πŸš€ Hostinger Optimized
πŸ–₯️ Server: LiteSpeed
πŸ’» System: Linux s20058.bom1.stableserver.net 5.14.0-611.55.1.el9_7.x86_64 #1 SMP PREEMPT_DYNAMIC Tue May 19 15:19:29 EDT 2026 x86_64
πŸ‘€ User: skhata (1324)
🐘 PHP: 8.4.20
🚫 Disabled: ✨ NONE

πŸ’» Terminal

πŸ“ /home/skhata/chandrasons.com/public
$

πŸ“„ changelog.txt

πŸ“ Path: //var/softaculous/nukeviet/changelog.txt
πŸ“Š Size: 4.45 KB
πŸ”’ Perm: 0644
πŸ“ MIME: text/plain
NUKEVIET 4.6.01
- Fix XSS in class Request. Thanks mrlihd from GitHub @mrlihd
- Select2 v4.1.0, DOMPurify v3.4.13.
- guzzlehttp/guzzle v7.15.2
- Fix numeric-entity leading-zero bypass in Request XSS sanitizer. Thanks Mai Đăng Khoa from GitHub @dkoazw
- Restrict users custom field callback to prevent RCE. Thanks Nguyα»…n Hα»“ng GiΓ‘p from GitHub @PinkArmor
- Fix pre-auth SSRF via spoofed Host header in set_ini_file server info request. Thanks prat1kz from GitHub @prat1kz
- Fix arbitrary file write via S/MIME certificate CN in SMTP settings. Thanks Jace from GitHub @manus-use
- Fix a permission issue when changing comment status
- Prevent SSRF DNS rebinding in Files\Upload URL import

NUKEVIET 4.6.00
- Fixed an issue where figure tags were removed from tables in the editor.
- Updated the password hashing and cookie encryption mechanisms
- Use CSPRNG (random_int) for TOTP and nv_genpass security tokens
- Fix second-order SQL injection in users sql_choices custom field
- Harden deserialization and TLS verification across the system
- Fixed issues related to HTML popovers
- Fix PHP code injection in robots.php via unfiltered filename keys
- Update guzzlehttp/guzzle 7.12.1, guzzlehttp/psr7 2.12.1
- Refactor nv_check_dump_path function to enhance file extension validation and improve directory checks
- Fixed an issue where some valid uploaded images were incorrectly blocked
- Require PHP >=7.4.00

NUKEVIET 4.5.08
- Remove abandoned package true/punycode
- Remove the and/oauth package, which has long been unmaintained, and replace it with league/oauth2-client
- Remove SDK of social network like/share button tools and replace with pure HTML/JS
- Fix XSS bug. Thanks Nguyα»…n Quang BαΊ±ng from WhiteHub#4394
- Support PHP 8.5
- Add a strict permission-checking mode for uploading application packages #3910
- Prevent CKEditor 5 UI buttons from triggering parent form submission #3916
- Fix CSS content conflicts between CKEditor 4 and CKEditor 5
- Fix voting popup
- Ckeditor 5 v47.6.2
- Jquery UI v1.14.2
- DOMPurify 2.5.9 and 3.4.0

NUKEVIET 4.5.07
- CKEditor 5 v47.0.0 and remove CKEditor 4
- PDF.js 3.11.174
- Fix warning error in nv_is_image function when checking webp files
- Fix download database backup files during upgrade
- Add feature to force re-login when editing account in admin area
- Adjust the explanation for the "Developer Mode"
- Fix the error in viewing attachments in the module news
- Add custom block position feature
- Add http_response_code before trigger_error
- Fix banner module error when installing a new language
- Improved source display in the admin panel of the news module
- Improve the configuration for inserting logos into images
- Fix the error in counting article views
- Improved article review workflow in the news module
- Fix password reset issue when using Recaptcha 3
- Enhance the permission system for the Zalo module
- Jquery UI 1.14.1
- Update the versions of Composer libraries
- DOMPurify 3.2.7 and 2.5.7
- Remove function searchKeywordforSQL

NUKEVIET 4.5.06
- The default editor is Ckeditor 5 Classic
- Change the name of DB backup files
- Add plugin NVMedia for Ckeditor 5 Classic
- Add config: api_check_time
- Fix template email
- Change usage from serialize to json
- Updated how to check extension package uploads
- Fix Division by zero in modules/contact/admin/supporter.php
- Fix auto delete notification
- Add allow-popups for iframe sandbox attribute
- Auto sticky table thead in theme admin_default
- Update version: Jquery UI v1.13.3, jQuery Validation Plugin - v1.21.0, DOMPurify 3.1.6

NUKEVIET 4.5.05
- Fix CKEditor 4 iframe, delete plugin googledocs and replace with docviewer
- Fix upload error when filename contains character %
- Support location: hash in link menu
- Display the result counter in admin module news
- Fix breadcrumb error when zooming the screen
- Fix error in determining domain name when activating proxy on the server
- Cloudflare Flexible SSL support
- Multi-port support
- Accepts style tags that contain attributes
- Fix error of content in noscript tag being pushed out
- Required cURL library to be enabled
- Add Ckeditor Classic 5 v41.0
- Save system log in the module contact supporter area
- Add full header for function nv_xmlOutput
- Fixed errors in account suspension/activation/delete operations in administration area
- Add Permissions-Policy and Feature-Policy header management
- Support choosing layout for news category
- Update version: PHPMailer v6.9.1, Jquery v3.7.1, jquery.validator v1.20.0, DOMPurify v2.4.7 and v3.0.9
← BackπŸ“₯ Raw✏️ EditπŸ”’ Chmod
✨ File Manager Magic ✨