NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
Packagist · #3801 most downloaded on Packagist
Craft CMS
Last release 5 days ago
01 Oct 2026
Ships on a steady schedule
a new release about every 2 weeks
Most releases are documented
notes for 41 of the last 60 stable releases
Nothing withdrawn
no release was ever pulled
13 years old
1341 releases · first in 2013
Fixed an error that occurred when upgrading to Craft 5.
One column per quarter.
Fixed an error that could occur when updating to Craft 5.9.
position properties weren’t being handled properly. (#18310)Fixed low-severity XSS vulnerabilities. (GHSA-4mgv-366x-qxvx)
min/max attributes set on their input. (#17973)composer.json are now set with caret operators (e.g. ^1.2.3). (#18297)entrify commands no longer require a category group/tag group/global set handle to be passed.entrify commands now automatically assign newly-created channel/structure sections to “Categories” or “Tags” pages. (#17779)clear-cache command now accepts a space-delimited list of cache IDs that should be cleared.up command now warns about any astray license issues before running migrations. (#18297)up command rather than from migrate commands.enableTwigSandbox config setting. (#18208, #18216)useIdnaNontransitionalToUnicode config setting. (#17946)maxCachedCloudImageSize config setting is now set to 0 by default. (#17997)disableGraphqlTransformDirective config setting is now deprecated.true/false/null/integer/float values to the appropriate types. (#18267)foo/$ENV_NAME/bar or foo-${ENV_NAME}-bar). (#17794)CRAFT_SITE (the current site’s handle) and CRAFT_SITE_UPPER (the current site’s handle in UPPER_SNAKE_CASE) environment variables, which are defined at runtime. (#17794)yii\base\BaseObject via the create() Twig function, which fixes a moderate-severity SSTI issue. (GHSA-94rc-cqvm-m4pw)randomString() Twig function. (#18020)uuid() Twig function.hash filter now supports passing a hashing algorithm, such as 'md5' or 'sha256'. (#17885)@parseRefs and @transform GraphQL directives are now optional for each GraphQL schema, which fixes a high-severity IDOR issue. (GHSA-7x43-mpfg-r9wj)X-Craft-Preview-Token header, set to the x-craft-preview/x-craft-live-preview query param in the preview target URL.foo/$ENV_NAME/bar or foo-${ENV_NAME}-bar). (#17949)yii\base\BaseObject via the create() Twig function. (GHSA-94rc-cqvm-m4pw)uuid() Twig function.@parseRefs and @transform GraphQL directives are now optional for each GraphQL schema. (GHSA-7x43-mpfg-r9wj)craft\web\View::EVENT_BEFORE_RENDER_TEMPLATE and EVENT_BEFORE_RENDER_PAGE_TEMPLATE. (#18125)getIcon() method.craft\base\ElementIndex::multiPageSources(). (#17779)craft\base\ElementTrait::$applyingDraft. (#18057)craft\base\ElementTrait::$hasProvisionalChanges. (#17915)craft\base\ElementTrait::$propagateRequired.craft\base\FieldInterface::propagateValue().craft\elements\Entry::EVENT_DEFINE_META_FIELDS. (#17996)craft\elements\User::isInGroups(). (#17989)craft\elements\actions\Duplicate::$asDrafts.craft\elements\conditions\HintableConditionRuleTrait. (#17909)craft\events\DefineFieldActionsEvent.craft\events\DefineGqlArgumentsEvent.craft\events\DefineMetaFields. (#17996)craft\events\RegisterElementCardAttributesEvent::$fieldLayout. (#17920)craft\fieldlayoutelements\BaseField::EVENT_DEFINE_ACTION_MENU_ITEMS. (#18037)craft\fieldlayoutelements\BaseField::copyAttributeAction(). (#18114)craft\fieldlayoutelements\BaseField::getPreviewOptions().craft\fieldlayoutelements\BaseField::key().craft\fieldlayoutelements\CustomField::getElementEditCondition().craft\fieldlayoutelements\CustomField::setElementEditCondition().craft\fields\BaseRelationField::VIEW_MODE_CARDS_GRID.craft\fields\BaseRelationField::VIEW_MODE_CARDS.craft\fields\BaseRelationField::VIEW_MODE_LIST_INLINE.craft\fields\BaseRelationField::VIEW_MODE_LIST.craft\fields\BaseRelationField::VIEW_MODE_THUMBS.craft\fields\Matrix::VIEW_MODE_CARDS_GRID.craft\fields\data\LinkData::getAttributes(). (#18184)craft\gql\base\ElementArguments::EVENT_DEFINE_ARGUMENTS. (#18062)craft\helpers\Assets::resolveSubpath(). (#18103)craft\helpers\Cp::cardPreviewOptions().craft\helpers\ElementHelper::loadProvisionalChanges(). (#17915)craft\helpers\StringHelper::convertLineBreaks().craft\helpers\UrlHelper::cpReferralUrl().craft\i18n\Locale::getDefaultCurrency().craft\models\EntryType::$uiLabelFormat.craft\models\FieldLayout::$thumbFieldKey.craft\models\FieldLayout::getCardBodyHtmlForElement().craft\models\FieldLayout::getElementByKey().craft\models\FieldLayoutForm::getStaticElements().craft\models\Section::getCpIndexUri().craft\models\Section::getPage().craft\services\ElementSources::getFirstPage(). (#17779)craft\services\ElementSources::getPageSettings(). (#17779)craft\services\ElementSources::getPages(). (#17779)craft\services\ElementSources::pageExists(). (#17779)craft\services\ElementSources::pageNameId(). (#17779)craft\services\ElementSources::savePageSettings().craft\services\ElementSources::saveSources().craft\services\Search::deleteOrphanedIndexJobs().craft\services\Structure::EVENT_AFTER_UPDATE_ELEMENT.craft\services\Structure::EVENT_BEFORE_UPDATE_ELEMENT.craft\web\BaseSpreadsheetResponseFormatter.craft\web\GqlResponseFormatter.craft\web\Request::getHasInvalidToken().craft\web\Response::FORMAT_GQL.craft\web\Response::FORMAT_XLSX.craft\web\Response::FORMAT_YAML.craft\web\View::renderSandboxedObjectTemplate().craft\web\View::renderSandboxedString().craft\web\View::renderSandboxedTemplate().craft\web\XlsxResponseFormatter.craft\web\YamlResponseFormatter.craft\web\twig\AllowedInSandbox. (#18219)craft\web\twig\SecurityPolicy.craft\web\twig\nodes\BaseNode.Craft.BaseElementIndex::asyncSelectDefaultSource().Craft.BaseElementIndex::asyncSelectSource().Craft.BaseElementIndex::asyncSelectSourceByKey().Craft.BaseElementIndex::ensureSourceAttributeInfo().craft\base\Element::EVENT_AFTER_MOVE_IN_STRUCTURE is no longer deprecated.craft\base\Element::EVENT_BEFORE_MOVE_IN_STRUCTURE is no longer deprecated.craft\base\ElementInterface::afterMoveInStructure() is no longer deprecated.craft\base\ElementInterface::beforeMoveInStructure() is no longer deprecated.craft\base\ElementInterface::cardAttributes() now has a $fieldLayout argument. (#17920)craft\events\ElementStructureEvent is no longer deprecated.craft\fieldlayoutelements\CustomField::editable() now has an $element argument.craft\helpers\ElementHelper::findSource() now has $withDisabled and $page arguments.craft\helpers\FileHelper::writeToFile() now throws an exception if the file path isn’t writable, or there isn’t sufficient free space on the disk. (#17762)craft\helpers\UrlHelper now encodes square brackets in generated URLs. (#17840)craft\models\FieldLayout::getCardBodyElements() now always returns an array of arrays with html keys.craft\services\ElementSources::getSources() now has a $page argument. (#17779)craft\services\ElementSources::sourceExists() now has a $page argument. (#17779)craft\web\Request::accepts() now accepts wildcard characters (*) in the $contentType argument, to check for a range of MIME types (e.g. application/*+json).craft\web\Request::getAcceptsJson() now returns true for requests with Content-Type headers that match application/*+json, in addition to application/json.storageKey setting._includes/forms/checkbox.twig template now escapes the label variable. A raw HTML label can be passed by wrapping the label value in raw() or craft\helpers\Template::raw()._includes/forms/radio.twig template now escapes the label variable. A raw HTML label can be passed by wrapping the label value in raw() or craft\helpers\Template::raw().Craft.ui.createCheckbox() now escapes the config.label property. A raw HTML label can be passed via the config.labelHtml property.Craft.ui.createSelect() now