NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
Packagist · #3801 most downloaded on Packagist
Craft CMS
Last release today
07 Oct 2026
Ships on a steady schedule
a new release about every 2 weeks
Most releases are documented
notes for 41 of the last 60 stable releases
Nothing withdrawn
no release was ever pulled
13 years old
1343 releases · first in 2013
Items that rely on JavaScript are left out, and deprecation warnings point to the code to update.
craft-button links couldn’t be reached with the Tab key. (#19785)elements.* MCP tools that list, read, create, update, delete, restore, validate, and duplicate elements of any supported type, with elements.schema and craft://element-types resources describing each type’s criteria and attributes. (#19846)activity.list and activity.comments.create MCP tools for reading element timelines and adding editorial comments. (#19846)mcp:serve command, which serves the authenticated MCP server over stdio as a named user. (#19846)CraftCms\Cms\Config\McpConfig::$instructions setting, and the CraftCms\Cms\Mcp\Events\CollectingAdminInstructions event for site and plugin guidance. (#19846)elements.list, drafts.list, revisions.list, and search.query MCP tools. (#19846)<craft-component-select>, keeping selected entry types listed as checked options. (#19888)money columns and grouped options in legacy editable tables and Form tables, including a configurable Money cell type for Table fields. (#19870)CraftCms\Cms\Form\Controls\NestedElements and CraftCms\Cms\Element\NestedElementManager::formControl(), allowing plugins to manage custom nested element types as cards or embedded element indexes. (#19792)CraftCms\Cms\Http\ViewModels\ElementEditViewModel for custom element types. (#19792)craft:layout-slot, craft:app-layout, and craft:cp-container global Vue components, which plugins can use to fill control panel screen layout regions on their own Inertia pages. (#19854)primary-action screen layout slot and CraftCms\Cms\Http\Responses\CpScreenResponse::primaryAction(), for replacing the Save button while keeping its action menu. (#19854)CraftCms\Cms\Element\Events\ElementActionMenuDescriptorsResolving, allowing plugins to add action menu items to the Inertia element editor and element chips. (#19783)CraftCms\Cms\Mcp\Elements\ElementAdapter, CraftCms\Cms\Mcp\Elements\BaseElementAdapter, and CraftCms\Cms\Mcp\Elements\ElementAdapterRegistry, allowing plugins to make their element types available through the elements.* MCP tools. (#19846)CraftCms\Cms\Mcp\Attributes\RequiresHttp, for MCP capabilities that only work over HTTP. (#19846)directPermissions to MCP user permission results and CraftCms\Cms\User\UserPermissions::getDirectPermissionsByUserId(). (#19846)CraftCms\Cms\Element\Events\ElementEditorPayloadResolving. (#19792)CraftCms\Cms\Asset\AssetUploadHandler::ingest(), allowing non-HTTP adapters to reuse Craft’s asset creation workflow. (#19823)CraftCms\Cms\Asset\Data\AssetIngest, allowing transport adapters to set metadata and custom field values before validation and persistence. (#19827)CraftCms\Cms\Element\UserInitiatedElementSave and CraftCms\Cms\Element\Data\UserInitiatedElementSaveResult, providing a shared workflow for user-initiated element saves. (#19822)CraftCms\Cms\Component\TypeRegistry::defer(), for registering types once the registry is first read rather than at boot. (#19851)$appearance argument to CraftCms\Cms\Cp\Html\StatusHtml::statusIndicatorHtml() and componentStatusIndicatorHtml(). (#19842)CraftCms\Cms\Markdown\MarkdownOptions::$indentedCode, which determines whether indented lines can start code blocks. (#19859)CraftCms\Cms\Search\Events\KeywordsIndexing::$layoutElementUid. (#13991)--c-layer-header and --c-layer-skip-link CSS custom properties, and the z-header and z-skip-link utilities. (#19886)width attribute to <craft-input-date-time>, along with CraftCms\Cms\Cp\Components\InputDateTime::width() and CraftCms\Cms\Form\Controls\DateTime::fullWidth(), for stretching date and time inputs across their container. (#19871)createHttpClient(), http, isHttpError(), and isCancel() to @craftcms/ui.Craft.isCancel().CraftCms\Cms\Cp\Components\ComponentSelect and CraftCms\Cms\Cp\Components\EntryTypeSelect, which the _includes/forms/componentSelect.twig and _includes/forms/entryTypeSelect.twig templates now render. (#19888)CraftCms\Cms\Cp\FormFields::componentSelectFromConfig() and entryTypeSelectFromConfig(). (#19888)CraftCms\Cms\Form\Controls\EntryTypeSelect. (#19888)checkbox-options attribute to <craft-component-select>, which keeps selected options listed as checked items. (#19888)text-quiet Tailwind utility. (#19888)craft\base\Element::EVENT_DEFINE_ACTION_MENU_ITEMS, or by plugin element types’ safeActionMenuItems() and destructiveActionMenuItems() overrides, through the Yii adapter, if they define a url or action. Items that rely on JavaScript are left out, and deprecation warnings point to the code to update. (#19783)CraftCms\Cms\Cp\FormFields::editableTableHtml(), editableTableFieldHtml(), and the corresponding Twig macros to use form-builder tables. (#19873)CraftCms\Cms\Entry\EntryTypes::saveEntryType() to validate entry types and their field layouts by default, with a $runValidation argument for bypassing validation. (#19821)<craft-indicator> to use the solid appearance by default, rather than outline-fill, except for white and black fills, which keep outline-fill (with a white outline for black). (#19842)actionClient and apiClient from @craftcms/ui to use a fetch-based HTTP client with the same request methods, rather than Axios.Craft.sendActionRequest() and Craft.sendApiRequest() to no longer use Axios. Their errors still pass axios.isAxiosError() and axios.isCancel() checks.axios when craftcms/yii2-adapter is installed. Craft.sendActionRequest() or actionClient from @craftcms/ui should be used instead.craft\queue\Queue::getJobId() to return null when the current job isn’t being run by Yii’s queue. (#19835)craftcms/yii2-adapter. (#19804)initJs option and number column locale option. Tables now mount automatically, and number columns submit unformatted values. (#19873)cancelToken request option for Craft.sendActionRequest() and Craft.sendApiRequest(). signal should be used instead.craft\base\Plugin::getVersion() and setVersion(). The $version property should be used instead. (#19850)Cp.$axios.craft\elements\db\ElementQuery::beforePrepare(). CraftCms\Cms\Element\Queries\ElementQuery::elementQueryBeforeQuery() should be overridden instead. (#19838)craft\elements\db\ElementQuery::joinElementTable(). Element queries should now declare their element table via the $table property, which is joined automatically. (#19838)craft\elements\db\ElementQuery::$subQuery. Element queries are now a single query, so joins and conditions should be applied to $query. (#19838)breadcrumbs and submit-button screen layout slots, which never rendered on full pages. The crumbs page prop and the primary-action slot should be used instead. (#19854)pasteableEntryTypeIds nested element manager setting. pasteableData should be used instead. (#19792)showLabelField was disabled. (#19811)minRows setting before becoming visible. (#19815)on instead of their configured checked value in HTML forms. (#19873)slot attribute. (#19874)CraftCms\Cms\User\UserGroups::saveGroup() did not validate user groups, and added its $runValidation argument. (#19820)craft:up could fail on installs that didn’t have a migrations table yet. (#19796)craft\services\Dashboard::EVENT_REGISTER_WIDGET_TYPES listeners, relied on the current user. Legacy type registration events are now triggered when the types are first needed rather than on every request, as they were in Craft 5. (#19851)craft\base\Plugin::getVersion() returned 1.0 for Craft 5 plugins, rather than the version from their Composer manifest. (#19850)Craft::getAlias() was passed a value that wasn’t an alias, such as null. Non-alias values are now returned unchanged, as they were in Craft 5. (#19853)craft\web\assets\htmx\HtmxAsset. The bundle is now deprecated and doesn’t register htmx, so plugins that rely on htmx should bundle it themselves. (#19836)actions/… URL. (#19837)cp.js, leaving legacy controls unresponsive. (#19840)cp.js, causing “jQuery is not defined” errors. (#19840)getFieldLayout() methods declared a craft\models\FieldLayout return type. craft\models\FieldLayout is now an alias of CraftCms\Cms\FieldLayout\FieldLayout. (#19834)craft\base\Model. (#19813)CpContainer’s full slot wasn’t displayed at full width. (#19854)One column per quarter.
