untyped tokens in OIDC backchannel logout, require unset `nonce` (#10097) |
alec
as Aleksander Machniak
|
More...
|
about 1 month ago
|
| Fix bug where redis/memcache session could have been updated more often than needed |
alec
as Aleksander Machniak
|
More...
|
about 1 month ago
|