escapes options’ label properties. Raw HTML labels can be passed via labelHtml properties.craft\fieldlayoutelements\BaseField::$includeInCards.craft\fieldlayoutelements\BaseField::$providesThumbs.craft\fields\BaseRelationField::$showCardsInGrid.craft\fields\Matrix::$showCardsInGrid.craft\helpers\StringHelper::capitalizePersonalName(). toPascalCase() should be used instead.craft\helpers\StringHelper::isWhitespace(). isBlank() should be used instead.craft\helpers\StringHelper::upperCamelize(). toPascalCase() should be used instead.craft\models\FieldLayout::getCardBodyAttributes().craft\models\FieldLayout::getCardBodyFields().craft\services\Structure::EVENT_AFTER_MOVE_ELEMENT. EVENT_AFTER_UPDATE_ELEMENT should be used instead.craft\services\Structure::EVENT_BEFORE_MOVE_ELEMENT. EVENT_BEFORE_UPDATE_ELEMENT should be used instead.craft\web\CsvResponseResponseFormatter::$escapeChar.Craft.BaseElementIndex::selectDefaultSource().Craft.BaseElementIndex::selectSource().Craft.BaseElementIndex::selectSourceByKey().$cardElements argument in craft\helpers\Cp::cardPreviewHtml().$cardElements argument in craft\models\FieldLayout::getCardBodyElements().Content-Type header to application/graphql-response+json.:) in their names. (#18158)users/send-password-reset-email requests. (#17337)search query param if present on the initial request.Nothing published for this version
Nothing published for this version
Fixed low-severity XSS vulnerabilities. (GHSA-6j87-m5qx-9fqp, GHSA-3jh3-prx3-w6wc)
purgeStaleUserSessionDuration config setting was set to a duration interval string. (#18238)Fixed moderate-severity SSRF vulnerabilities. (GHSA-96pq-hxpw-rgh8, GHSA-m5r2-8p9x-hp5m, GHSA-8jr8-7hr4-vhfx)
orderBy. (#18148)utils/fix-field-layout-uids command now checks for duplicate top-level field layout UUIDs. (#18193):empty:/:notempty: element query params properly for options with blank values. (#18156)-) within Link fields’ “Class Name” values were getting removed. (#18201)Fixed RCE vulnerabilities. (GHSA-255j-qw47-wjh5, GHSA-742x-x762-7383)
lazyGqlTypes config setting was enabled. (#18014)@. (#18123):empty:/:notempty: element query params properly if the field had multiple instances within a field layout. (#18092)Plugin licenses are now assigned immediately when installed via the plugin/install command.
plugin/install command. (#17871)folderPath param. (#18056)Icon pickers now return focus to the “Choose” button when the modal is closed without making a selection.
.env if the environment variable didn’t exist yet. (#17942)_includes/field.twig template was included without passing an element variable. (#17926):empty:/:notempty: params properly. (#17763)The fields/auto-merge command now writes updated project config YAML files after each merge.
fields/auto-merge command now writes updated project config YAML files after each merge. (#16198)new is now a reserved filesystem handle.craft\base\ApplicationTrait::ensureEdition().utils/fix-field-layout-uids command. (#17848)EVENT_DEFINE_EXTRA_FIELDS event wasn’t getting triggered for elements. (#17866)craft\services\Assets::EVENT_AFTER_REPLACE_ASSET events weren’t getting triggered when replacing an asset file via GraphQL. (#17005)craft\helpers\Typecast wasn’t typecasting DateTimeInterface property values.lazyGqlTypes config setting was enabled. (#17858)Craft::$app->getEdition() was called early in the request. (#16288)Added craft\base\NestedElementInterface::getOwners().
craft\base\NestedElementInterface::getOwners().craft\base\NestedElementTrait::getOwners().firstName, lastName, and fullName values properly. (#17807)When searching for elements, partial matches within titles are now scored higher than exact matches in other fields.
sort query string parameter, so the selected sort option could revert back if the window was reloaded. (#17761)Improved the performance of element queries.