Important This update contains breaking changes for plugins. See #19574 , #19563 , #19588 , #19585 , and #19650 for details.
Important
This update contains breaking changes for plugins. See #19574, #19563, #19588, #19585, and #19650 for details.
contentMaxWidth and centerContent options. (#19648)ElementEditor now supports rendering as a full page in addition to a slideout. (#19648)formModal element action behavior. (#19768)sidebarForm and metadataHtml props to Form.vue pages, allowing sidebar controls to be saved alongside the main form. (#19778)CraftCms\Cms\Http\Responses\CpScreenResponse::addAltAction() submissions on Inertia Form pages and slideouts. (#19779)<craft-timeline-item> web component. (#19629)placeholder property to <craft-thumbnail>, for an image to show while the thumbnail loads. (#19750)CraftCms\Cms\Form\Controls\Combobox\CreateOption for creating and selecting resources in comboboxes, including user photo volumes. (#19777)--c-thumbnail-image-radius custom property to <craft-thumbnail>, and its other custom properties can now be set on an ancestor. (#19758)<craft-chip>’s prefix slot no longer replaces its thumbnail, icon, and status; it’s shown before them. (#19758)CraftCms\Cms\Form\Nodes\Callout::padding(), supported by PHP and Vue form rendering. (#19773)crop, fit, stretch, and letterbox modes to craft-thumbnail, and removed size-dependent asset thumbnail cropping.<img> tags returned by CraftCms\Cms\Asset\Elements\Asset::getImg() now have a blurred placeholder as their background, unless the image has transparent regions. (#19750)asset.blurhash in templates and the blurhash field in GraphQL queries. (#19755)blurhash, colors, and placeholderDataUrl fields to assets in GraphQL queries. (#19740, #19750, #19755)$mode argument to core thumbnail APIs, defaulting to Fit for thumbnail HTML and Crop for CraftCms\Cms\Asset\Assets::getThumbUrl(). Implementations of CraftCms\Cms\Component\Contracts\Thumbable and CraftCms\Cms\Field\Contracts\ThumbableFieldInterface, and overrides of thumbnail layout methods and thumbUrl(), must update their signatures for Craft 6, including through existing Yii aliases; existing calls remain valid. The Yii Assets service wrapper and legacy thumbnail event are unchanged.CraftCms\Cms\Asset\Elements\Asset::$colors. (#19740, #19750)CraftCms\Cms\Asset\Elements\Asset::getBlurhash(). (#19755)CraftCms\Cms\Asset\Elements\Asset::getPlaceholderDataUrl(). (#19750)CraftCms\Cms\Asset\Elements\Asset::$uploadColors. (#19751)CraftCms\Cms\Image\Blurhash. (#19755)CraftCms\Cms\Image\ColorGrid. (#19755)CraftCms\Cms\Image\Data\ImageColors. (#19740, #19750)CraftCms\Cms\Image\Images::colors(). (#19740, #19750)users/upload-user-photo to start an upload session using JSON file metadata instead of multipart file data.assets/upload and assets/replace-file multipart endpoints and legacy uploader events and overrides.CraftCms\Cms\Condition\BaseConditionGroup. (#19587)CraftCms\Cms\Condition\ConditionBuilderPayload. (#19587)CraftCms\Cms\Condition\ConditionBuilderRenderer. (#19587)CraftCms\Cms\Condition\ConditionBuilder. (#19587)CraftCms\Cms\Condition\ConditionRulePayload. (#19587)CraftCms\Cms\Condition\Contracts\ConditionComponentInterface. (#19587)CraftCms\Cms\Condition\Contracts\ConditionGroupInterface. (#19587)CraftCms\Cms\Condition\Contracts\ConditionInterface::createGroup(). (#19587)CraftCms\Cms\Condition\Contracts\ConditionRuleInterface::getForm(), which replaces getHtml(). (#19588)CraftCms\Cms\Condition\Contracts\ConditionRuleInterface::isSelectableForCondition(). (#19563)CraftCms\Cms\Condition\Enums\GroupOperator. (#19587)CraftCms\Cms\Element\Conditions\Contracts\ElementQueryConditionRuleInterface, which element condition rules that modify element queries should now implement. (#19563)CraftCms\Cms\Element\Conditions\ElementCondition::$forQuery. (#19563)CraftCms\Cms\Element\Conditions\ElementCondition. (#19587)CraftCms\Cms\Condition\Contracts\ConditionRuleInterface::getHtml(). getForm() must be implemented instead. (#19588)CraftCms\Cms\Element\Conditions\Contracts\ElementConditionRuleInterface::getExclusiveQueryParams() and modifyQuery(). ElementQueryConditionRuleInterface::modifyQuery() should be implemented instead, which now accepts the underlying query builder directly. (#19563)CraftCms\Cms\Element\Conditions\ElementCondition::$queryParams. (#19563)CraftCms\Cms\Field\Contracts\FieldInterface::modifyQuery() now accepts an Illuminate\Database\Query\Builder object for its $query argument, and has a new CraftCms\Cms\Element\Queries\Contracts\ElementQueryInterface $elementQuery argument, and a void return type. (#19562, #19585)CraftCms\Cms\Workflow\Contracts\WorkflowStageInterface and CraftCms\Cms\Workflow\Stages\WorkflowStage, for creating custom workflow stage types. (#19667)CraftCms\Cms\Workflow\WorkflowStageTypes, for registering custom workflow stage types. (#19667)CraftCms\Cms\Workflow\Contracts\WorkflowableInterface, which element types can implement to support workflows. (#19667)CraftCms\Cms\Workflow\Workflows and CraftCms\Cms\Support\Facades\Workflows. (#19667)CraftCms\Cms\Workflow\Events\WorkflowTransitioning, WorkflowTransitioned, and WorkflowCommented events. (#19667)autoEagerLoadElements general config setting (true by default), which determines whether element queries should be automatically lazy eager-loaded. (#19637)CraftCms\Cms\Activity\Contracts\ShouldBeRetained, allowing activity event types such as comments to opt out of activity garbage collection.CraftCms\Cms\User\Elements\User elements. (#19541)authGuard and authPasswordBroker general config settings, allowing Craft authentication to use a dedicated Laravel guard, provider, and password broker. (#19598)config/filesystems.php, and each defines whether its assets have public URLs. Existing filesystem references are migrated to matching disks automatically, with an actionable error if a disk isn’t configured. (#19650)CraftCms\Cms\Asset\Models\Volume::$hasUrls, which determines whether the volume’s assets have public URLs. (#19650)CraftCms\Cms\Config\GeneralConfig::$uploadSessionDisk