a:2:{i:0;a:2:{s:3:"cms";a:4:{s:6:"status";s:8:"eligible";s:8:"releases";a:1:{i:0;a:4:{s:7:"version";s:6:"5.11.4";s:8:"critical";b:0;s:5:"notes";s:3265:"<ul>
<li>Added <code>craft\services\Users::destroyOtherSessions()</code>.</li>
<li>Setting up a two-step verification method now destroys the user’s other sessions.</li>
<li>Deleting a passkey now requires an elevated session.</li>
<li>Fixed a bug where an uninformative error message could be shown when saving a draft that no longer passed validation. (<a href="https://github.com/craftcms/cms/issues/19674">#19674</a>)</li>
<li>Fixed a bug where the Assets index page could display the wrong assets and subfolders after reloading the browser tab. (<a href="https://github.com/craftcms/cms/issues/19689">#19689</a>)</li>
<li>Fixed a bug where Matrix fields set to the “Cards”, “Card grid”, or “Index” view modes weren’t respecting <code>craft\fields\Matrix::EVENT_DEFINE_ENTRY_TYPES</code>. (<a href="https://github.com/craftcms/cms/pull/19685">#19685</a>)</li>
<li>Fixed a bug where the <code>attribute()</code> Twig function was allowed within sandboxed Twig environments, even if it wasn’t listed in <code>allowedFunctions</code>.</li>
<li>Fixed a bug where Twig array access with a <code>false</code> key could return the wrong value when Dev Mode was disabled.</li>
<li>Fixed an error that could occur when adding a new site to a draft, if it contained multiple levels of nested content. (<a href="https://github.com/craftcms/cms/issues/18281">#18281</a>)</li>
<li>Fixed a bug where dragged items weren’t getting dropped where expected, if their container had scrolled during the drag operation. (<a href="https://github.com/craftcms/cms/issues/19721">#19721</a>)</li>
<li>Fixed a bug where publicly-registered users weren’t getting activated and logged in immediately, if email verification wasn’t required but the password was deferred. (<a href="https://github.com/craftcms/cms/issues/19610">#19610</a>)</li>
<li>Fixed a bug where changing an entry’s type could cause values for fields shared by both entry types to be lost. (<a href="https://github.com/craftcms/cms/issues/19737">#19737</a>)</li>
<li>Fixed an error that could occur when running the <code>setup/php-session-table</code> and <code>setup/db-cache-table</code> commands. (<a href="https://github.com/craftcms/cms/pull/19742">#19742</a>)</li>
<li>Fixed an infinite loop that could occur when editing nested Matrix entries in Blocks view. (<a href="https://github.com/craftcms/cms/issues/19756">#19756</a>)</li>
<li>Fixed a bug where filtering elements by textual params or conditions could only work if the param/condition value was all-lowercase. (<a href="https://github.com/craftcms/cms/issues/19781">#19781</a>)</li>
<li>Fixed a <a href="https://github.com/craftcms/cms/security/policy#severity--remediation">high-severity</a> RCE vulnerability. (GHSA-hq78-cm2m-h24h)</li>
<li>Fixed a <a href="https://github.com/craftcms/cms/security/policy#severity--remediation">low-severity</a> RCE vulnerability. (GHSA-6m9q-c5q4-3732)</li>
<li>Fixed a <a href="https://github.com/craftcms/cms/security/policy#severity--remediation">low-severity</a> authorization bypass vulnerability. (GHSA-j2r3-x468-c6j5)</li>
<li>Fixed a <a href="https://github.com/craftcms/cms/security/policy#severity--remediation">low-severity</a> XSS vulnerability. (GHSA-q2rx-mr36-8rh5)</li>
</ul>