Relational fields’ search inputs no longer exclusively search for elements by their titles.
folderPath asset query param required a trailing slash. (craftcms/html-field#18)_includes/forms/button.twig template was HTML-encoding the iconHtml value.Added craft\services\UserPermissions::reset().
craft\services\UserPermissions::reset().craft\models\FieldLayout::EVENT_CREATE_FORM event handlers can now control whether the form will be rendered statically, by setting $event->static. (#17699)craft\elements\Asset::getFormattedSizeInBytes() wasn’t returning null when the asset’s size property was null. (#17695)Added support for passing a hashed returnUrl param to standalone Live Preview URLs.
returnUrl param to standalone Live Preview URLs. (#17684)Fixed a potential session leakage vulnerability.
Deprecated craft\helpers\User::getLoginFailureMessage().
craft\helpers\User::getLoginFailureInfo().craft\helpers\User::getLoginFailureMessage().preventUserEnumeration was enabled.Element index and edit pages now include the selected site’s name in the window title, on multi-site installs.
newUser set to true. (#17659)Fixed a bug where Content Block fields could lose their initial values, if they had just been conditionally shown for the first time.
Button Group fields set to only show icons now add title text to the buttons, revealing the icon name.
title text to the buttons, revealing the icon name. (#17598)Entry type groups within Matrix field settings are no longer justified in height.
submitButtonLabel was set on the controller response. (#17567)Fixed a bug where the autoLoginAfterAccountActivation config setting wasn’t being respected when email verification was disabled.
autoLoginAfterAccountActivation config setting wasn’t being respected when email verification was disabled. (#17571)Fixed a potential remote execution vulnerability.
craft\elements\Asset::getMimeType() no longer fetches the MIME type from disk for local assets. (#17549)field or fieldId parameters if an owner parameter wasn’t specified. (#17565)Added craft\helpers\Cp::parseMarkdown().
craft\helpers\Cp::parseMarkdown().craft\helpers\Html::decodeDoubles().cpmd Twig filter for control panel templates.author fields via GraphQL. (#17555)Improved the performance of element indexes when custom sources are defined.
Element selector modals now clear out the search input when opened.
allowAdminChanges was disabled. (#17535)Deprecated craft\web\assets\picturefill\PicturefillAsset.
[!NOTE] Elements with Link fields created before Craft 5.5.0 should be resaved to take advantage of the new “is of type” condition rule operator. (#17277)
[!NOTE] Elements with multi-instance relation fields created before Craft 5.3.0 should be resaved to ensure their condition rules continue to work properly. (#17295)
accessibilityDefaults config setting can now contain notificationPosition and slideoutPosition keys. (#17169)autoLoginAfterAccountActivation config setting no longer applies to the password reset flow. (#17522)<handle>Entry GraphQL queries for each Single section, which resolve to the single entry within them. (#17278)returnUrl query string param. (#17137)craft\base\Describable.craft\base\Element::EVENT_RENDER. (#17188)craft\base\Element::partialTemplatePathCandidates().craft\base\ElementInterface::getGeneratedFieldValues().craft\base\ElementInterface::render().craft\base\ElementInterface::setGeneratedFieldValues().craft\base\ElementTrait::$updateSearchIndexImmediately.craft\base\Field::RESERVED_HANDLES.craft\base\FieldInterface::showStatus().craft\elements\Asset::setMimeType().craft\elements\ContentBlock.craft\elements\db\ContentBlockQuery.craft\events\RenderElementEvent. (#17188)craft\fieldlayoutelements\BaseField::showStatus().craft\fields\BaseRelationField::$showSearchInput.craft\fields\BaseRelationField::canShowSiteMenu().craft\fields\BaseRelationField::hasSelectionCondition().craft\fields\BaseRelationField::showSearchInput().craft\fields\conditions\GeneratedFieldConditionRule.craft\fields\conditions\LinkFieldConditionRule.craft\fields\data\IconData.craft\fields\data\OptionData::$color.craft\fields\data\OptionData::$icon.craft\gql\arguments\elements\ContentBlock.craft\gql\interfaces\elements\ContentBlock.craft\gql\resolvers\elements\ContentBlock.craft\gql\types\IconData.craft\gql\types\elements\ContentBlock.craft\gql\types\generators\ContentBlock.craft\gql\types\generators\IconDataType.craft\gql\types\input\ContentBlock.craft\helpers\Cp::buttonGroupFieldHtml().craft\helpers\Cp::buttonGroupHtml().craft\helpers\Cp::editableTableHtml().craft\helpers\Cp::generatedFieldsTableHtml().craft\helpers\ElementHelper::isMultiSite().craft\helpers\ElementHelper::setProvisionalDraftUser().craft\models\EntryType::$description.craft\models\EntryType::$group.craft\models\FieldLayout::getCardThumbAlignment().craft\models\FieldLayout::getGeneratedFieldByUid().craft\models\FieldLayout::getGeneratedFields().craft\models\FieldLayout::isUiElementIncluded().craft\models\FieldLayout::resetUids().craft\models\FieldLayout::setCardThumbAlignment().craft\models\FieldLayout::setGeneratedFields().craft\records\ContentBlock.craft\services\Gql::defineContentArgumentsForGeneratedFields().craft\web\Request::getValidatedQueryParam().craft\elements\Asset::getMimeType() now returns the file’s actual MIME type (rather than the MIME type associated with the file’s extension), for locally-stored assets. (#17254)craft\fields\data\ColorData now extends craft\base\Model and includes blue, green, hex, luma, red, and rgb attributes in its array keys. (#17265)craft\services\Assets::replaceAssetFile() now has a $mimeType argument.craft\services\Users::saveUserPhoto() now has a $mimeType argument.craft\validators\HandleValidator now supports validateValue().buttonGroup and buttonGroupField macros to the _includes/forms.twig template._includes/forms/buttonGroup.twig template._layouts/cp.twig template now supports passing an actionButton variable. (#17423)Craft.CpScreenSlideout now supports overriding the closeOnEsc, closeOnShadeClick, containerElement, and containerAttributes settings. Slideouts with a non-<form> container element won’t get a “Save” button, and the close button will be labelled “Close” rather than “Cancel”. (#13593)Craft.EntryTypeSelectInput now triggers an applySettings event. (#17387)craft\web\assets\picturefill\PicturefillAsset. (#17344)craft\elements\db\ElementQuery::customFields().craft\elements\Asset::getMimeType(). (#17254)Table fields with “Static Rows” enabled now get populated with the default row values when their value is null.
null. (#17452)craft\fields\linktypes\BaseLinkType::isValueEmpty().craft\services\Auth::getAuthErrorMessage().craft\services\ElementSources::sourceExists().aria-describedby and aria-labelledby values. (#17413)Fixed a bug where addresses’ Latitude and Longitude fields weren’t validating their values.
Fixed a bug where it wasn’t possible to copy nested entries within Matrix fields set to cards or element index views, if the Max Entires setting had b
0 icons. (#17381)It’s now possible to mutate Table field data via GraphQL using custom column handles, rather than just the column IDs.
update-statuses action now ensures it is only being run once at a time.craft\elements\User::getHasSsoIdentity().craft\services\Fields::getLayoutById() now has a $withTrashed argument.--language option was required when running the install command non-interactively.craft up with pending project config YAML files which cause a Single section’s entry type to be soft-deleted.__blank” for custom fields with labels overridden to be hidden. (#17305)up command was updating project config YAML files when admin changes weren’t allowed. (#17345)where is now a reserved field handle.
where is now a reserved field handle. (#17269)Matrix fields set to the inline-editable blocks view mode now duplicate/copy all selected nested entries, rather than just the one the action was acti
assets/generate-transform requests. (#17228)^6.0. (#17229)Return URLs are now sanitized before being saved to the PHP session.
craft\services\Entries::getEntryTypeById() now has a $withTrashed argument.craft\helpers\StringHepler::replaceMb4(). (#17202)_includes/forms/button.twig wasn’t rendering labels set to '0'. (#17225)0 icon selections.entry-types/merge command, if the outgoing entry type was used by a Single section. (#16628)resave/* commands could end prematurely if an unexpected error occurred.Improved the styling of editabe tables, Link fields, and select inputs.
