<link href="/assets/9600c281ef06d8d7784a4ad6595c8740.css" type="text/css" rel="stylesheet">

[New release] wallabag 2.5.4

MONTHS_OF_THE_YEAR[1] 09, 2023

<p>⚠️ This is a <strong>security</strong> release of wallabag.</p> <p>To update your instance, <a href="https://doc.wallabag.org/en/admin/upgrade.html#upgrading-from-23x-to-23y">just run <code>make update</code>.</a></p> <p><em>🤝 A little reminder that you can support our work on wallabag by sponsoring us on <a href="https://liberapay.com/wallabag">Liberapay</a> or subscribe on <a href="https://www.wallabag.it/en">wallabag.it</a>. Thanks!</em></p> <p>We added a limitation on adding tags from the entry page : only 4 tags at a time and a max length of 40 characters.</p> <h2>What's Changed</h2> <ul> <li>Fix release script by @j0k3r in <a href="https://github.com/wallabag/wallabag/pull/6275">https://github.com/wallabag/wallabag/pull/6275</a></li> <li>Fix (CVE-2023-0734) adding tag to entries from other people by @j0k3r in <a href="https://github.com/wallabag/wallabag/pull/6290">https://github.com/wallabag/wallabag/pull/6290</a></li> <li>Fix (CVE-2023-0736) XSS on username on share page by @j0k3r in <a href="https://github.com/wallabag/wallabag/pull/6288">https://github.com/wallabag/wallabag/pull/6288</a></li> <li>Fix (CVE-2023-0735 &amp; CVE-2023-0737) CSRF on user deletion by @j0k3r in <a href="https://github.com/wallabag/wallabag/pull/6289">https://github.com/wallabag/wallabag/pull/6289</a></li> <li>Prepare 2.5.4 by @j0k3r in <a href="https://github.com/wallabag/wallabag/pull/6291">https://github.com/wallabag/wallabag/pull/6291</a></li> </ul> <p><strong>Full Changelog</strong>: <a href="https://github.com/wallabag/wallabag/compare/2.5.3...2.5.4">https://github.com/wallabag/wallabag/compare/2.5.3...2.5.4</a></p> <h2>Download wallabag 2.5.4</h2> <p>To download, install/upgrade wallabag, <a href="https://doc.wallabag.org/en/admin/installation/installation.html">please read our Downloads page</a>.</p> <hr /> <h2>Need help?</h2> <p><a href="https://gitter.im/wallabag/wallabag">We are on Gitter</a> and <a href="irc://irc.freenode.net/wallabag">on IRC</a>, ping us! You can also open a <a href="https://github.com/wallabag/wallabag/issues/new">new issue on GitHub</a>.</p> <hr /> <h2>How can you help us?</h2> <p>By using wallabag, by reporting bugs, by translating wallabag and its documentation, by talking about wallabag to your friends, ... You can help us via <a href="https://liberapay.com/wallabag/">Liberapay</a> or <a href="https://www.paypal.com/cgi-bin/webscr?cmd=_s-xclick&amp;hosted_button_id=9UBA65LG3FX9Y&amp;lc=gb">PayPal</a>.</p>
With wallabag, archive the web freely. wallabag is a self hostable application for saving web pages.
<script src="/system/assets/jquery/jquery-2.x.min.js"></script> <script src="/user/themes/boxify/js/main.js"></script> <script src="https://sidecar.gitter.im/dist/sidecar.v1.js" defer></script> <script src="/user/plugins/highlight/js/highlight.pack.js"></script> <script src="/user/themes/boxify/js/jquery.jscroll.min.js"></script> <script defer> ((window.gitter = {}).chat = {}).options = { room: 'wallabag/wallabag' }; </script> <script> hljs.initHighlightingOnLoad(); </script>