and getUploadSessionDisk(), which determine the disk used to stage upload sessions. (#19650)CraftCms\Cms\Config\GeneralConfig::$tempAssetUploadFs to $tempAssetUploadDisk, and getTempAssetUploadFs() to getTempAssetUploadDisk(), which now reference a Laravel filesystem disk exclusively. (#19650)CraftCms\Cms\Cp\SelectOptions::getFsOptions() to getDiskOptions(), which now returns Laravel filesystem disk options exclusively. (#19650)CraftCms\Cms\Asset\Assets::getTempAssetUploadFs() and CraftCms\Cms\Asset\AssetsHelper::isTempUploadFs(). Assets::getTempAssetUploadDisk() should be used instead, which now returns a Laravel filesystem disk. (#19650)CraftCms\Cms\Cp\Components\FilesystemSelect and CraftCms\Cms\Form\Controls\FilesystemSelect. (#19650)CraftCms\Cms\Filesystem\Filesystems, FilesystemTypes, Contracts\FsInterface, Filesystems\Filesystem (and its DiskFilesystem, Local, MissingFs, and Temp implementations), Resources\FsResource, Events\FilesystemRenamed, and CraftCms\Cms\Support\Facades\Filesystems. Laravel filesystem disks should be configured and referenced directly instead; Craft filesystem types registered through craft\base\Fs remain supported for legacy plugins via the Yii adapter. (#19650)CraftCms\Cms\Http\Controllers\Settings\FilesystemsController and CraftCms\Cms\Http\ViewModels\FilesystemsEditViewModel, along with the Filesystems control panel settings page. (#19650)CraftCms\Cms\Plugin\Concerns\HasFilesystemTypes. Plugins can no longer register custom Craft filesystem types. (#19650)CraftCms\Cms\Form\Controls\Text::suffix() for display-only suffix text in PHP and Vue form controls. (#19770)CraftCms\Cms\Element\Data\ElementSiteSettings, the shared base for element URI and route settings. (#19762)CraftCms\Cms\Form\Nodes\Group::expanded(), allowing collapsible section groups to start expanded in Vue and HTML forms. (#19772)CraftCms\Cms\Route\CurrentElement, a contextual attribute for injecting the matched element into controller actions and route closures. (#19762)CraftCms\Cms\Contracts\PluginInterface::createSettings(), which replaces createSettingsModel(). (#19574)CraftCms\Cms\Dashboard\Widgets\Widget::component() and props(), which replace getBodyHtml(). (#19564)CraftCms\Cms\Support\Url::stripCpTrigger(). (#19724)CraftCms\Cms\Support\Url::removeParam() now accepts an array of param names. (#19724)CraftCms\Cms\Contracts\PluginInterface::createSettingsModel(). createSettings() must be implemented instead. (#19574)CraftCms\Cms\Dashboard\Widgets\Widget::getBodyHtml(). component() and props() must be implemented instead. (getBodyHtml() remains supported through the Yii adapter.) (#19564)CraftCms\Cms\Support\Url::baseUrl(), cpHost(), encodeParams(), host(), isFullUrl(), removeParams(), and rootRelativeUrl(). (They remain available on craft\helpers\UrlHelper through the Yii adapter.) (#19724)Cp.$elementDetailsTabs, allowing plugins to register control panel element-details tabs. (#19646)CraftCms\Cms\Support\Flash::all(), make(), and push(), and a $target argument to Flash::success(), error(), and notice() for showing a message in an inline outlet rather than the default message display.messages Inertia shared prop, which carries every flashed control panel message with its type, settings, and id.useMessages() and useMessageOutlet() for showing control panel messages from Vue, and the craft-message window event for showing them from anywhere else.asSuccess() and asFailure() JSON responses now include a messages list on control panel requests, and asSuccess() no longer also flashes the message to the session for JSON responses.asFailure() now flashes its message even when the response has validation errors.flash Inertia shared prop. messages should be used instead.useFlash(), useFlashMessages(), and the FlashMessages Vue component. useMessages() should be used instead.XRegExp library by default. Plugins that require it can register craft\web\assets\xregexp\XregexpAsset. (#19621)CraftCms\Cms\ProjectConfig\ProjectConfig::getPendingChanges().url(''), siteUrl(''), and homepage URLs, now respect the addTrailingSlashesToUrls config setting, so they no longer end with a trailing slash by default. The siteUrl Twig variable still always ends with a trailing slash. (#19723)CraftCms\Cms\Support\Env::parse() to preserve unknown aliases rather than throw an exception. (#19535)CraftCms\Cms\Filesystem\Filesystems\Filesystem::getRootUrl(). (#19535)resave and update-statuses commands reported skipped revisions as root element lookup errors.composer.json partially modified after a failure. (#19568)__ERROR__ or __VALUE__ keys. (#19568)readOnly state. (#19726)<craft-input-date-time> didn’t have individual accessible names. (#19741)CRAFT_SITE or X-Craft-Site referenced a missing site. (#19745)<craft-callout> boxes didn’t span all columns in grid layouts. (#19773)<craft-input> fields with a maxlength weren’t sized to fit it, which made the element index pagination’s page input overlap the “Next page” button.Removed CraftCms\Cms\Config\GeneralConfig::$isSystemLive , app()->isLive() , and the core craft:on and craft:off commands. Deprecated compatibility re…
CraftCms\Cms\Asset\AssetTransformers and CraftCms\Cms\Asset\AssetTransformDrivers.CraftCms\Cms\Config\GeneralConfig::$defaultAssetTransformer.CraftCms\Cms\Config\GeneralConfig::$isSystemLive, app()->isLive(), and the core craft:on and craft:off commands. Deprecated compatibility remains available through craftcms/yii2-adapter.generateTransformsBeforePageLoad setting to Craft Asset Transformer profiles.CraftCms\Cms\Image\ImageTransforms. Legacy equivalents remain available through craftcms/yii2-adapter.$ or @, automatically bracing embedded environment variables.config/craft/app.php did not receive messages logged with Craft::info() and related methods. (#19517)CraftCms\Cms\Filesystem\Filesystems\Local, with legacy filesystem compatibility remaining available through craftcms/yii2-adapter. (#19525)Improved template resource cache collection by replaying structured HTML stack entries without parsing rendered tags.
