XenForo News

Latest news and announcements about XenForo, including new releases and development updates.
  • Threads: 303
  • Messages: 334
XenForo 2.2.12 Released XenForo 2.2.12 is now available for all licensed customers to download. We strongly recommend that all customers running previous versions of XenForo 2.2 upgrade to this release to benefit from increased stability. We're pleased to announce the introduction of two new features available in XenForo 2.2.12. New CAPTCHA provider: Cloudflare Turnstile In September, Cloudflare Turnstile was announced. You may have noticed that we quickly implemented... Read more Continue reading...
Today, we are releasing XenForo 2.2.11 to address a potential security vulnerability. We recommend that all customers running XenForo 2.2 upgrade to 2.2.11 or use the attached patch file as soon as possible. The issue relates to HTML attribute injection which can be triggered when rendering editor content, such as when a post is edited or quoted. XenForo extends thanks to security researcher @PaulB, the team at @NamePros and @Xon for reporting the issues. We recommend... Read more Continue reading...
Today, we are releasing XenForo 2.1.13 to address a potential security vulnerability. We recommend that all customers still running XenForo 2.1 upgrade to 2.1.13 or use the attached patch file as soon as possible. The issue relates to HTML attribute injection which can be triggered when rendering editor content, such as when a post is edited or quoted. XenForo extends thanks to security researcher @PaulB, the team at @NamePros and @Xon for reporting the issues. We... Read more Continue reading...
Here we go! We're four HYS threads in already and you might be wondering just how many there are left. Well, I can't tell you 😉 But what I can tell you is - we're not even half way through yet! In case you've not yet seen the previous entries, you can check them out here. As ever, to ensure you're kept up to date, we strongly recommend caressing that "Watch forum" link and make sure you enable email notifications if you haven't done so already 🙂 Continue reading...
XenForo 2.2.10 Released XenForo 2.2.10 is now available for all licensed customers to download. We strongly recommend that all customers running previous versions of XenForo 2.2 upgrade to this release to benefit from increased stability. This version contains a fix for an issue whereby outgoing requests from the server running XenForo could be tricked into accessing web-accessible resources on the local network. The scope to exploit this issue is limited within the core and... Read more Continue reading...
Over the next few weeks, we'll be adding to the Building with XenForo 2 video series, starting today with a look at how to make your custom add-on content taggable! Continue reading...
XenForo 2.2.9 Released XenForo 2.2.9 is now available for all licensed customers to download. We strongly recommend that all customers running previous versions of XenForo 2.2 upgrade to this release to benefit from increased stability. In addition to the usual bug fixes and improvements, we've continued to improve compatibility with PHP 8.1 and added support for self-hosted licenses to more easily sign outgoing emails with DKIM as per this recent suggestion by... Read more Continue reading...
It has come to our attention today that a vulnerability has been discovered in popular Java logging library Log4j 2 which may allow attackers to arbitrarily execute code (remote code execution). Apache Log4j 2 is bundled with and used in many Java applications including Elasticsearch. XenForo itself is not directly exploitable, and we are currently investigating whether XenForo Enhanced Search can be used as a vector at all, but this is potentially significant enough that an abundance of... Read more Continue reading...
XenForo 2.2.8 Released XenForo 2.2.8 is now available for all licensed customers to download. We strongly recommend that all customers running previous versions of XenForo 2.2 upgrade to this release to benefit from increased stability. XenForo 2.2.8 brings initial PHP 8.1 support to XenForo. We do not currently recommend upgrading to PHP 8.1 in production but would encourage, where possible, running XF 2.2.8 and PHP 8.1 together on your staging sites/servers if possible... Read more Continue reading...
When we announced XenForo Cloud a little while back, we were encouraged by the great feedback we received. Having taken onboard all your comments, we have been hard at work refining our offering to make it an even more compelling proposition, and today we are ready to talk about some of the changes we've implemented. Faster Not content with already offering the industry's most capable and responsive infrastructure, we are now using even most powerful underlying hardware with faster... Read more Continue reading...
XenForo 2.2.7 Released XenForo 2.2.7 is now available for all licensed customers to download. We strongly recommend that all customers running previous versions of XenForo 2.2 upgrade to this release to benefit from increased stability. Notably, XenForo 2.2.7 includes a fix for a potentially significant issue surrounding IP address spoofing in very specific circumstances using previously trusted IP address ranges. Thanks to NamePros for taking the time to report this issue... Read more Continue reading...
XenForo 2.2.6 Released XenForo 2.2.6 is now available for all licensed customers to download. We strongly recommend that all customers running previous versions of XenForo 2.2 upgrade to this release to benefit from increased stability. One-click upgrade to XenForo 2.2.6 Directly from your admin control panel Some of the changes in XF 2.2.6 include: Adjust file copying order of the one click upgrader to reduce issues with page breaks.... Read more Continue reading...
XenForo 2.2.6 Released XenForo 2.2.6 is now available for all licensed customers to download. We strongly recommend that all customers running previous versions of XenForo 2.2 upgrade to this release to benefit from increased stability. One-click upgrade to XenForo 2.2.6 Directly from your admin control panel Some of the changes in XF 2.2.6 include: Adjust file copying order of the one click upgrader to reduce issues with page breaks.... Read more Continue reading...

Create an account or login to comment

You must be a member in order to leave a comment

Create account

Create an account on our community. It's easy!

Log in

Already have an account? Log in here.

Top