|
Welcome soft
Serendipity
Version : 2.6.1
Release Date : 23-07-2026
Changelog
Version 2.6.1 () ------------------------------------------------------------------------
* Security fix: The check for which URLs are allowed to be fetched when downloading images to the ML was outdated and did not catch e.g. AWS IMDS at 169.254.169.254. Thanks to @riodrwn for the report and patch.
* Security fix: Close an open redirect in exit.php that was opened when the trackexit plugin was installed and the option was set to redirect comment links via the blog. Thanks to @DevVaibhav07 for the report and patch. * Security fix: A new account could re-use the username of an existing account and gain adming rights this way. Thanks to @DevVaibhav07 for the report and patch.
* Security fix: Reflected XSS in search clean-URL route. Thanks to @hutsbotnet for the report and patch.
* Fix plugin drag'n drop not working on new installs
* Fix some PHP 8 code quality warnings
* Add cleanCache() on comment editing, deletion and category changes (thanks to @fasterit/DLange)
* Fix division by zero error when accessing all PHP comments on PHP 8 (thanks to @qbi) * Fix error message and 404 status code on plugin pages when cache was active (thanks to @fasterit/DLange)
Version 2.6.0 (April 10th, 2026) ------------------------------------------------------------------------
* Add an option to limit which hosts are accepted as automatically detected baseURL, serendipity['validBaseHosts']. This is a security measure for installations that run under multiple domains and also accept arbitrary host headers. * Security fix: Attackers could manipulate the mail headers of notification mails, on some server setups. Thanks to Marcelo Barbosa for the report. * Security fix: The domain of the login cookie could be manipulated, on some server setups. Thanks to Marcelo Barbosa for the report.
* Rework of the XSRF token protection, it was a replaced with a check on the Sec-Fetch-Site header. This should eliminate the timeouts that caused referer error messages on entry previews and saves.
* Fix: The bootstrap4 theme now sets the serendipity_entry class. This fixes the lightbox plugins photoswipe mode when using one gallery per entry and potentially other plugins. * Provide option for a second factor on login. Currently this consists of a code sent to the autor's email that has to be entered on login.
* 2k11 now shows examples for its multiple date format options in the theme's configuration * Maintenance action for clearing the template cache now also empties the internal cache of serendipity and clears all smarty cache files. It was thus renamed to "clear cache".
* nl2br: Fix an error that occured on some configuration in nl2p mode on the isolation tags check
* Removed Sourceforge from Spartacus' mirror list, as it caused HTML to be written to the plugin files instead of the wanted PHP code.
* Removed obsolete Pragma header from some responses, controlling brwoser cache behaviour. Alternative headers were already set.
* Fix: clean blog's sticky header (that appears when scrolling up) was positioned with a gap, when it contained too many navigation links
* Breaking Change: Removed Net/DNSBL.php, Net/CheckIP.php and pear/net_dns2 from the bundled libs.
* Update Smarty to current v5.6.0 (official support for PHP 8.4)
* Make smarty->entries also available when entry is cached. This fixes e.g. opengraph tags of the social plugin disappearing. * Brute force protection for the logins. Logins now only accept 5 login attempts a minute, bound to the user's anonymized IP. * Show error when uploaded file is too big (PHP ini settings) * Move 2k11's url validation helper function into the load event, so loading of jQuery itself can be delayed * clean blog: Updated to use newer versions of font awesome, bootstrap and its webfonts. Also hosts those files locally now and drops the shims for old versions of the Internet Explorer. Add option for a mastodon profile button.
* Fix CSS based tabs in plugin and media upload area
* Fix tooltips in installer not working and the installer's language list using the wrong encoding
* Add XSLT shylesheet to the RSS and Atom feed, including a link to an explainer about how to use feeds
Version 2.5.0 (13.02.2024) ------------------------------------------------------------------------
* Restore compatibility with PHP 7.4
* Remove bundled composer.phar (thanks to hboeck)
* Update composer dependencies (mostly for PHP 8.3 compatibility): katzgrau/klogger (1.0.0 => 1.2.2) pear/http_request2 (v2.5.1 => v2.6.0) pear/net_dns2 (v1.5.3 => v1.5.4) psr/log (1.0.0 => 1.1.4) smarty/smarty (v4.3.2 => v4.3.5)
* Fix a PHP notice in User management ("isEditable") (garvinhicking)
* Fix a bug when the p parameter given was set to 0 (@hannob)
* Fix an incompatibility with MySQL 5.7 or later (@mariohommel) Version 2.4.0 (November 20th, 2022) ------------------------------------------------------------------------
* Fix: Avoid bad number of arguments to sprintf and fix logic error in spamblock plugin.