CraftCms\Cms\Auth\Passkeys\Passkeys::verifyPasskey() to return the updated credential record on success.webonyx/graphql-php while preserving Craft-specific query condition validation.CraftCms\Cms\Form\FormResolver performance by indexing control paths and node UIDs for membership checks.CraftCms\Cms\Http\ResponseHeaders and CraftCms\Cms\Support\Facades\ResponseHeaders for accumulating response headers within the current request scope.CraftCms\Cms\Support\Json::decode() to use exception-based JSON decoding.craft:db:drop-all-tables to use Laravel’s schema API.CraftCms\Cms\Asset\Enums\AssetIndexStatus and explicit status transitions.CraftCms\Cms\Plugin\Plugin::settingsForm() for defining standard plugin settings pages with the Control Panel Form system. (#19439)CraftCms\Cms\Plugin\Plugin::settingsHtml(). settingsForm() should be used instead; Yii-era plugin settings HTML remains supported by craftcms/yii2-adapter. (#19439)CpScreenResponse-based screen as an in-page panel from a normal Inertia response, alongside the existing legacy Craft.CpScreenSlideout. (#19354)CraftCms\Cms\Http\Responses\CpScreenResponse::screenData(). (#19354)Pane.vue Vue component in favor of the craft-pane web component. (#19398)CraftCms\Cms\Edition capability checks could report capabilities from the configured edition rather than the receiver.CraftCms\Cms\Element\ElementCollection::with() could pass incompatible element classes into eager loading.CraftCms\Cms\Utility\Utilities\ClearCaches::add() and addTag() were unavailable as Artisan commands.craft\web\View::registerAssetBundle() during plugin initialization were not included in rendered pages. (#19393)craftcms/yii2-adapter. (#19394)config/craft/app.web.php or config/craft/app.console.php was present.jobprogress table was missing dateCompleted and dateFailed columns for installs that were upgraded from Craft 5.Fixed a bug where Yii-style migrations could be required twice.
Deprecated the Craft.LightSwitch , Craft.InfoIcon , Craft.ColorInput , Craft.PasswordInput , Craft.IconPicker , Craft.SlidePicker , Craft.SlideRuleInp…
resources/widgets/ directory. (#19319)pixelandtonic/imagine with intervention/image for image manipulation.intervention/image-driver-vips package.CraftCms\Cms\FieldLayout\FieldLayout, CraftCms\Cms\FieldLayout\FieldLayoutTab, and field layout elements.craft:resave:all to discover registered craft:resave:* Artisan commands directly, rather than relying on a resolving event. (#19270)CraftCms\Cms\Cp\FormFields::textFromConfig() to accept an optional CraftCms\Cms\Cp\Components\Input instance as a second argument, so callers can build on an existing component instead of always creating a plain Input. (#19323)CraftCms\Cms\Search\Events\SearchPerformed to be a readonly, immutable event; its $results and $scores properties can no longer be overridden by listeners. CraftCms\Cms\Search\Events\SearchScoresResolving should be used to override scores instead. (#19308)CraftCms\Cms\Asset\AssetFileKinds. (#19270)CraftCms\Cms\Cp\Components\Button::action(), for declarative click actions. (#19324)CraftCms\Cms\Cp\Components\Button::inherit(). (#19306)CraftCms\Cms\Cp\Components\InputColor. (#19323)CraftCms\Cms\Cp\Components\InputPassword. (#19323)CraftCms\Cms\Cp\Data\NavItem::group(). (#19350)CraftCms\Cms\Cp\Enums\ButtonVariant. (#19306)CraftCms\Cms\Cp\FormFields::colorFromConfig(). (#19323)CraftCms\Cms\Cp\FormFields::passwordFromConfig(), passwordHtml(), and passwordFieldHtml(). (#19323)CraftCms\Cms\Cp\Html\ElementHtml::elementCardLabelHtml(), elementCardActionsHtml(), elementCardThumbHtml(), and elementCardThumbAlignment(). (#19324)CraftCms\Cms\Cp\Settings::registerSetting() and registerReadOnlySetting(). (#19270)CraftCms\Cms\Dashboard\WidgetTypes. (#19270)CraftCms\Cms\Database\Commands\MigrateCommand::registerMigrator(). (#19270)CraftCms\Cms\Element\ElementTypes. (#19270)CraftCms\Cms\Element\NestedElementManager::getCardsData() and getIndexData(). (#19324)CraftCms\Cms\Field\FieldTypes. (#19270)CraftCms\Cms\Field\LinkTypes. (#19270)CraftCms\Cms\Field\NestedEntryFieldTypes. (#19270)CraftCms\Cms\FieldLayout\NativeFields. (#19270)CraftCms\Cms\Filesystem\FilesystemTypes. (#19270)CraftCms\Cms\Gql\GqlArguments. (#19270)CraftCms\Cms\Gql\GqlDirectives. (#19270)CraftCms\Cms\Gql\GqlMutations. (#19270)CraftCms\Cms\Gql\GqlQueries. (#19270)CraftCms\Cms\Gql\GqlTypes. (#19270)CraftCms\Cms\Image\ImageTransformers. (#19270)CraftCms\Cms\Image\Raster::getInterventionImage().CraftCms\Cms\Plugin\Plugin::$filesystemTypes. (#19307)CraftCms\Cms\Plugin\Plugin::$gqlDirectives. (#19307)CraftCms\Cms\Plugin\Plugin::$gqlMutations. (#19307)CraftCms\Cms\Plugin\Plugin::$gqlQueries. (#19307)CraftCms\Cms\Plugin\Plugin::$gqlTypes. (#19307)CraftCms\Cms\Plugin\Plugin::$linkTypes. (#19307)CraftCms\Cms\Plugin\Plugin::$siteTemplateRoots. (#19307)CraftCms\Cms\Plugin\Plugin::getCacheOptions(). (#19307)CraftCms\Cms\Plugin\Plugin::getCacheTags(). (#19307)CraftCms\Cms\Plugin\Plugin::getNativeFields(). (#19307)CraftCms\Cms\Plugin\Plugin::getSystemMessages(). (#19307)CraftCms\Cms\Search\Events\SearchResultsResolving. (#19308)CraftCms\Cms\Search\Events\SearchScoresResolving. (#19308)CraftCms\Cms\Support\Facades\AuthMethods. (#19270)CraftCms\Cms\SystemMessage\SystemMessages::register(). (#19270)CraftCms\Cms\Twig\Variables\Cp::color() and password(). (#19323)CraftCms\Cms\User\UserPermissions::registerPermissionGroup(). (#19270)CraftCms\Cms\Utility\Utilities\ClearCaches::add() and addTag(). (#19270)CraftCms\Cms\Utility\UtilityTypes. (#19270)CraftCms\Cms\View\TemplateCacheCollectors. (#19270)CraftCms\Cms\View\TemplateRoots. (#19270)CraftCms\Cms\Support\Concerns\EvaluatesClosures and support for closure values in fluent CP component and field layout builder APIs.CraftCms\Cms\FieldLayout\LayoutElements\BaseField::label() to accept an optional label and return the field layout element when one is passed. Overrides must accept the new optional argument.CraftCms\Cms\Image\Raster::getTextBox() to return a width and height array.CraftCms\Cms\FieldLayout\LayoutElements\BaseField::instructions(), tip(), and warning() methods to instructionsText(), tipText(), and warningText().CraftCms\Cms\Asset\Events\AssetFileKindsResolving. CraftCms\Cms\Asset\AssetFileKinds::register() should be