";s:4:"date";s:19:"2026-10-01T00:00:00";}}s:13:"phpConstraint";s:4:"^8.2";s:11:"packageName";s:12:"craftcms/cms";}s:7:"plugins";a:9:{s:9:"admin-bar";a:3:{s:6:"status";s:8:"eligible";s:8:"releases";a:0:{}s:11:"packageName";s:23:"wbrowar/craft-admin-bar";}s:8:"announce";a:3:{s:6:"status";s:8:"eligible";s:8:"releases";a:0:{}s:11:"packageName";s:27:"honchoagency/craft-announce";}s:8:"calendar";a:3:{s:6:"status";s:8:"eligible";s:8:"releases";a:0:{}s:11:"packageName";s:23:"solspace/craft-calendar";}s:8:"ckeditor";a:4:{s:6:"status";s:8:"eligible";s:8:"releases";a:1:{i:0;a:4:{s:7:"version";s:5:"5.8.0";s:8:"critical";b:0;s:5:"notes";s:2088:"<ul>
<li>CKEditor packages registered by plugins that load after CKEditor, including from <code>Craft::$app-&gt;onInit()</code> callbacks, are now registered properly. (<a href="https://github.com/craftcms/ckeditor/issues/621">#621</a>)</li>
<li>CKEditor fields now only import third-party CKEditor packages, and register their asset bundles, when one of the package’s toolbar items is in the field’s toolbar. Packages without toolbar items are still loaded for every field.</li>
<li>Third-party CKEditor plugins are now referenced via namespace imports, so plugins with the same name from different packages no longer conflict. Custom config JS can still refer to them by name (e.g. <code>extraPlugins: [Tokens]</code>), as long as the name is unique.</li>
<li>Added <code>craft\ckeditor\Plugin::registerCkeditorPackageBundles()</code>.</li>
<li>Deprecated <code>craft\ckeditor\helpers\CkeditorConfig::getImportStatements()</code>.</li>
<li>Package asset bundles are no longer registered automatically whenever <code>CkeditorAsset</code> is registered.</li>
<li>Fixed a bug where package toolbar items were registered again each time a CKEditor field was rendered.</li>
<li>Fixed a bug where grouped toolbar items from third-party packages weren’t matched against the field’s toolbar.</li>
<li>Fixed a bug where all of a package’s toolbar items were shown as a single group in the toolbar builder, instead of as separately-placeable items and groups.</li>
<li>Fixed a bug where the “Displayed text” value was ignored when inserting a new element link, and the element’s title was used instead. (<a href="https://github.com/craftcms/ckeditor/pull/617">#617</a>)</li>
<li>Fixed a bug where links’ types would change to “URL” if a URL suffix was entered before an element was chosen. (<a href="https://github.com/craftcms/ckeditor/issues/619">#619</a>, <a href="https://github.com/craftcms/ckeditor/pull/624">#624</a>)</li>
<li>Fixed an error that could occur when uninstalling CKEditor. (<a href="https://github.com/craftcms/ckeditor/issues/623">#623</a>)</li>
</ul>
";s:4:"date";s:19:"2026-09-28T00:00:00";}}s:13:"phpConstraint";s:4:"^8.2";s:11:"packageName";s:17:"craftcms/ckeditor";}s:6:"formie";a:4:{s:6:"status";s:8:"eligible";s:8:"releases";a:3:{i:0;a:4:{s:7:"version";s:6:"3.1.44";s:8:"critical";b:0;s:5:"notes";s:1979:"<h3>Added</h3>
<ul>
<li>Add Salesforce Client Credentials authentication with configurable My Domain support. (<a href="https://github.com/verbb/formie/issues/2961">#2961</a>)</li>
<li>Add the <code>allowLegacySignatureImageUrls</code> config setting to disable unsigned Signature image URLs for existing submissions.</li>
</ul>
<h3>Changed</h3>
<ul>
<li>Protect Signature image URLs for new submissions with field-scoped access tokens while preserving URLs in previously sent email notifications.</li>
</ul>
<h3>Fixed</h3>
<ul>
<li>Fixed a moderate-severity authorization vulnerability. (GHSA-q6g7-g2wg-h43h)</li>
<li>Fix field variables in notification email address settings resolving to rendered HTML when custom email templates are used. (<a href="https://github.com/verbb/formie/issues/2974">#2974</a>)</li>
<li>Fix OAuth integrations failing to connect after authorisation. (<a href="https://github.com/verbb/formie/issues/2973">#2973</a>)</li>
<li>Fixed OAuth callback transaction validation.</li>
