<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
<title>Mein Newsfeed — BookStack</title>
<link>https://newsfeed.avintaris.com</link>
<description>News zum Thema BookStack</description>
<language>de</language>
<lastBuildDate>Fri, 22 May 2026 21:22:05 +0000</lastBuildDate>
<item>
<title>BookStack: BookStack v26.03.5 — Security Release gegen MFA-Brute-Force</title>
<link>https://www.bookstackapp.com/blog/bookstack-release-v26-03-5/</link>
<guid isPermaLink="false">https://www.bookstackapp.com/blog/bookstack-release-v26-03-5/</guid>
<pubDate>Thu, 21 May 2026 12:00:00 +0000</pubDate>
<category>BookStack</category>
<description>Fünftes Patch-Release der v26.03-Linie (Latest). Adressiert Brute-Force-Schwachstelle im MFA-Flow (Codes ohne ausreichendes Rate-Limiting). Mehrere PHP-Composer-Dependencies aktualisiert für transitive Sicherheitslücken. Für Instanzen mit aktiviertem MFA: Update dringend empfohlen. Standard php artisan migrate ausreicht.</description>
</item>
<item>
<title>BookStack: v26.03 Jahres-Release — Theme-Module-System &amp; HTML-Purifier Content-Filtering</title>
<link>https://www.bookstackapp.com/blog/bookstack-release-v26-03/</link>
<guid isPermaLink="false">https://www.bookstackapp.com/blog/bookstack-release-v26-03/</guid>
<pubDate>Sun, 15 Mar 2026 12:00:00 +0000</pubDate>
<category>BookStack</category>
<description>Großes Feature-Release. **Theme-Module-System**: Mehrere Module parallel zu aktivem Theme, je eigene bookstack-module.json und views/. Installation via php artisan bookstack:install-module. Neue Logical-Theme-Events: THEME_REGISTER_VIEWS (Priority-basierte View-Injection), PAGE_CONTENT_PRE_STORE und PAGE_CONTENT_POST_RENDER (Content-Manipulation), OIDC_AUTH_PRE_REDIRECT (OIDC-URL-Customizing). APP_CONTENT_FILTERING ersetzt deprecated ALLOW_CONTENT_SCRIPTS — HTML-Purifier-basiertes Allow-List-Filtering. REST-API: Book-Read-Endpoints liefern Parent-Shelf-Info mit. **BREAKING:** SMTP-HELO-Domain-Logik geändert; modules/ Ordner reserviert; ALLOW_CONTENT_SCRIPTS deprecated.</description>
</item>
</channel>
</rss>