used instead. (#19270)CraftCms\Cms\Auth\Events\AuthMethodsResolving. CraftCms\Cms\Auth\AuthMethods::register() should be used instead. (#19270)CraftCms\Cms\Cp\Events\RegisterCpSettings and CraftCms\Cms\Cp\Events\RegisterReadonlyCpSettings. CraftCms\Cms\Cp\Settings::registerSetting() and registerReadOnlySetting() should be used instead. (#19270)CraftCms\Cms\Dashboard\Events\WidgetTypesResolving. CraftCms\Cms\Dashboard\WidgetTypes::register() should be used instead. (#19270)CraftCms\Cms\Database\Events\MigratorsResolving. CraftCms\Cms\Database\Commands\MigrateCommand::registerMigrator() should be used instead. (#19270)CraftCms\Cms\Element\Events\ElementResaveCommandsResolving. A normal Artisan command in the craft:resave namespace should be registered instead. (#19270)CraftCms\Cms\Element\Events\ElementTypesResolving. CraftCms\Cms\Element\ElementTypes::register() should be used instead. (#19270)CraftCms\Cms\Field\Events\FieldTypesResolving. CraftCms\Cms\Field\FieldTypes::register() should be used instead. (#19270)CraftCms\Cms\Field\Events\LinkTypesResolving. CraftCms\Cms\Field\LinkTypes::register() should be used instead. (#19270)CraftCms\Cms\Field\Events\NestedEntryFieldTypesResolving. CraftCms\Cms\Field\NestedEntryFieldTypes::register() should be used instead. (#19270)CraftCms\Cms\FieldLayout\Events\NativeFieldsResolving. CraftCms\Cms\FieldLayout\NativeFields::register() should be used instead. (#19270)CraftCms\Cms\Filesystem\Events\FilesystemTypesResolving. CraftCms\Cms\Filesystem\FilesystemTypes::register() should be used instead. (#19270)CraftCms\Cms\Gql\Events\GqlArgumentHandlersResolving. CraftCms\Cms\Gql\GqlArguments::register() should be used instead. (#19270)CraftCms\Cms\Gql\Events\GqlDirectivesResolving. CraftCms\Cms\Gql\GqlDirectives::register() should be used instead. (#19270)CraftCms\Cms\Gql\Events\GqlMutationsResolving. CraftCms\Cms\Gql\GqlMutations::register() should be used instead. (#19270)CraftCms\Cms\Gql\Events\GqlQueriesResolving. CraftCms\Cms\Gql\GqlQueries::register() should be used instead. (#19270)CraftCms\Cms\Gql\Events\GqlTypesResolving. CraftCms\Cms\Gql\GqlTypes::register() should be used instead. (#19270)CraftCms\Cms\Image\Events\ImageTransformersResolving. CraftCms\Cms\Image\ImageTransformers::register() should be used instead. (#19270)CraftCms\Cms\Image\Images::MINIMUM_IMAGICK_VERSION and craft\services\Images::MINIMUM_IMAGICK_VERSION.CraftCms\Cms\Image\Raster::getImagineImage().CraftCms\Cms\Search\Events\ScoringResults in favor of the following new events: (#19308)
CraftCms\Cms\Search\Events\SearchResultsResolvingCraftCms\Cms\Search\Events\SearchScoresResolvingCraftCms\Cms\SystemMessage\Events\SystemMessagesResolving. CraftCms\Cms\SystemMessage\SystemMessages::register() should be used instead. (#19270)CraftCms\Cms\User\Events\UserPermissionsResolving. CraftCms\Cms\User\UserPermissions::registerPermissionGroup() should be used instead. (#19270)CraftCms\Cms\Utility\Events\ClearCachesOptionsResolving and CraftCms\Cms\Utility\Events\ClearCachesTagOptionsResolving. CraftCms\Cms\Utility\Utilities\ClearCaches::add() and addTag() should be used instead. (#19270)CraftCms\Cms\Utility\Events\UtilitiesResolving. CraftCms\Cms\Utility\UtilityTypes::register() should be used instead. (#19270)CraftCms\Cms\View\Events\CpTemplateRootsResolving and CraftCms\Cms\View\Events\SiteTemplateRootsResolving. CraftCms\Cms\View\TemplateRoots::register() should be used instead. (#19270)CraftCms\Cms\View\Events\TemplateCacheCollectorsResolving. CraftCms\Cms\View\TemplateCacheCollectors::register() should be used instead. (#19270)@craftcms/ui/factory module, a jQuery-free layer of typed element factories that mirror the src/Cp/Components PHP builders. (#19323)createTextInput() and createCopyTextPrompt() to the @craftcms/ui/factory module. (#19333)turnOn(), turnOff(), and turnIndeterminate() methods to the <craft-switch> web component. (#19323)group property to the <craft-nav-item> web component, for rendering a subnav as a non-collapsible semantic grouping. (#19350)Garnish.CustomSelect and Garnish.MenuBtn to @craftcms/garnish, jQuery-free TypeScript ports of the legacy floating listbox menu and menu-button classes. (#19352)Craft.ComponentSelectInput control panel JavaScript class out of the core bundle into a yii2-adapter compatibility asset, since <craft-component-select> is now used everywhere in core; the componentSelect.twig jsClass escape hatch still works for plugin subclasses. (#19333)Craft.AssetMover, Craft.AssetSelectorModal, Craft.BaseElementSelectInput, Craft.BaseElementSelectorModal, Craft.BaseUploader, Craft.Chart, Craft.CpModal, Craft.CustomizeSourcesModal, Craft.DataTableSorter, Craft.ElementActionTrigger, Craft.ElementDeletionManager, Craft.ElementTableSorter, Craft.EntrySelectInput, Craft.Grid, Craft.PreviewFileModal, Craft.Tabs, Craft.TagSelectInput, Craft.Uploader, and Craft.VolumeFolderSelectorModal control panel JavaScript classes from the legacy jQuery bundle to TypeScript modules. (#19352)<craft-nav-item> to render as a <span> instead of an <a> when it has no href, dropping aria-current in that case. (#19350)Craft.LightSwitch, Craft.InfoIcon, Craft.ColorInput, Craft.PasswordInput, Craft.IconPicker, Craft.SlidePicker, Craft.SlideRuleInput, and Craft.Tooltip control panel JavaScript classes, along with the .infoicon jQuery plugin. The corresponding @craftcms/ui web components should be used instead. (#19323)Craft.Accordion and Craft.EnvVarGenerator control panel JavaScript classes. (#19323)Craft.DeleteUserModal control panel JavaScript class. It was deprecated in 5.10.0 and unused. (#19352)accent semantic color used by colorable elements (e.g. craft-callout, [data-color]) rendered red instead of blue, due to a drifted color mapping in @craftcms/ui. (#19306)forms.checkboxField() and CraftCms\Cms\Cp\FormFields::checkboxFieldHtml() rendered an empty field. (#19338)$ is not defined and window.Cp.config is not a function errors to the console. (#19340)actionClient requests for bare action paths could corrupt the ?site= query string on multi-site installs. (#19342)Craft.cp.announce() now accepts live regions that are plain elements as well as jQuery collections. (#19340)Fixed a high-severity authorization bypass vulnerability.
