You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
* Path traversal in LESS parser via theme color settings, incomplete fix for CVE-2023-27577 (https://github.com/flarum/framework/security/advisories/GHSA-xjvc-pw2r-6878)
6
+
* Account takeover via expired password reset token (https://github.com/flarum/framework/security/advisories/GHSA-649p-3mfg-mx5r)
7
+
* Invalidate active sessions when password is changed (https://github.com/flarum/framework/pull/4546)
8
+
* Delete stale password tokens when requesting a new reset (https://github.com/flarum/framework/pull/4547)
9
+
### Added
10
+
* Sync abandoned extensions list from `flarum/abandoned-extensions` (https://github.com/flarum/framework/pull/4559)
0 commit comments