XOOPS

XOOPS 2.7.4-RC2 Released

Mamba  06 Oct 2026 3:00 PM 83 Reads   No comments 
274-RC2
XOOPS 2.7.4 RC 2 — security hardening ahead of the final release

The XOOPS Development Team is pleased to announce XOOPS 2.7.4 RC 2, the second release candidate for XOOPS 2.7.4. RC 2 adds no new features. It collects the security hardening and bug fixes made since RC 1, after a review of the core with CodeQL, Snyk, SonarCloud, Scrutinizer and manual audits.

XOOPS 2.7.4 brings two-factor authentication into the core, makes SCEditor a full visual editor and the default for new sites, and adds Markdown support through EasyMDE. It runs on PHP 8.2 through 8.5.

Please test RC 2 on a staging copy of your site and report anything you find. Unless something serious turns up, the next release is 2.7.4 Final.

DOWNLOAD: https://github.com/XOOPS/XoopsCore27/releases

What's new since RC 1

Forms and redirects

* Form security tokens no longer depend on the browser's User-Agent: a token is now a random value compared in constant time. A browser update, a privacy extension or a "desktop site" toggle between opening and submitting a form no longer rejects it. Forms opened before the upgrade still submit
* Protector uses the core form token: its admin pages check the same token as the rest of XOOPS. XoopsGTicket is deprecated and now wraps the core token, so modules that still call it keep working
* One same-site check for redirects: login, post-login and theme-switch return addresses share one check. It refuses targets written with backslashes, encoded slashes, HTML entities or embedded line breaks, and sends them to the home page instead
* Escaped confirmation pages and error lists: xoops_confirm() escapes every field, value and label, and the object and login error lists are escaped too

Files and storage

* Uploads are deleted only inside the upload directory: the image manager and the smilies, user-rank and avatar admin pages resolve a stored file name before they delete it
* Protected database dumps: a dump is written only under XOOPS_VAR_PATH, into a directory guarded by a deny-all .htaccess and private to the PHP user
* Cache ids use a site key: the group part of theme and block cache ids is keyed with a random site key in xoops_data/data instead of the database credentials
* Random installer names: the installer renames itself and names its cleanup script with random_bytes(). Only the installing session can finish the clean-up
* Protector writes its ban files atomically and rejects an uploaded image it cannot inspect instead of staging it in uploads/

Server configuration

* xoops_lib/.htaccess works on Apache 2.4 without mod_access_compat, where the old rules returned a 500 error instead of denying access
* PHPMailer's unused OAuth helper is removed from the bundled vendor tree, and a Composer script removes it again after every vendor refresh
* reCAPTCHA v2 verifies over POST, so the secret key no longer appears in proxy or server logs
* The bundled XMF library is updated to 1.3.2, which tightens the tag and attribute filtering used for request input

Fixes

* The optional confirmation step for deleting notifications works again
* Deleting a user rank or avatar that no longer exists shows an error instead of a fatal error
* Uploading an image to a database-stored category reports a failed upload instead of stopping with a fatal error
* The TinyMCE 5 and 7 image managers no longer double-encode their target field
* Errors that were silenced with @ (cache, avatar and debug clean-up, session start-up, upgrade-script clean-up) are now handled or reported

The full list is in docs/changelog.270.txt.

Upgrading

From 2.7.4 RC 1

Copy the new files over the web root. There are no database changes since RC 1, so the upgrade wizard is not required (running it does no harm).
* A Protector admin form that was open during the upgrade must be reloaded once
* xoops_data/data must stay writable: the new cache-id key is created there on first use

From XOOPS 2.7.3 or a 2.7.4 beta

Copy the new files over the web root and run the upgrade wizard. It creates the user_2fa table and the two-factor preference, registers the SCEditor emoticons as smileys, adds the Editors preferences, and updates the System module. No mainfile.php changes are needed.
* Two-factor authentication needs the PHP sodium extension; the wizard reports whether it is available. Operations notes are in docs/2fa-operations.md
* Every remembered device logs in once more after the upgrade
* An upgraded site keeps its current editor settings; SCEditor becomes the default only on a fresh install
* If you copied extras/login.php elsewhere on your site, replace or remove that copy
* A site running a custom template set should re-import it

System requirements

* PHP 8.2 to 8.5
* MySQL 5.7+ or MariaDB 10.3+
* The PHP sodium extension for two-factor authentication

Translations

XOOPS is available in 37 community translations at github.com/XoopsLanguages. RC 2 adds two English strings for the database dump in the System module's maintenance page; docs/lang_diff.txt lists every new constant in 2.7.4. Translators, thank you: updated packs are very welcome before the final release.

Reporting issues

Please report bugs at github.com/XOOPS/XoopsCore27/issues, with your PHP and MySQL versions and the steps to reproduce. Questions are welcome in the support forums.

Thank you
Thank you to everyone who tested RC 1, reported issues, submitted pull requests (including the documentation and typo fixes from peter279k), translated strings and reviewed security findings. And a standing thank-you to JetBrains for the complimentary PhpStorm licenses that power the core team's development.

The XOOPS Development Team
Rating 0/5
Rating: 0/5 (0 votes)
Voting is disabled!


Login

Donat-O-Meter

Stats
Goal: $15.00
Due Date: Oct 31
Gross Amount: $0.00
Net Balance: $0.00
Left to go: $15.00
Make donations with PayPal!

Categories