Home/What's New

Release notes

What's new in VonCMS.

Product improvements, fixes, and upgrade notes.
Follow the changes that matter to your publication.

Full release archive
Version
v1.27.8
Status
Stable Release
Published
October 8, 2026
License
GPL-3.0-only

Release notes from GitHub. A verified snapshot is included below.

Latest stable release

VonCMS v1.27.8 "OverDrive

Original notes

This maintenance release strengthens login, password recovery, and settings ownership, with compatible dependency updates and no new database migration.

VonCMS v1.27.8 "OverDrive"

This maintenance release strengthens login, password recovery, and settings ownership, with compatible dependency updates and no new database migration.

Highlights

  • Login now requires a valid guest-session CSRF token before processing credentials. Normal login and Remember Me remain supported.
  • Legacy comment migration retains Admin and CSRF checks and rejects payloads that mix migration data with individual comment actions.
  • Legacy Domain URL input now follows the same Primary Admin permissions and validation as the canonical setting.
  • Password-recovery quotas now use one locked, expiry-pruned storage file, capped at 4,096 entries and 1 MiB.
  • Existing recovery limits remain unchanged, without adding a shared-IP restriction for visitors behind proxies or CDNs.
  • Login, registration, newsletter subscription, and password recovery now recognize 0 as a filled honeypot value.
  • Theme and editor entity decoding preserve literal angle-bracket text instead of interpreting it again as HTML.
  • Updated OpenRouter SDK, Lucide React, Vite, the Vite React plugin, PostCSS, and express-rate-limit.
  • Updated Tailwind Typography's selector parser to address the build-time CPU-exhaustion advisory.

Updating

Back up your website files and database before updating.

Existing installations may update using the VonCMS updater or upload the latest Deploy package manually. After updating, verify the homepage, one article, one page, and the admin dashboard.

No new database migration is required. Sites upgrading from before v1.27.7 should complete the existing Schema Repair step described in the upgrade guide.

Sites using a legacy nested Domain URL mirror should save General Settings once as the Primary Admin after updating.

Downloads

  • VonCMS_v1.27.8_Deploy.zip - installation and hosting update package
  • VonCMS_v1.27.8_Source.zip - complete source package

SHA-256

Deploy:

96AFADE6F24A4BC3983394098ECE7BCF2B79F5FEF255A5CC7429E2C2CB22589D

Source:

3C1EC06C0015A5509D6E4966E8B6FA10D69936389903BF98977E92973D222C13