Important
This update contains breaking changes for plugins. See #19263 for details.
extra.laravel.providers in composer.json. (#19263)CraftCms\Cms\Cp\Components\Button. (#19248)CraftCms\Cms\Cp\Components\ButtonGroup. (#19248)CraftCms\Cms\Cp\Components\Callout. (#19248)CraftCms\Cms\Cp\Components\Checkbox. (#19248)CraftCms\Cms\Cp\Components\CheckboxGroup. (#19248)CraftCms\Cms\Cp\Components\CheckboxSelect. (#19248)CraftCms\Cms\Cp\Components\ChoiceGroup. (#19248)CraftCms\Cms\Cp\Components\ComponentRegistry. (#19248)CraftCms\Cms\Cp\Components\Field. (#19248)CraftCms\Cms\Cp\Components\FieldGroup. (#19248)CraftCms\Cms\Cp\Components\Lightswitch. (#19248)CraftCms\Cms\Cp\Components\Radio. (#19248)CraftCms\Cms\Cp\Components\RadioGroup. (#19248)CraftCms\Cms\Cp\Components\ViewComponent. (#19248)CraftCms\Cms\Cp\Concerns\EvaluatesClosures. (#19248)CraftCms\Cms\Cp\Concerns\HasAppearance. (#19248)CraftCms\Cms\Cp\Concerns\HasDisabled. (#19248)CraftCms\Cms\Cp\Concerns\HasId. (#19248)CraftCms\Cms\Cp\Concerns\HasSize. (#19248)CraftCms\Cms\Cp\Concerns\HasVariant. (#19248)CraftCms\Cms\Cp\Enums\Appearance. (#19248)CraftCms\Cms\Cp\Enums\Size. (#19248)CraftCms\Cms\Cp\Enums\Variant. (#19248)CraftCms\Cms\Cp\FormFields::buttonFromConfig(). (#19248)CraftCms\Cms\Cp\FormFields::buttonGroupFromConfig(). (#19248)CraftCms\Cms\Cp\FormFields::checkboxFromConfig(). (#19248)CraftCms\Cms\Cp\FormFields::checkboxGroupFromConfig(). (#19248)CraftCms\Cms\Cp\FormFields::checkboxSelectFromConfig(). (#19248)CraftCms\Cms\Cp\FormFields::lightswitchFromConfig(). (#19248)CraftCms\Cms\Cp\FormFields::radioFromConfig(). (#19248)CraftCms\Cms\Cp\FormFields::radioGroupFieldHtml(). (#19248)CraftCms\Cms\Cp\FormFields::radioGroupFromConfig(). (#19248)CraftCms\Cms\Support\Facades\Template. (#19290)CraftCms\Cms\Twig\Contracts\TwigRendererInterface. (#19290)CraftCms\Cms\Twig\Variables\Cp::button(). (#19248)CraftCms\Cms\Twig\Variables\Cp::buttonGroup(). (#19248)CraftCms\Cms\Twig\Variables\Cp::checkbox(). (#19248)CraftCms\Cms\Twig\Variables\Cp::checkboxGroup(). (#19248)CraftCms\Cms\Twig\Variables\Cp::checkboxSelect(). (#19248)CraftCms\Cms\Twig\Variables\Cp::lightswitch(). (#19248)CraftCms\Cms\Twig\Variables\Cp::radio(). (#19248)CraftCms\Cms\Twig\Variables\Cp::radioGroup(). (#19248)CraftCms\Cms\ui(). (#19248)CraftCms\Cms\View\TemplateManager. (#19290)template() and pageTemplate() now accept an optional template renderer name. (#19290)TemplateRendered and PageTemplateRendered events now expose the final renderer name via $rendererName; the corresponding before events no longer expose renderer identity. (#19290)CraftCms\Cms\Support\HtmlSanitizer\HtmlSanitizers with CraftCms\Cms\Support\HtmlSanitizer\HtmlSanitizerManager. HTML sanitizers should now be registered via CraftCms\Cms\Support\Facades\HtmlSanitizers::extend() rather than CraftCms\Cms\Support\HtmlSanitizer\HtmlSanitizers::register(). (#19292)CraftCms\Cms\Plugin\Events\PluginUnregistered. (#19263)CraftCms\Cms\Plugin\Plugin::bootPlugin(). boot() should be used instead. (#19263)CraftCms\Cms\Plugin\Plugin::registerPlugin(). register() should be used instead. (#19263)yii\web\JqueryAsset wasn’t resolving properly. (#19264)craft:users:set-password password validation, exit statuses, and session invalidation. (#19272)Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Fixed a high-severity SQL injection vulnerability. (GHSA-cphx-cx67-jcqj)
craft\db\Connection::cache() could cause infinite recursion when craft\cache\DbCache was used as the cache component. (#19877)update command. (#19878)Fixed a high-severity RCE vulnerability. (GHSA-hq78-cm2m-h24h)
craft\services\Users::destroyOtherSessions().craft\fields\Matrix::EVENT_DEFINE_ENTRY_TYPES. (#19685)attribute() Twig function was allowed within sandboxed Twig environments, even if it wasn’t listed in allowedFunctions.false key could return the wrong value when Dev Mode was disabled.setup/php-session-table and setup/db-cache-table commands. (#19742)Fixed an error that could occur when registering or logging in with a passkey. ( #19657 , #19660 )
Fixed a high-severity SQL injection vulnerability. (GHSA-mjj9-pjh4-r48g)
craft\helpers\StringHelper::containsNewlines().craft\services\ElementSources::CONTEXT_RESTRICTED_MODAL.craft\elements\db\EagerLoadPlan::$siteIds.Added support for symfony/filesystem 7.x and 8.x.
Fixed high-severity RCE vulnerabilities. ( GHSA-g48f-wc2q-4rrv , GHSA-wr79-9v6x-5rfq , GHSA-qm9x-rmcj-h2rc , GHSA-xmwr-88vw-5ghh )
Warning
GraphQL fields that return user data (author, authorId, authors, authorIds, draftCreator, revisionCreator, uploader, and uploaderId) are no longer available to schemas that don’t have “Query for users” enabled.
