FreeScout - Package Updates
-
[1.16.15]
- Update freescout to 1.8.224
- Full Changelog
- Added throttling to file upload routes (Security: GHSA-ph4f-2jhx-q76w)
- Fixed user-setup empty
invite_hashissue (Security: GHSA-jqj5-r72v-v29g) - Improved downloading log files logic (Security: GHSA-858x-8f77-9vc5)
- Restricted
.phtfiles upload (Security: GHSA-27vp-fpg8-j8wv) - Improved sanitizing customer Websites field.
- Enabled browser check - now it will be impossible to access FreeScout instance from a browser which does not support CSP.
-
[1.16.16]
- Update freescout to 1.8.225
- Full Changelog
- Added throttling and authentication in
tools.php(Security: GHSA-w2p9-3666-vw9j) - Fixed color of texts in logs table (#5442)
- Patched
symfony/routing(Security: CVE-2026-45065) - Upgraded
symfony/polyfill-intl-idnto 1.38.1 (Security: CVE-2026-46644) - Fixed path traversal in Log Viewer (Security: GHSA-9ph7-f3hc-95gg)
- Moved option to UI: "User can see only assigned conversations" (#701)
- Improved
Helper::stripDangerousTags()to strip nested tags (Security: GHSA-jpq8-j69f-mj98) - Fixed saving mailbox signature by non-admin users (#5443)
-
[1.16.17]
- Update freescout to 1.8.226
- Full Changelog
- Paginate by SEARCH count so the newest emails are never dropped (#546)
- Fixed
json_decode()error inUser::hasManageMailboxPermission()(#5465) - Fixed Error 500 in
ConversationsController::viewwhen a user has no Mine folder (#5466) - Fixed "Could not scan for classes" error (#5469)
- Escape channel name in LIKE query in
PolycastServiceProvider.php(Security: GHSA-gh3r-jh6q-wrvj) - Fixed access check in realtime Polycast events (Security: GHSA-gh3r-jh6q-wrvj)
- Improved
RealtimeConvNewThreadevent access check (Security: GHSA-w668-wq26-6c94) - Prevent sending blank email when Summernote leaves empty HTML tags (#5478)
- Check access permissions when searching conversations by number (Security: GHSA-wqq7-4q7m-273v)
- Fixed: customer Waiting Since shows time of the last customer message instead of the first (#5475)
-
[1.16.18]
- Update freescout to 1.8.229
- Full Changelog
- Fixed "Undefined variable $addressString" (#5487)
- Fixed "Undefined array key 10004" on outbound Guzzle request without a proxy (#5486)
- Fixed "Undefined variable $ensureAddressesAreSafe" (#5487)
- Fixed permissions check when merging conversations (Security: GHSA-v8vc-cmf9-gg2c)
- Patched security issues in dependency libraries: GHSA-vm85-hxw5-5432, GHSA-hq7v-mx3g-29hw, GHSA-34xg-wgjx-8xph, GHSA-cwxw-98qj-8qjx, GHSA-wpwq-4j6v-78m3, GHSA-h5x3-xfc9-m39h, GHSA-5vg9-5847-vvmq
-
[1.16.19]
- Update freescout to 1.8.230
- Full Changelog
- Save conversation subject when pressing Enter in the subject field (#5492)
- Do not send notifications to users when customer replies to a Spam conversation.
- Improved showing bell notifications (#5491)
- Enabled
Core.EscapeNonASCIICharactersin Purifier (#5481) - Improved remote URL sanitizing (Security: GHSA-6w8v-qp43-vg2h)
- Send CSP header in
/ajax-html/URLs (Security: GHSA-2g42-f97q-973x) - Fixed real time bell notifications (#5499)
- Fixed separating replies from Outlook (#5504)
-
[1.16.20]
- Update description
-
[1.16.21]
- Update freescout to 1.8.231
- Full Changelog
- Check customer visibility in
load_customer_infoajax action (Security: GHSA-cr68-27qv-p5m4) - Restricted access to Assigned Conversations option in user profiles (GHSA-m4hc-rc98-38jc)
- Change customer when received a reply to a conversation from completely new email address (Security: GHSA-j49f-9g94-3wh4)
- Tighten throttling in Forgot Password requests (GHSA-jvmv-2qcp-7855)
- Allow to define PHP path via
PHP_PATH.env parameter for tools.php script (#5507) - Update customer in threads when merging customers (#5505)
- Do not allow to send reply till all uploads finished (#5515)
- Create a new conversation for email notifications forwarded to another mailbox (#4515)
- Fixed missing space in browser push notifications (#5520)
- Show warning on Status page when HTTPS is used but
SESSION_SECURE_COOKIE=trueis not set.
-
[1.16.22]
- Update freescout to 1.8.232
- Full Changelog
- Use salt in
tools.phpauth. - Return empty value in
Helper::decrypt()when decryption fails. - Tighten throttling Forgot Password requests (Security: GHSA-jvmv-2qcp-7855)
- Throttle
ResetPasswordControllercontroller. - Escape title in symfony
ExceptionHandler. - Purify mailbox signature HTML on saving.
- Sanitize module alias on activating a license.
- Use
hash_equals()when checking attachment token. - Revert changing
last_reply_atfield update logic #5501 - Restrict file extensions uploaded by support agents.
-
[1.16.23]
- add white list ip ranges and store mail password encrypted fixing #15783
-
[1.16.24]
- Update freescout to 1.8.233
- Full Changelog
- Sound notifications for chat messages.
- Allow to switch "Waiting Since" field into the "Time of the last customer activity" via
WAITING_SINCE_AS_FIRST_UNANSWERED_CUSTOMER_MESSAGE.env parameter (#5225) - Fixed
CTRL+Zafter loading draft in the editor (#4837) - Do not insert
<hr>tag onCTRL+ENTERclick (#4909) - Create forward-note for each recipient when forwarding conversation to multiple recipients (#5441)
- Fixed too long
Referencesheader in emails to customers (#5542) - Fixed Outlook reply separator for incoming emails (#5544)
- Strip Outlook reply header from the body of replies sent to email notifications (#5545)
- Allow
styleattribute in inline elements in Purifier config (#5547)
Hello! It looks like you're interested in this conversation, but you don't have an account yet.
Getting fed up of having to scroll through the same posts each visit? When you register for an account, you'll always come back to exactly where you were before, and choose to be notified of new replies (either via email, or push notification). You'll also be able to save bookmarks and upvote posts to show your appreciation to other community members.
With your input, this post could be even better 💗
Register Login