Fixed a PHP deprecation error that could occur when applying the replace Twig filter to a null variable.
forms.checkboxField macro wasn’t respecting fieldset and checkboxLabel keys passed into its config.replace Twig filter to a null variable. (#17159)Fixed a bug where static relational field inputs weren’t showing the related elements’ hierarchy.
disableAutofocus and notificationDuration values per the accessibilityDefaults config setting weren’t being respected for users who hadn’t saved their preferences yet.omitScriptNameInUrls and usePathInfo config settings were both disabled. (#17147)not 1 to a Lightswitch field’s element query param wasn’t yielding expected results. (#17149)Fixed a SQL error that could occur when executing an element query, if the orderBy param contained unexpected syntax.
orderBy param contained unexpected syntax.Added a “Duplicate” action to nested element cards and inline-editable Matrix blocks.
0, preventing the “Author” field from being displayed on Edit Entry screens. (#16898)allowAdminChanges is disabled. (#16508)staticStatuses config setting, for opting into entry statuses being stored statically and only updated on save. (#17024)db/repair command. (#16812)fields/delete command. (#16828)update-statuses command. (#17024)--batch-size option for resave/* commands. (#16586)plugin/install command now accepts an edition argument, and prompts for the default edition if none is specified. (#17030)plugin/uninstall command now reports if no plugin is installed with the provided handle. (#17030)users/create command now prompts to send an activation email, or outputs an activation URL. (#16794)classHandle, content, rawContent, and value are no longer globally-reserved handles.searchKeywords is no longer a globally-reserved handle, except for custom fields.section and type are no longer globally-reserved handles, except for custom fields within entry type field layouts.postDate is no longer a reserved custom field handle, except within entry type field layouts.username is no longer a reserved custom field handle, except within the user field layout.canonicalsOnly element query param.value and strict keys. (#17083)null. (#17084)defaultLabel nested field to Link fields’ GraphQL data. (#16637)download and filename nested fields to Link fields’ GraphQL data. (#16844)element, asset, entry, etc., nested fields to Link fields’ GraphQL data. (#16698)searchTermOptions GraphQL query argument. (#16979)withProvisionalDrafts GraphQL query argument. (#16720)revisionNotes GraphQL entry mutation argument. (#16943)orderBy expressions. (#16729)aria-label attributes via an ariaLabel property.icon columns.craft\base\Element::couldHaveAnimatedThumb().craft\base\ElementInterface::baseBulkDuplicateAttributes().craft\base\ElementInterface::baseGqlType().craft\base\ElementInterface::canCopy().craft\base\ElementInterface::getCardTitle().craft\base\ElementInterface::getSerializedFieldValuesForDb().craft\base\Field::EVENT_DEFINE_ACTION_MENU_ITEMS. (#16779)craft\base\FieldInterface::serializeValueForDb().craft\base\FieldLayoutComponent::conditionalSettingsHtml().craft\base\FieldLayoutComponent::normalizeCondition().craft\base\FieldLayoutElement::alwaysRefresh().craft\base\FieldTrait::$static.craft\base\conditions\BaseMultiSelectConditionRule::$includeEmptyOperators.craft\db\Table::BULKOPEVENTS.craft\db\Table::SEARCHINDEXQUEUE_FIELDS.craft\db\Table::SEARCHINDEXQUEUE.craft\elements\Entry::$oldStatus. (#17024)craft\elements\Entry::$placeInStructure.craft\elements\actions\Copy.craft\elements\actions\MoveDown.craft\elements\actions\MoveUp.craft\events\BulkOpEvent::defer(). (#16655)craft\events\UpdateReleaseEvent.craft\fieldlayoutelements\CustomField::getEditCondition().craft\fieldlayoutelements\CustomField::setEditCondition().craft\fields\BaseOptionsField::$optionColors, which can be set to true by subclasses to enable the “Color” setting for field options. (#16645)craft\fields\BaseOptionsField::$optionIcons, which can be set to true by