params argument of the url() Twig function now accepts false to remove all params from the passed-in URL. (#19102)craft\web\DbSession, which should be used instead of yii\web\DbSession to prevent “headers already sent” warnings from getting logged. (#19139)craft\fields\data\LinkData objects now include type, value, url, label, filename, link, attributes, defaultLabel, elementType, elementId, elementSiteId, and elementTitle keys. (craftcms/element-api#201)craft\fieldlayoutelements\CustomField::$oldFieldUid.craft\fields\conditions\FieldConditionRuleInterface::getFieldUid().craft\helpers\ElementHelper::containsTempSlug().craft\helpers\Gql::canQueryAllUsers().craft\helpers\UrlHelper::removeAllParams(). (#19102)craft\helpers\UrlHelper::removeParams(). (#19102)craft\services\Config::doesEnvVarExist().craft\services\Elements::reorderNestedElements(). (#19321)craft\helpers\App::parseEnv() behavior. (#19524, #19522)$params argument of craft\helpers\UrlHelper::url() now accepts false to remove all params from the passed-in URL. (#19102).well-known/passkey-endpoints requests. (#19364)craft\web\Controller::asModelSuccess() and asModelFailure() could include more data than expected. (#19469)null was passed to an asset query’s uploader param. (#19484).env file, and cause the license key input to disappear. (#19518)fields/auto-merge command. (#19519)getEagerLoadedElements() wasn’t returning results for eager-loaded native fields, such as authors. (#19471)Fixed high-severity RCE vulnerabilities. (GHSA-5m2g-hhqr-84pc, GHSA-vfcw-xv8p-8rj2)
Fixed high-severity RCE vulnerabilities. (GHSA-5jmw-g85v-7jv2, GHSA-9c4j-cjw3-r3xx, GHSA-5r92-75j8-c534)
craft\helpers\StringHelper::isMd5().project-config/apply --force. (#19300){{ head() }}, {{ beginBody() }}, or {{ endBody() }} tags. (#19304)Fixed high-severity RCE vulnerabilities. (GHSA-9wcj-wqqh-cqvg, GHSA-qj4v-m29p-fj4m)
craft\helpers\Gql::isMutation(). (#19285)Fixed high-severity authorization bypass vulnerabilities. (GHSA-6qw4-cjqw-fj72, GHSA-3wcr-p33w-528f)
craft\gql\base\MutationResolver::requireAllowedSite().craft\web\twig\variables\CraftVariable::$rebrand was getting defined for Craft Team installs. (#19249)Updated web-auth/webauthn-lib to 5.3.
Fixed a low-severity information disclosure vulnerability.
craft\services\Security::isRestrictedDir(). (#19179)craft\helpers\Image::imageSizeByStream() now supports WebP, AVIF, and HEIC/HEIF images. (#19189)craft\services\Sites::getGroupById() now has a $withTrashed argument.site/siteId params weren’t being respected on eager-loaded localized queries. (#18588)--single-transaction flag on MariaDB. (#19191)Fixed a low-severity XSS vulnerability. (GHSA-2rp4-x2j7-qmcc)
previewTokenDuration config setting was defaulting to 1 day, rather than to the defaultTokenDuration value. (#18550)Fixed a high-severity RCE vulnerability. (GHSA-f5wm-88jv-g5hx)
craft\web\twig\AllowableInSandbox.craft\helpers\App::parseEnv() wasn’t resolving aliases for environment variables that referenced an alias (e.g. @root/storage/rebrand). (#19108)Fixed high-severity RCE vulnerabilities. (GHSA-f5wm-88jv-g5hx, GHSA-265m-7826-wjqm)
craft\controllers\EVENT_BEFORE_SAVE_IMAGE. (#19068)craft\events\SaveAssetImageEvent. (#19068)craft\web\Request::getPreviewParam().X-Robots-Tag: none headers weren’t always being sent for requests with x-craft-preview or x-craft-live-preview query string params. (#19060)craft\helpers\App::parseEnv() wasn’t returning boolean values for environment variable names that resolved to true/false values. (#19029)width and height attributes. (#1902w7)config/general.console.php or config/general.web.php. (#19083)Fixed a moderate-severity authorization bypass vulnerability. (GHSA-wg23-69c2-gjc8)
craft\base\ElementInterface::afterAssignedId().users/remove-2fa command non-interactively, if --method wasn’t provided. (#18724):empty:/:notempty: params properly. (#18988, #19019){id} in their Default Title Format weren’t always getting created with the correct generated title. (#18991)Fixed a bug where an empty storage/runtime/ directory was getting created even if runtimePath was being overridden in config/app.php.
storage/runtime/ directory was getting created even if runtimePath was being overridden in config/app.php. (#18936)Fixed a moderate-severity authorization bypass vulnerability. (GHSA-rvmm-v933-jgxq)
craft\services\Path::getRuntimePath(). Craft::$app->getRuntimePath() should be called instead.config/app.php wasn’t possible. (#18936)Updated Twig to 3.26. (#18924, #18926)
Fixed a bug where assets’ Alternative Text values weren’t always being set when replacing an existing asset’s file.
Fixed a high-severity RCE vulnerability. (GHSA-f74w-488g-8x5r)
min-width styles based on their configured widths, if set. (#18534)<br> tags. (#18058)--to-default option to resave commands. (#18522)--method option to the users/remove-2fa command. (#18732)heading()/h() and h1()…h6() Twig functions. (#18524)tag() Twig function now accepts a string for its second argument. (#18524)|attr, |parseAttr, and |removeClass Twig filters no longer log warnings when performed on a string without an HTML tag. (#17622)|default Twig filter and is empty Twig test now treat all yii\base\Model instances as not empty. (#18727)|number Twig filter now has a locale argument. (#18823)|time and |datetime Twig filters now have withTimeZone arguments. (#18639)|timestamp Twig filter now returns the current time, if applied to a null/empty string value. (#18642)dataUrl() is no longer allowed in sandboxed Twig environments by default.delete GraphQL queries now have a hardDelete argument. (#18511)postDate values are now null on creation, rather than set to the dateCreated value. (#18642)url GraphQL fields’ immediately arguments are no longer deprecated. (#18581)craft\filters\SecFetchSiteFilter for request origin verification. (#18641)craft\fields\data\LinkData::getUrl() now has an $anyStatus argument, which can be set to false to prevent a value from being returned if a disabled/pending/expired element is linked. (#18527)craft\base\DefaultableFieldInterface. (#18522)craft\base\Element::EVENT_DEFINE_DELETION_BLOCKERS. (#18728)craft\base\ElementActionInterface::getTriggerId().craft\base\ElementInterface::deletionBlockers(). (#18728)craft\base\ElementInterface::setDirtyFieldTracking().craft\elements\PopulateElementEvent::$content.craft\elements\db\ElementQuery::$activeQuery.craft\elements\db\ElementQueryInterface::collectIds().craft\elements\deletionblockers\BaseDeletionBlocker. (#18728)craft\elements\deletionblockers\DeletionBlockerInterface. (#18728)craft\elements\deletionblockers\EntryAuthorsBlocker. (#18728)craft\elements\deletionblockers\RelationDeletionBlocker. (#18728)craft\errors\FieldNotFoundException::$fieldId.craft\events\DefineElementDeletionBlockersEvent. (#18728)craft\fieldlayoutelements\CustomField::setFieldId().craft\helpers\ElementHelper::belongsToCanonicalOwner().craft\helpers\Html::jsWithVars().craft\helpers\Markdown. (#18671)craft\models\Section::$minAuthors. (#18662)craft\queue\jobs\ReplaceRelations. (#18728)craft\services\Elements::REF_TAG_PATTERN.craft\services\Entries::reassignEntries().craft\validators\TimeValidator::$outOfRange. (#18575)Craft.CpScreenSlideout::reload(). (#18625)Craft.ElementDeletionManager.craft\elements\PopulateElementEvent::$row no longer includes fieldValues or generatedFieldValues keys.craft\helpers\DateTimeHelper::timeZoneAbbreviation() is no longer deprecated, and now has a $date argument.craft\i18n\Formatter::asTime() and asDatetime() now have $withTimeZone arguments. (#18639)craft\controllers\AppController::actionResourceJs(). (#18559)Craft.CP now triggers a queueCompleted event when the last queue job is completed.craft\controllers\UsersController::EVENT_DEFINE_CONTENT_SUMMARY. (#18728)craft\elements\User::$inheritorOnDelete. (#18728)craft\elements\actions\DeleteUsers. (#18728)craft\events\DefineUserContentSummaryEvent. (#18728)Craft.DeleteUserModal. (#18728)optimizeImageFilesize is disabled. (#18635)Fixed a high-severity XSS vulnerability. (GHSA-24x4-j6x9-rfw5)
entrify/global-set command on subsequent environments. (#18767)Fixed a moderate-severity authorization bypass vulnerability. (GHSA-7h62-6v23-v8fm)
composer.json were getting updated when installing/updating plugins. (#18755)Fixed high-severity authorization bypass vulnerabilities. (GHSA-x5m4-g2cq-52pq)
resourceBasePath and resourceBaseUrl config settings weren’t being respected for console requests. (#18685)*Interface type condition. (#18708)id param was overridden. (#15570)Fixed an issue that prevented Craft from being installed.
