[ข่าว] XenForo 1.5.11 Released
Today, we are pleased to release XenForo 1.5.11. This release fixes a number of bugs and issues that were found since the release of 1.5.10. As this is a maintenance release, the vast majority of the focus was an increase in stability.

Notably, we have adjusted the exact procedure used for generating secure random data to adhere to current best practices. If your system does not have access to a modern and fully secure approach to generating random data, we will now warn you during installation/upgrades and display a message indicating this in the control panel. If possible, we recommend using PHP 7 to take advantage of the new features for generating random numbers. Thanks to @rugk for bringing this to our attention.

Some of the changes in 1.5.11 include:
  • Workaround a Firefox bug where the Flash uploader shows as an opaque white box.
  • Support redirects in the image proxy and link title conversion process (while maintaining security).
  • Improve autolinking when there...
XenForo Media Gallery 1.1.10 is a maintenance release for our media gallery add-on. We recommend all customers running XenForo Media Gallery to upgrade to 1.1.10 to benefit from increased stability.

This release fixes several bugs that were reported following the release of XenForo Media Gallery 1.1.9:
  • Ensure video quota permissions are displayed on the Gallery Permissions page
  • Some PhotoPost importer improvements
  • Performance improvements to reduce query time in large galleries
For the full list of bug fixes, see the Resolved Media Gallery Bugs forum.

The following template has been changed:
  • xengallery_album_thumb_item.css
  • xengallery_font_awesome
  • xengallery_media_add.css
  • xengallery_media_thumb_item.css
XenForo Media Gallery requires XenForo 1.5.0 or later.

Customers with active XenForo Media Gallery licenses may now download the new...
XenForo Enhanced Search 1.1.6 is a maintenance release for our search add-on. This release is designed to improve compatibility with the recent Elasticsearch 5 release. If you plan to use Elasticsearch 5, you must use this (or a subsequent) version of XenForo Enhanced Search.

XenForo Enhanced Search requires Elasticsearch and XenForo 1.3.0 or later.

Customers with active XenForo Enhanced Search licenses may now download the new version from the customer area.

Download XenForo Enhanced Search 1.1.6
From the Licensed Customer Area

Purchasing

The XenForo Enhanced Search can be purchased with a new license via the purchase page or with an existing license via the customer area.

Installation, Upgrading and Configuration

Please see our...
Today, we are pleased to release XenForo 1.5.10. This release fixes several bugs and issues that were found since the release of 1.5.9.

Most importantly, this release includes a fix for a security issue that we found during internal testing. The issue is known as a server-side request forgery (SSRF). This could allow an attacker to use your server to bypass your server's firewall and make internal requests. Depending on the services found, this could lead to privilege escalation or remote code execution.

This is a potentially serious issue and we strongly recommend all customers follow one of the below methods to fix this security issue.


If you are running XenForo 1.4, please see the 1.4.13 announcement for a patch. If you are running XenForo 1.3 or older, you must upgrade to the latest 1.4 or 1.5 release to fix this issue.

If you are running XenForo Media Gallery 1.0, you...
XenForo Media Gallery 1.1.9 is a maintenance release for our media gallery add-on. We recommend all customers running XenForo Media Gallery to upgrade to 1.1.9 to benefit from increased stability.

While XenForo Media Gallery is potentially affected by the server side request forgery (SSRF) issue patched by XenForo 1.5.10, following the steps in the XenForo 1.5.10 announcement is sufficient to fix the issue in XenForo Media Gallery 1.1.5 or newer. If you are running XenForo Media Gallery 1.1.0 to 1.1.4, you must upgrade to 1.1.5 or newer and apply the XenForo 1.5.10 patch to fix the SSRF issue.

This release fixes several bugs that were reported following the release of XenForo Media Gallery 1.1.8:
  • Implements better permission checks in the Media alert handler
  • Resolves an issue which could see a thumbnail not created for short videos
  • Photopost importer fixes...
During internal testing, we discovered a security issue within XenForo. The issue is known as a server-side request forgery (SSRF). This could allow an attacker to use your server to bypass your server's firewall and make internal requests. Depending on the services found, this could lead to privilege escalation or remote code execution.

