News aus der Forenwelt

Today, we are releasing XenForo 2.2.11 to address a potential security vulnerability. We recommend that all customers running XenForo 2.2 upgrade to 2.2.11 or use the attached patch file as soon as possible. The issue relates to HTML attribute injection which can be triggered when rendering editor content, such as when a post is edited or quoted. XenForo extends thanks to security researcher @PaulB, the team at @NamePros and @Xon for reporting the issues. We recommend... Read more Written by XenForo - (Weiterlesen)
Today, we are releasing XenForo 2.1.13 to address a potential security vulnerability. We recommend that all customers still running XenForo 2.1 upgrade to 2.1.13 or use the attached patch file as soon as possible. The issue relates to HTML attribute injection which can be triggered when rendering editor content, such as when a post is edited or quoted. XenForo extends thanks to security researcher @PaulB, the team at @NamePros and @Xon for reporting the issues. We... Read more Written by XenForo - (Weiterlesen)
Here we go! We're four HYS threads in already and you might be wondering just how many there are left. Well, I can't tell you 😉 But what I can tell you is - we're not even half way through yet! In case you've not yet seen the previous entries, you can check them out here. As ever, to ensure you're kept up to date, we strongly recommend caressing that "Watch forum" link and make sure you enable email notifications if you haven't done so already 🙂 Written by Chris D - (Weiterlesen)
XenForo 2.2.10 Released XenForo 2.2.10 is now available for all licensed customers to download. We strongly recommend that all customers running previous versions of XenForo 2.2 upgrade to this release to benefit from increased stability. This version contains a fix for an issue whereby outgoing requests from the server running XenForo could be tricked into accessing web-accessible resources on the local network. The scope to exploit this issue is limited within the core and... Read more Written by XenForo - (Weiterlesen)
Ahh, it seems like only yesterday (as I write this, it was!) we were talking about the fifth in our HYS series for XF 2.1, and already we're onto the sixth, so welcome! In case you've not yet seen the previous entries, (why not?!) you can check them out here. As ever, to ensure you're kept up to date, we strongly recommend giving that "Watch forum" link a tickle and make sure you enable email notifications if you haven't done so already 🙂 Written by Chris D - (Weiterlesen)
Over the next few weeks, we'll be adding to the Building with XenForo 2 video series, starting today with a look at how to make your custom add-on content taggable! Written by XenForo - (Weiterlesen)
XenForo 2.2.9 Released XenForo 2.2.9 is now available for all licensed customers to download. We strongly recommend that all customers running previous versions of XenForo 2.2 upgrade to this release to benefit from increased stability. In addition to the usual bug fixes and improvements, we've continued to improve compatibility with PHP 8.1 and added support for self-hosted licenses to more easily sign outgoing emails with DKIM as per this recent suggestion by... Read more Written by XenForo - (Weiterlesen)
It has come to our attention today that a vulnerability has been discovered in popular Java logging library Log4j 2 which may allow attackers to arbitrarily execute code (remote code execution). Apache Log4j 2 is bundled with and used in many Java applications including Elasticsearch. XenForo itself is not directly exploitable, and we are currently investigating whether XenForo Enhanced Search can be used as a vector at all, but this is potentially significant enough that an abundance of... Read more Written by XenForo - (Weiterlesen)
XenForo 2.2.8 Released XenForo 2.2.8 is now available for all licensed customers to download. We strongly recommend that all customers running previous versions of XenForo 2.2 upgrade to this release to benefit from increased stability. XenForo 2.2.8 brings initial PHP 8.1 support to XenForo. We do not currently recommend upgrading to PHP 8.1 in production but would encourage, where possible, running XF 2.2.8 and PHP 8.1 together on your staging sites/servers if possible... Read more Written by XenForo - (Weiterlesen)
When we announced XenForo Cloud a little while back, we were encouraged by the great feedback we received. Having taken onboard all your comments, we have been hard at work refining our offering to make it an even more compelling proposition, and today we are ready to talk about some of the changes we've implemented. Faster Not content with already offering the industry's most capable and responsive infrastructure, we are now using even most powerful underlying hardware with faster... Read more Written by XenForo - (Weiterlesen)