* Improve w3c compatibility be encode square brackets of comment mode links (thanks @hannob)
* Fix: Previewing comments warning threw a warning on PHP 8, when debug mode on (thanks @hannob)
* Fix: Editor autosave cached was not deleted when saving entry
* Fix: Editor autosave was not on by default, despite the setting being active by default
* Fix: admin/entries.tpl: fix undefined variable iso2br
* Fix: The calendar plugin threw a warning about $cond['join'] not existing in some setups
* Fix: Avoid one more situation where responsive image upscaled a small thumbnail
* Bugfix: Entryproperites plugin no longer insert empty records for multiple authors (garvinhicking)
* Improve permalink generation performance and enable more unicode replacements (thanks to mbirth!) Version 2.3.5 (April 25th, 2020) ------------------------------------------------------------------------
* Fix: CSS: Restrict block display of summary to trackbacks. (#703)
* Fix: Don't strip HTML from comments body in serendipity_plugin_comments before serendipity_event_unstrip_tags can convert the HTML tags (being called via frontend_display hook). (#702)
* Fix: [CKE] Don't remove <details> and <summary> elements from WYSIWYG editor.
* Fix: Don't delete extend properties from the entryproperties plugin when publishing from dashboard (or sending delayed trackbacks). (#695)
* Fix: SQL error in serendipity_plugin_history present since we "don't allow requesting an archive page that doesn't exist" (2.3.3). (#694)
* Fix: Entry title in backend list of entries was double escaped.
* Fix: Don't drop upgraded_version from local plugin cache.
* Fix: Regular expression in functions_routing.inc.php
* Fix: Truncate extension of media items to 5 chars (which ist the max length of the corresponding database field). (#609) Thanks to @mmitch!
Serendipity is a PHP-powered weblog application which gives the user an easy way to maintain an online diary, weblog or even a complete homepage. While the default package is designed for the casual blogger, Serendipity offers a flexible, expandable and easy-to-use framework with the power for professional applications.
Casual users appreciate the way Serendipity's sophisticated plugin architecture allows you to easily modify both the appearance of your blog and its features. You can install more than120 plugins with just one click, instantly enhancing your blog's functionality. No need to edit code!
Serendipity is free, open, and available to anyone under the BSD 3-Clause License.
Space Required
Available Space : Unlimited MB Required Space : 33.68 MB
Software Support
Visit Support Site
Note: Softaculous does not provide support for any software.
Checking the submitted data
(0 %)
NOTE: This may take 3-4 minutes. Please do not leave this page until the progress bar reaches 100%
- Simple. Designed for users of all technical levels.
- Robust Editing Interface. Featuring an (optional) WSYISWG editor, easily browsable image manager, extended entry support, entries statistics and a host of other features.
- Threaded comments, Nested categories and posting to multiple categories are supported.
- Anti-Spam / Comment moderation. Through use of a (bundled) plugin you can enable CAPTCHAs, SURBL-blacklisting, automatted comment moderation based on the content of a comment. Highly configurable.
- Support for XML-RPC Editing. Support for both the Movable Type? and Blogger XML-RPC APIs.
- Dynamic. You don't need to constantly wait while your weblogging system regenerates pages. Caching is dynamically managed, so you don't need to worry about it when publishing your weblog. Optional advanced URL rewriting rules and customizable permalinks are available.
- Trackback and Pingback. Serendipity can accept, send and autodiscover trackbacks and pingbacks. Of course you can also ping common weblog services like technorati, blo.gs, blogger, yahoo and blogg.de.
- Plugins. A robust plugin system allows you to modify Serendipity without digging through the core source code. Sidebar plugins allow easy customization of your blog with dozens of features. Event plugins are a powerful method of method callbacks, which can hook in into any place in s9y to make it one of the most flexible APIs available. Our online repository (Spartacus) supports adding plugins within a few mouseclicks and no manual file up/downloading! Powerful plugins exist for maintaining static page content, displaying galleries, making rss aggregators, ldap authentication, customized template view, multilingual content and much more.
- Multiple Databases. Serendipity supports MySQL(i), PostgreSQL and SQLlite database backends.
- Multiple Users. Multiple users can edit and administrate the weblog. A free permission setup can tell which user is allowed to do what.
- Internationalized. Serendipity is available in English, German, Danish, French and many more, and adding new translations is a snap.
- Skinable. Templates can easily be added by the magic of CSS. Several templates are included by default. Even visitors of your blog are able to change the layout on-the-fly if you use the template-dropdown plugin. For the advanced user, the full flexibility of the Smarty templating engine allows to change every aspect of the Serendipity look.
- Open Source. Serendipity is licensed under the BSD License.
- Standards Compliant. Serendipity supports XHTML 1.1, CSS 2.0, RSS 0.93, 1.0, and 2.0, Atom 0.3 and 1.0. Supports conditional GET for caching RSS feeds on the client-side. It also supports UTF-8 environments.
- Shared library. You can use Serendipity as a single installation to serve multiple and independent weblogs, but only maintaining a single codebase.
- Easy Upgrading. An easy and automatic upgrader helps you in the process of upgrading between Serendipity versions (starting with version 0.5).
- Flexible Input/Output. Choose between HTML, Textile, Wiki, BBCode and a boast of other markups. For both users and your editors!
- PHP-powered to fulfill the needs of ever-growing PHP-enabled websites and easy integration with support of embedding Serendipity into your webpage.
- Actively maintained by some skilled and open-minded developers who enjoy the touch to the actual user and give support on the Forums as well as listen to every new user suggestion.
23-07-2026
44
|