| Name | Modified | Size | Downloads / Week |
|---|---|---|---|
| Parent folder | |||
| README.md | 2025-10-21 | 1.5 kB | |
| Security Release v6.6.10.7 source code.tar.gz | 2025-10-21 | 12.5 MB | |
| Security Release v6.6.10.7 source code.zip | 2025-10-21 | 19.9 MB | |
| Totals: 3 Items | 32.5 MB | 0 | |
See the UPGRADE.md for all important technical changes.
- GHSA-m895-2hj3-8cg9 - fix: Reading media entities by aggregating fields individually bypasses MediaVisibilityRestrictionSubscriber
- GHSA-27c9-vp3w-6ww8 - fix: Exposure of sensitive user information via CSV export mapping
- GHSA-3cpp-fv95-mpr5 - fix: Server-Side Request Forgery (SSRF) - order invoice
- GHSA-6wh5-mw9h-5c3w - fix: Path traversal via Plugin upload
- GHSA-r2vg-hvjm-fg38 - fix: Customer Orders can be canceled, even if refunds are disabled
- #6912 - fix: require with minimum-stability stable (fixes: [#6912]) (#6914)
- #6960 - ci: skip downstreams in case of no write perms (fixes: [#6960]) (#6985)
- #9031 - ci: reenable 6.6.0.0 update (fixes [#9031])[6.6.x] (#9248)
- #9851 - feat: implement event on Sitemap Generation, closes [#9851] [6.6.x] (#9968)