Today marks the day when the alpha stage of XenForo 2.2 comes to an end and we mark that occasion by unleashing the first public beta. Look out for an announcement on that shortly. Before that, however, we wanted to highlight a few more things that we've been working on over the last couple of weeks. Some of these you will be aware of as they have been running here for some time and we may have mentioned them elsewhere. Others are slightly more subtle... Image and video... Read more Written by XenForo - (Weiterlesen)
Having upgraded XenForo.com yesterday, we've fielded lots of feedback and implemented a fair few changes. Here's a handful of things we've done in response to your feedback. Editor styling We've removed the gradient entirely from the unfocused editor, and changed the styling when the editor is focused so that the background now gets lighter on focus, in order to give an editing background that is more like the final destination background. XenForo 2.2 RTE... Read more Written by XenForo - (Weiterlesen)
XenForo 2.2.7 Released XenForo 2.2.7 is now available for all licensed customers to download. We strongly recommend that all customers running previous versions of XenForo 2.2 upgrade to this release to benefit from increased stability. Notably, XenForo 2.2.7 includes a fix for a potentially significant issue surrounding IP address spoofing in very specific circumstances using previously trusted IP address ranges. Thanks to NamePros for taking the time to report this issue... Read more Written by XenForo - (Weiterlesen)
Participation. It's the life blood of a forum, and once you have a group of dedicated members creating and discussing content, your forum will flourish. But there's a barrier to entry when it comes to participation. When a new visitor stumbles upon your forum from a search engine, they may read the content that piqued their interest and then feel inclined to add their own thought-provoking response, but at that point they are confronted with the dreaded ... at... Read more Written by XenForo - (Weiterlesen)
Here at XenForo, we like to keep our development environments up-to-date and as useful as possible, and from time to time we include some of our findings in our online documentation. Recently, we've published an easy setup guide for a Windows-based development environment and now we've added both a guide for building a very flexible macOS-based system and instructions for setting-up a similar multi-PHP... Read more Written by XenForo - (Weiterlesen)
A long time ago, in a forum not particularly far, far away (may the fourth be with you), we produced a series of videos showing off how easy it was to build rich pages with XenForo's templates and javascript framework. While many of the principles demonstrated in these videos remain a key part of XenForo 2, most of the syntax employed by XenForo 1 back then has changed, and there are many more tools at your disposal, like entities and command-line functions. Building with... Read more Written by XenForo - (Weiterlesen)
With the publication of our Building with XenForo 2 video series, we've received various questions about a presenting broad overview of the XenForo architecture as a jumping-off point for would-be developers who want to know roughly what's going on behind the scenes. Therefore, with dubious penmanship, we've put together a ten minute overview of how XenForo works. Presenting ideas like the Router, Controller Actions and Replies before handing off... Read more Written by XenForo - (Weiterlesen)
Welcome to the first of our "Have you seen...?" (HYS) series for XenForo 2.2! To ensure you're kept up to date with future threads, we strongly recommend clicking the "Watch forum" link here and enabling email notifications if you haven't done so already 🙂 Over the course of the next few weeks we would like to not only introduce you to the new features we've been working hard on for the next version of XenForo, but also introduce you to some new members of the XenForo... Read more Written by XenForo - (Weiterlesen)
Welcome to the first of our "Have you seen...?" series for XenForo 2.1. We've got a lot to show you over the course of the next few weeks so you may well be hearing from us quite frequently... To ensure you're kept up to date, we strongly recommend clicking the "Watch forum" link here and enabling email notifications if you haven't done so already 🙂 But first... The first thing that we should announce before we get started is something which we have talked about over the... Read more Written by Chris D - (Weiterlesen)
Welcome to the third in our "Have you seen...?" series for XF 2.1. We've had a phenomenal, er, reaction, to what we've shown so far. In case you haven't seen our previous two entries, you can check them out here. As ever, to ensure you're kept up to date, we strongly recommend giving that "Watch forum" link a poke here and enabling email notifications if you haven't done so already 🙂 Today we're going to show you something that we have been talking about doing internally for... Read more Written by Chris D - (Weiterlesen)
Oben