grthtrhthjhtyjytjytkergtrhtrjytjerhrfh4:24 29/09/2026NUKEVIET 4.6.02 - Fix reflected XSS via double URL decoding of search keyword in news module (CVE-2026-94599). Thanks Thế from GitHub @Pbat6 - DOMPurify v3.4.15 - Fix stored XSS via internal marker injection in iframe srcdoc (CVE-2026-94598). Thanks Thế from GitHub @Pbat6 - Fix RCE via image upload bypass chain (CVE-2026-94597). Thanks CAN QUANG HIEU from GitHub @canhieu - Fix a security vulnerability in the SVG file upload (CVE-2026-94567). Thanks Nguyễn Huy Hoàng from GitHub @hoanggxyuuki - Fix SSRF vulnerabilities in the upload functions, the Image class, and sitemap ping. Thanks canhieu from GitHub @canhieu. - Fix dangerous functions accessible via the GET method. Thanks archnexus707 from GitHub @archnexus707 - Fix a security vulnerability in the module language write functionality. Thanks phuongmai1212 from GitHub @phuongmai1212 and AuQuangDuc from GitHub NUKEVIET 4.6.01 - Fix XSS in class Request. Thanks mrlihd from GitHub @mrlihd - Select2 v4.1.0, DOMPurify v3.4.13. - guzzlehttp/guzzle v7.15.2 - Fix numeric-entity leading-zero bypass in Request XSS sanitizer. Thanks Mai Đăng Khoa from GitHub @dkoazw - Restrict users custom field callback to prevent RCE. Thanks Nguyễn Hồng Giáp from GitHub @PinkArmor - Fix pre-auth SSRF via spoofed Host header in set_ini_file server info request. Thanks prat1kz from GitHub @prat1kz - Fix arbitrary file write via S/MIME certificate CN in SMTP settings. Thanks Jace from GitHub @manus-use - Fix a permission issue when changing comment status - Prevent SSRF DNS rebinding in Files\Upload URL import NUKEVIET 4.6.00 - Fixed an issue where figure tags were removed from tables in the editor. - Updated the password hashing and cookie encryption mechanisms - Use CSPRNG (random_int) for TOTP and nv_genpass security tokens - Fix second-order SQL injection in users sql_choices custom field - Harden deserialization and TLS verification across the system - Fixed issues related to HTML popovers - Fix PHP code injection in robots.php via unfiltered filename keys - Update guzzlehttp/guzzle 7.12.1, guzzlehttp/psr7 2.12.1 - Refactor nv_check_dump_path function to enhance file extension validation and improve directory checks - Fixed an issue where some valid uploaded images were incorrectly blocked - Require PHP >=7.4.00 NUKEVIET 4.5.08 - Remove abandoned package true/punycode - Remove the and/oauth package, which has long been unmaintained, and replace it with league/oauth2-client - Remove SDK of social network like/share button tools and replace with pure HTML/JS - Fix XSS bug. Thanks Nguyễn Quang Bằng from WhiteHub#4394 - Support PHP 8.5 - Add a strict permission-checking mode for uploading application packages #3910 - Prevent CKEditor 5 UI buttons from triggering parent form submission #3916 - Fix CSS content conflicts between CKEditor 4 and CKEditor 5 - Fix voting popup - Ckeditor 5 v47.6.2 - Jquery UI v1.14.2 - DOMPurify 2.5.9 and 3.4.0 NUKEVIET 4.5.07 - CKEditor 5 v47.0.0 and remove CKEditor 4 - PDF.js 3.11.174 - Fix warning error in nv_is_image function when checking webp files - Fix download database backup files during upgrade - Add feature to force re-login when editing account in admin area - Adjust the explanation for the "Developer Mode" - Fix the error in viewing attachments in the module news - Add custom block position feature - Add http_response_code before trigger_error - Fix banner module error when installing a new language - Improved source display in the admin panel of the news module - Improve the configuration for inserting logos into images - Fix the error in counting article views - Improved article review workflow in the news module - Fix password reset issue when using Recaptcha 3 - Enhance the permission system for the Zalo module - Jquery UI 1.14.1 - Update the versions of Composer libraries - DOMPurify 3.2.7 and 2.5.7 - Remove function searchKeywordforSQL