subclasses to enable the “Icon” setting for field options. (#16645)craft\fields\BaseRelationField::$defaultPlacement.craft\fields\BaseRelationField::DEFAULT_PLACEMENT_BEGINNING.craft\fields\BaseRelationField::DEFAULT_PLACEMENT_END.craft\fields\Matrix::$enableVersioning.craft\fields\data\ColorData::$label. (#16492)craft\fields\data\JsonData.craft\fields\data\LinkData::$download.craft\fields\data\LinkData::getFilename().craft\fields\data\LinkData::setFilename().craft\fields\linktypes\BaseElementLinkType::elementGqlType().craft\fields\linktypes\BaseLinkType::filename().craft\helpers\Cp::reset(). (#16848)craft\helpers\Json::reindent().craft\models\FieldLayout::getEditableCustomFields().craft\models\UpdateRelease::EVENT_IS_CRITICAL.craft\models\UpdateRelease::isCritical().craft\queue\ReleasableQueueInterface. (#16672)craft\records\User::haveIndexAttributesChanged().craft\services\Elements::EVENT_AUTHORIZE_COPY.craft\services\Elements::canCopy().craft\services\Elements::getBulkOpKeys().craft\services\Search::indexElementIfQueued().craft\services\Search::queueIndexElement().craft\web\CpScreenResponseBehavior::$toolbarHtml.craft\web\CpScreenResponseBehavior::toolbarHtml().craft\web\CpScreenResponseBehavior::toolbarTemplate().craft\web\View::registerIcon().craft\web\assets\codemirror\CodeMirrorAsset.craft\base\Element::fieldLayoutFields() now has an editableOnly argument.craft\base\ElementInterface::eagerLoadingMap() and craft\base\EagerLoadingFieldInterface::eagerLoadingMap() can now specify mappings for multiple target element types, or not specify the element types at all. (#16972)craft\cache\ElementQueryTagDependency now merges cache tags provided by the element query with any tags already set on its $tags property.craft\elements\NestedElementManager::getCardsHtml() and getIndexHtml() now accept canPaste config options, which can be set to true, false, or a JavaScript function.craft\helpers\Db::parseBooleanParam() now accepts null and array<string|bool|null> values.craft\services\Elements::duplicateElement() now has a checkAuthorization argument.craft\services\Fields::getLayoutByType() now has a create argument.craft\services\Users::ensureUserByEmail() now prioritizes credentialed users.Craft.animate() and Craft.animateAll(). (#16849)Craft.cp.clearCopiedElements().Craft.cp.getCopiedElements().Craft.cp.onCopyElements().Craft.ui.createIconPicker().Craft.ui.createIconPickerField().Craft.ui.createPasteButton().Craft.ui.icon().Craft.ui.createButton() now supports passing an icon config option._includes/forms/button.twig control panel template now supports passing an icon variable.elements/bulk-duplicate action.elements/duplicate action no longer creates an unpublished draft by default, or deletes the source element if it’s a provisional draft by default. asUnpublishDraft and deleteProvisionalDraft params can be passed to it to re-enable those behaviors where needed.craft\queue\Queue::release() and releaseAll() now call release() and releaseAll() on the proxied queue if it implements craft\queue\ReleasableQueueInterface. (#16672)changedattributes and changedfields tables are now cleaned up during garbage collection. (#16531)resourcepaths table is now truncated when clearing control panel resources, via the Caches utility or the clear-caches/cp-resources command. (#16514)dateAdded values each time the project config is rebuilt, for field layouts that haven’t been explicitly saved since updating to Craft 5.3.0+. (#16899)CRAFT_WEB_URL and CRAFT_WEB_ROOT environment variables could be overridden by @web and @webroot aliases define by the aliases config setting. (#16980)getOwner() and getPrimaryOwner() methods weren’t working properly if they had been queried alongside other elements that didn’t share the same owner type. (#16960)href-less <a> tags.craft\mail\Mailer::send() wasn’t always setting the template mode back to the original. (#17089)Nothing published for this version
Nothing published for this version
- Fixed an RCE vulnerability.