<li>Fixed authorization for connecting and disconnecting OAuth integrations.</li>
<li>Fixed a moderate-severity information disclosure vulnerability. (GHSA-rh4q-6j5r-8jqf)</li>
<li>Fixed a moderate-severity authorization vulnerability. (GHSA-p696-447f-9258)</li>
<li>Fixed a moderate-severity authorization vulnerability. (GHSA-qg3f-hm4x-h5h8)</li>
<li>Fixed a moderate-severity information disclosure vulnerability. (GHSA-963f-vfpf-f85p)</li>
<li>Fix slow GraphQL schema creation and form rendering when integrations have large cached settings. (<a href="https://github.com/verbb/formie/issues/2972">#2972</a>)</li>
<li>Fix email notifications failing when their content references an empty optional field.</li>
<li>Fix email notifications failing when their content references a deleted field.</li>
<li>Fix PHP 8.4 deprecation warnings caused by implicitly nullable parameters and CSV parsing. (<a href="https://github.com/verbb/formie/issues/2970">#2970</a>)</li>
</ul>
";s:4:"date";s:19:"2026-09-30T00:00:00";}i:1;a:4:{s:7:"version";s:6:"3.1.43";s:8:"critical";b:0;s:5:"notes";s:660:"<h3>Fixed</h3>
<ul>
<li>Fixed a high-severity server-side request forgery vulnerability. (<a href="https://github.com/verbb/formie/security/advisories/GHSA-82jr-3xc8-86mr">GHSA-82jr-3xc8-86mr</a>)</li>
<li>Fix creating forms from legacy stencils containing temporary page, row, or field IDs.</li>
<li>Fix editing stencils when the Solspace Calendar event integration is installed.</li>
<li>Fix form redirect responses failing after the submission was saved. (<a href="https://github.com/verbb/formie/issues/2969">#2969</a>)</li>
<li>Fix form content fields being inaccessible in email notification variables after the Twig sandbox security changes.</li>
</ul>
";s:4:"date";s:19:"2026-09-24T00:00:00";}i:2;a:4:{s:7:"version";s:6:"3.1.42";s:8:"critical";b:0;s:5:"notes";s:1202:"<h3>Changed</h3>
<ul>
<li>Resolve redirect URL placeholders as strict submission, field and form tokens instead of executing Twig, while rendering remaining form-authored Twig and object templates in Base's explicit sandbox.</li>
<li>Require <code>verbb/base</code> 3.0.17 or later for the explicit sandbox renderers and collection safeguards.</li>
<li>Apply <code>EVENT_MODIFY_TWIG_ENVIRONMENT</code> permissions as additions to Twig sandbox defaults; broad <code>allowedClasses</code> permissions no longer apply to those renders.</li>
</ul>
<h3>Fixed</h3>
<ul>
<li>Fixed a high-severity server-side template injection vulnerability. (<a href="https://github.com/verbb/formie/security/advisories/GHSA-25q7-h5pg-6wjv">GHSA-25q7-h5pg-6wjv</a>)</li>
<li>Fixed a high-severity server-side template injection vulnerability. (<a href="https://github.com/verbb/formie/security/advisories/GHSA-3m2m-h2c6-gjwh">GHSA-3m2m-h2c6-gjwh</a>)</li>
<li>Fixed a high-severity server-side template injection vulnerability. (<a href="https://github.com/verbb/formie/security/advisories/GHSA-f55h-mf7f-7wx7">GHSA-f55h-mf7f-7wx7</a>)</li>
<li>Fixed a high-severity server-side template injection vulnerability.</li>
</ul>
";s:4:"date";s:19:"2026-09-23T00:00:00";}}s:13:"phpConstraint";s:4:"^8.2";s:11:"packageName";s:12:"verbb/formie";}s:22:"graphql-authentication";a:3:{s:6:"status";s:8:"eligible";s:8:"releases";a:0:{}s:11:"packageName";s:37:"jamesedmonston/graphql-authentication";}s:10:"lettermint";a:3:{s:6:"status";s:8:"eligible";s:8:"releases";a:0:{}s:11:"packageName";s:32:"somehow-digital/craft-lettermint";}s:12:"phone-number";a:3:{s:6:"status";s:8:"eligible";s:8:"releases";a:0:{}s:11:"packageName";s:25:"rynpsc/craft-phone-number";}s:15:"craft-recaptcha";a:3:{s:6:"status";s:8:"eligible";s:8:"releases";a:0:{}s:11:"packageName";s:20:"c10d/craft-recaptcha";}}}i:1;N;}