2026-06-04 - 2026-06-05
Overview
13 Unresolved Conversations
Open
#33
Add unit and integration test suite
Open
#34
JSON-LD script tag vulnerable to XSS via </script> in content
Open
#35
CSV import missing file type and size validation
Open
#36
Content type adapters (K2, VirtueMart, HikaShop) are dead code
Open
#37
Batch and ImportExport controllers lack ACL permission checks
Open
#38
System plugin DB queries run on every page load with no caching
Open
#39
Direct access to protected $doc->_links property breaks forward compat
Open
#40
Missing SPDX license identifiers on all PHP files
Open
#41
Content plugin ignores language when loading/saving OG data (multilingual bug)
Open
#42
Batch process limit parameter not capped - potential DoS
Open
#43
TagTable::check() does not validate field values
Open
#44
Update server XML excludes Joomla 4 and uses dev version
Open
#45
Security hardening, site-wide OG defaults, platform-specific social tags