Fixed a bug where craft\services\Assets::EVENT_BEFORE_REPLACE_ASSET events weren’t getting triggered when replacing an asset file via GraphQL.
craft\services\Assets::EVENT_BEFORE_REPLACE_ASSET events weren’t getting triggered when replacing an asset file via GraphQL. (#17005)Fixed a privilege escalation vulnerability.
resourceBasePath setting was set to a nonexistent folder path. (#17021)includeSubfolders asset GraphQL query argument wasn’t working. (#17023)Improved the styling of Markdown UI elements.
Craft::createObject() with its relation field data included in the passed-in config. (#16942)folderPath asset query param only accepted strings. (#16981)craft\elements\Asset::getSrcset() could return malformed results if any sizes didn’t have corresponding image URLs. (#16984)Fixed a performance degradation bug that occurred when working with Categories or Entries fields with “Maintain hierarchy” enabled.
Improved table styling. (#16771, #16829)
revisionNotes GraphQL fields were returning the entry’s current revision’s notes. (#16909)craft\base\NestedElementTrait::setPrimaryOwnerId() and setOwnerId() weren’t clearing out the memoized owner element.redirect params passed by login forms. (#16905)Added craft\base\conditions\BaseTextConditionRule::isEmpty().
craft\base\conditions\BaseTextConditionRule::isEmpty().craft\htmlpurifier\RelAttrLinkTypeDef.rel attributes to be set to any value. (#16798)_includes/forms/button.twig was always adding class="btngroup-btn-first" to the resulting button HTML.{slug} in the subpath could create folders named after temporary slugs. (#16799)Added craft\base\ElementTrait::$isNewSite.
craft\base\ElementTrait::$isNewSite.craft\queue\jobs\PropagateElements::$isNewSite.string().ancestors and parent eager-loading wasn’t working on some environments. (#16381, #16382, #16341)Fixed a bug where scrollable panes weren’t automatically scrolling when dragging objects near their edges.
Added craft\base\Element::ancestors().
craft\base\Element::ancestors().craft\base\Element::descendants().Fixed a bug where multiple “New file uploaded.” notifications could be shown at once.
preserveAspectRatio attributes. (#16709)<style> tags. (nystudio107/craft-retour#329)Fixed a bug where multi-site elements’ search indexes could be updated twice.
level. (#16661)up command, the app/migrate action, and the Project Config utility weren’t aware of pending project config changes if a database backup was restored but caches weren’t cleared. (#16668)users/remove-2fa command.Fixed a bug where transformed images could be slightly smaller than they should be when using the fit transform mode.
fit transform mode. (#16622)<sectionHandle>Entries) weren’t available if a Matrix or CKEditor field existed with the same handle as the section.migrate/up and migrate/all commands were writing out changes to the project config YAML when there were already pending YAML changes. (#16086)token query string param. (#16630)Fixed an error that occurred when accessing the edit/ route for a draft that no longer existed.
edit/<elementId> route for a draft that no longer existed.utils/prune-orphaned-entries command. (#16598)Fixed a bug where craft\db\QueryBatcher::getSlice() wasn’t using the database connection passed to the class constructor.
craft\db\QueryBatcher::getSlice() wasn’t using the database connection passed to the class constructor. (#16579)The Login page now displays the Login Page Logo above the login form, rather than within the header.
allowAdminChanges is disabled, indicating that settings are read-only. (#16563)craft\web\User::getDefaultReturnUrl().cp.login.alternative-login-methods hook to the system login template.allowAdminChanges was false. (#16509)craft\services\Sso::findUser() wasn't accounting for soft-deleted users. (#16491)Fixed a bug where all multi-byte characters were getting stripped out of search indexes.
craft\elements\Asset::getSrcset() (and srcset method arguments) weren’t producing the correct transform URLs if the asset already had a named transform applied to it. (#16486)utils/delete-empty-volume-folders command was deleting folders that had no assets directly, but had subfolders. (#16388)Your coding agent can read these notes before it upgrades. Set up the MCP server →