Read the official Contao announcements.
Contao 2.11.15 is available
by Leo Feyer – Announcements
Contao version 2.11.15 is available. The bugfix release fixes another security hole related to the PHP object injection vulnerability, which was still exploitable in the Contao back end in version 2.11.14.
The new patch is based on a general hardening of the
deserialize() function and thus not only secures the core but also potentially affected third-party extensions. The update is highly recommended!
Back to the news overview.