| Server IP : 104.21.32.175 / Your IP : 216.73.217.138 Web Server : Apache System : Linux vps-850873.bgcolombia.com 3.10.0-1160.144.1.el7.tuxcare.els5.x86_64 #1 SMP Wed May 13 12:31:54 UTC 2026 x86_64 User : melizav ( 1018) PHP Version : 7.4.33 Disable Function : NONE MySQL : OFF | cURL : ON | WGET : ON | Perl : ON | Python : ON | Sudo : ON | Pkexec : ON Directory : /var/softaculous/presta8/ |
Upload File : |
####################################
# v8.2.8 - (2026-08-12)
####################################
- Core:
- Improvement:
- GHSA-xrwj-pq6w-f8m4 Validate image URLs on CSV import to prevent Server-Side Request Forgery (by @clotairer & @matthieu-rolland, vulnerability reported by lrui1)
- GHSA-w6j9-q9rq-wrqg Escape leading formula characters in CSV exports (by @clotairer & @matthieu-rolland, vulnerability reported by Suphawith Phusanbai)
- GHSA-2cr4-vw9p-pjvf Parse the X-Forwarded-For header from right to left to prevent IP spoofing (by @clotairer & @matthieu-rolland, vulnerability reported by Pedro Gabaldón Juliá from ITRESIT)
- GHSA-whxq-pxj5-qq7v Escape identifiers in legacy admin list filters to prevent SQL injection (by @clotairer & @matthieu-rolland, found by Savio from Doyensec in collaboration with Anthropic Research)
- GHSA-jf3w-9rmr-5rcr Restrict the notifications endpoints to authorised employees (by @clotairer & @matthieu-rolland, vulnerability reported by Robert Scherer)
####################################
# v8.2.7 - (2026-06-03)
####################################
- Core:
- Bug fix:
- #231: Update faceted search (by @jolelievre)
####################################
# v8.2.6 - (2026-04-16)
####################################
- Back Office
- Improvement:
- GHSA-w9f3-qc75-qgx9 Prevent xss exploitation via unprotected variables in customer threads (found by Savio from Doyensec in collaboration with Anthropic Research)
####################################
# v8.2.5 - (2026-03-13)
####################################
- Front Office
- Improvement:
- GHSA-35pf-37c6-jxjv Prevent xss exploitation via unprotected variables in template
- GHSA-283w-xf3q-788v Fix improper use of validation framework
####################################
####################################
# v8.2.4 - (2026-02-03)
####################################
- Front Office
- Improvement:
- GHSA-67v7-3g49-mxh2 Protect users from time based email enumeration attacks (by @matthieu-rolland, vulnerability reported by Lam Yiu Tung)