This is a potentially serious issue and we strongly recommend all customers running XenForo 1.4 or older follow one of the below methods to fix this security issue.


If you are running XenForo 1.3 or older, you must upgrade to the latest 1.4 or 1.5 release to fix this issue.

If you have any questions relating to installing this patch or upgrading to the new version, please post in the Upgrade Support forum.

Method 1: Upgrade to the New Version (Recommended)

You may upgrade to XenForo 1.4.13 (or the latest version of 1.5) to fix this issue. You...
In order to apply the security fix included in XenForo 1.4.13 or 1.5.10 to XenForo Media Gallery 1.0, XenForo Media Gallery 1.0.10 has been released.

This fixes the server-side request forgery (SSRF) security issue. This could allow an attacker to use your server to bypass your server's firewall and make internal requests. Depending on the services found, this could lead to privilege escalation or remote code execution.

This is a potentially serious issue and we strongly recommend all customers running XenForo Media Gallery 1.0 follow one of the below methods to fix this security issue. You must also follow the instructions in the XenForo 1.4.13 or 1.5.10 release announcements for this patch to be effective.

Please note that XenForo Media Gallery 1.1.5 and newer will automatically be secured from this issue if you follow the instructions in the XenForo 1.5.10 release...
[ข่าว] XenForo 1.5.9 Released
Today, we are pleased to release XenForo 1.5.9. This release fixes a number of bugs and issues that were found since the release of 1.5.8. As this is a maintenance release, the vast majority of the focus was an increase in stability.

Some of the bugs fixed in 1.5.9 include:
  • Improved compatibility with upcoming PHP 7.1 release.
  • Add basic email typo detection for specific cases to reduce false positives with StopForumSpam checks.
  • Indicate when a StopForumSpam result is from a general blacklisting rather than specific reports.
  • Disable the rich text editor in Windows 10 Mobile Edge versions less than 14 due to problems using it.
  • Fix a case where changing the price of a recurring user upgrade could cause some existing payments to not be processed correctly.
  • Fix a situation where a user mention in a profile post was not displayed correctly.
  • Fix user mention matching being case sensitive for accented characters.
  • Fix a bug that caused transparent images to...
XenForo Media Gallery 1.1.8 is a maintenance release for our media gallery add-on. We recommend all customers running XenForo Media Gallery to upgrade to 1.1.8 to benefit from increased stability.

This release fixes several bugs that were reported following the release of XenForo Media Gallery 1.1.7:
  • Improved compatibility with upcoming PHP 7.1 release.
  • Improved the performance of marking large numbers of media as viewed.
  • Workaround a situation where MySQL's wait_timeout could prevent video transcoding from completing if set to a lower value.
  • For PhotoPostVb and PhotoPostXf importers, import Member Categories as albums.
  • For all other PhotoPost related importers, do not skip items belonging to users who no longer exist.
  • Thank you to @Kirby for suggesting a number of fixes for the vBGallery importer.
  • Only rebuild thumbnails if we have the ability to resize them.
  • Hide some of the automatic watch settings if there is no permission to view categories or...
XenForo Enhanced Search 1.1.5 is a maintenance release for our search add-on. We recommend all customers running XenForo Enhanced Search upgrade to 1.1.5 to benefit from increased stability.

This changes in this release include::
  • Improve compatibility with the upcoming Elasticsearch 5 release.
  • Do not treat a "-" with spaces around it as a negation operator in searches.
  • Fix a situation where errors when indexing would be erroneously detected, causing a "no response" error to be logged.
XenForo Enhanced Search requires Elasticsearch and XenForo 1.3.0 or later.

Customers with active XenForo Enhanced Search licenses may now download the new version from the customer area.

Download XenForo Enhanced Search 1.1.5
From the Licensed Customer Area

Purchasing

The XenForo Enhanced Search can be purchased with a new license via the...
  • Sponser

  • Like us on Facebook

  • Buy us a beer!

    The management works very hard to make sure the community is running the best software, best designs, and all the other bells and whistles. Care to buy us a beer? We'd really appreciate it!

    Donate to us!