eagerly(). (#18693)Deprecated craft\services\ProjectConfig::getPendingChangeSummary().
create() Twig function. (#18376)craft\helpers\ProjectConfig::pathDepth().craft\services\Fields::deleteLayout() and deleteLayoutById() now have $hardDelete arguments.craft\services\ProjectConfig::getPendingChangeSummary().entrify/global-set command. (#18650)craft\fields\data\JsonData objects from Twig. (#18656)Fixed moderate-severity information disclosure vulnerabilities. (GHSA-gj2p-p9m4-c8gw, GHSA-33m5-hqp9-97pw)
craft\controllers\ElementIndexesController::$fieldLayouts.craft\services\ElementSources::getTableAttributes() now has a $fieldLayouts argument.aria-activedescendant, aria-flowto, and aria-owns attributes weren’t getting namespaced by {% namespace %} tags. (#18577)enabled values were being treated as enabled. (#18572)on EntryInterface) rather than a specific type name. (#18588)loginPath, logoutPath, setPasswordPath, or verifyEmailPath config settings were set to a callable that called the sites service. (#18605)Added craft\helpers\DateTimeHelper::testTimeToSeconds().
craft\helpers\DateTimeHelper::testTimeToSeconds().utils/fix-field-layout-uids command. (#18516)craft\filters\SiteFilterTrait.authorGroup params with and or not operators wasn’t working properly. (#18551)gc command, if a Matrix field had been converted to an Addresses or Content Block field. (#18549)Updated @simplewebauthn/browser to 13.3.0.
craft\web\AssetManager::$cacheSourcePaths disabled. (#18536)craft\fields\data\LinkData::getUrl() was returning the URL suffix rather than an empty string, if the rendered base URL was an empty string.Fixed moderate-severity SSRF vulnerabilities. (GHSA-3m9m-24vh-39wx, GHSA-95wr-3f2v-v2wh)
craft\filters\IpRateLimitIdentity. (#18510)craft\helpers\App::resourcePathByUri().users/suspend-user and users/unsuspend-user actions required that the logged-in user have control panel access. (#18485)width and height attributes weren’t getting them set as expected.target="_blank" added to them. (#18500)resave commands. (#18453)craft\helpers\UrlHelper::cpReferralUrl() was returning the referrer URL even if it had the same URI as the current page. (#18483)Fixed low-severity information disclosure vulnerabilities. (GHSA-44px-qjjc-xrhq, GHSA-vgjg-248p-rfm2, GHSA-x76w-8c62-48mg)
PDO::MYSQL_ATTR_MULTI_STATEMENTS attribute is no longer set by default for database connections. (#18474)craft\elements\Entry::canMove().Fixed a high-severity RCE vulnerability. (GHSA-2fph-6v5w-89hh)
PDO::MYSQL_ATTR_MULTI_STATEMENTS attribute is now set to false by default for database connections.searchindex and searchindexqueue rows weren’t being deleted when an element was deleted for a site. (#18394)craft\helpers\App::parseEnv() was returning null instad of an empty string, when an environment variable name was passed in, which was set to an empty string.Fixed a high-severity permission escalation vulnerability. (GHSA-cc7p-2j3x-x7xf)
craft\services\Tokens::getRemainingTokenUsages().craft\web\Request::getTokenRoute().Fixed moderate-severity RCE vulnerabilities. (GHSA-4484-8v2f-5748, GHSA-qx2q-q59v-wf3j)
nb locale is now treated as a fallback for no on environments where no isn’t supported. (#18431)on/off and yes/no. (#18441)craft\helpers\Typecast. (#18426)App::normalizeBooleanValue().craft\events\ExecuteGqlQueryEvent::$cacheDuration. (#18442)craft\events\ExecuteGqlQueryEvent::$cacheTags. (#18442)craft\web\Request::getWantsImage().craft\web\Request::getWantsJson().craft\web\Request::wants().brokenImagePath config setting for Chrome. (#18438)0.slug columns referenced in element queries’ select, where, or orderBy expressions now explicitly resolve to elements_sites.slug.
slug columns referenced in element queries’ select, where, or orderBy expressions now explicitly resolve to elements_sites.slug. (#18416)craft\helpers\App::parseBooleanEnv() wasn’t handling false values properly. (#18418)DECIMAL field values with 0 precision weren’t gettnig typecasted properly in element queries.Fixed a high-severity RCE vulnerability. (GHSA-fp5j-j7j4-mcxc)
[!WARNING]
Relational condition rules’ element ID templates are now rendered in a sandboxed Twig environment, whenenableTwigSandboxis enabled.
craft\helpers\ElementHelper::cleanseQueryCriteria().Element edit pages no longer redirect to their referral URL on save.
Fixed a low-severity XSS vulnerability. (GHSA-fvwq-45qv-xvhv)
X-Craft-Gql-Cache: no-cache header, or if the request contained any mutations. (#18348)content/<page-name>.create() Twig function now allows craft\helpers\ classes to be created. (#18376)yii\base\Event is now allowed in its entirety within sandboxed Twig environments.craft\helpers\ElementHelper::elementRevisionsUrl().craft\web\View::renderSandboxedObjectTemplate() and renderSandboxedString() weren’t properly sandboxing templates rendered from the control panel.draftOf set to false were omitting canonical elements that were duplicated for an owner draft.craft\models\Volume::getSubpath() could return / instead of an empty string, if the subpath was set to an environment variable set to an empty string. (#18379)alt text via GraphQL mutations. (#18381)Deprecated craft\models\FieldLayout::getThumbField(). hasThumbField() or getThumbHtmlForElement() should be used instead.
craft\db\mysql\Schema::getRowFormat().craft\db\mysql\Schema::setRowFormat().craft\fieldlayoutelements\BaseField::getThumbOptions().craft\helpers\Cp::cardThumbOptions().craft\models\FieldLayout::getThumbHtmlForElement().craft\models\FieldLayout::hasThumbField().craft\models\FieldLayout::getThumbField(). hasThumbField() or getThumbHtmlForElement() should be used instead.entrytypes table’s row format was set to COMPACT. (#18349)Fixed an unintentional breaking change when querying Link field data via GraphQL.
Your coding agent can read these notes before it upgrades. Set up the MCP server →