Announcements

Upgrader should now work for alpha1 to alpha2
A bug on composr.app prevented alpha1 to alpha2 upgrades and should now be fixed.
Composr.app site opened (version 11)
The new website for version 11 (composr.app) is online. Read the full article for important information and implications.

Facebook login integration disabled on compo.sr
If you use Facebook login you will need to reset your password.

Two new XSS security holes, and resolutions
Two security holes were recently discovered in current and previous versions of Composr CMS, and patched.

Upgrading ocPortal sites if PHP compatibility breaks
Advice and tooling for dealing with ageing ocPortal websites.

Community Site Showcase
Announcing the Community Site Showcase, where you can show off your sites to others and upvote/downvote (Reddit-style).

Bogus vulnerability reported ("'banners' Persistent Cross Site Scripting")Bogus vulnerability reported ("'banners' Persistent Cross Site Scri…
Anatomy of a bogus vulnerability that is circulating.

Updated minimum PHP requirement
Composr now requires PHP 5.3+ (but really you should be on PHP 7.3+).

Bugs in Composr 10.0.33
There are a number of nasty bugs in 10.0.33, hot fixes are linked inside this issue.
Overhaul of project messaging
A number of development practices have been overhauled around how development work is messaged. This is to improve communication to Composr users and also within the development team.

Security vulnerability in Composr
A security hole has been found in Composr. This is a serious vulnerability that affects all versions of Composr 10+. It is critical that you deploy a resolution to this vulnerability as soon as possible.

Introducing the Conposr and Conposr++ frameworks
Introducing two new frameworks inspired by Composr, but targeted towards the development of standalone web apps.

compo.sr infrastructure problems (now solved)
An explanation for some recent instability on compo.sr.

Topic read counts - a bug affecting users who upgraded from ocPortal
We just discovered a bug affecting users who upgraded from ocPortal.

Announcing Composr 9000
We are currently hard at work on Composr 11, but in parallel we have been secretly working on something much grander – Composr 9000. More information is inside.

Important issue in PHP 5.1/5.2
There is a major problem running the latest Composr patch release in old PHP versions.