Exponent's Latest News

Version 2.3.8 Released

May 2, 2016 Tags: release, bugs

This version, code-named 'Mayday Mayhem' fixes many issues in the previous version(s) and adds several new features. There is a new Social Feed module which allows aggregating and displaying items from Facebook, Twitter, Instagram, and/or Pinterest.  The changes include: (read more)

Patch #4 Released for V2.3.7

February 16, 2016 Tags: patch, release, bugs

This patch fixes several issues in the v2.3.7 release and v2.3.7 patch #1, patch#2, and patch#3.  It also provides several tweaks and even some new features, though the main focus is providing several regression fixes.  It should be noted that the new optional 'Upgrade permissions' upgrade scripts will attempt to lock down the site by fixing file and folder permissions (except for cgi-bin) which means also turning off the 'execute' permission.   It must be noted that this patch (like the previous patches to v2.3.7) will break any custom text module view templates using in-place editing.  Unlike previous patches, this patch file also includes all the 'installation' files in the event you secured your site by deleting or renaming the /install folder. Patch #4 to v2.3.7 is found at http://sourceforge.net/projects/exponentcms/files/exponent-2.3.7-patch-4.zip/download (read more)

Exponent CMS Forums Back Up!

January 28, 2016 Tags: forums

(updated Jan 29th) After being out of service for quite some time, we have the Exponent CMS forums back up and running (forums.exponentcms.org) with a few caveats: (read more)

Patch #3 Released for V2.3.7

January 23, 2016 Tags: patch, release, bugs

This patch fixes several issues in the v2.3.7 release and v2.3.7 patch #1 and patch#2.  It also provides several tweaks and even some new features. The main fix is for a security vulnerability using malformed arrays.  It also provides some regression fixes to the text module inline-edit view(s). It must be noted that this patch will (again) break any custom text module view templates using in-place editing. This patch adds a couple new features to Twitter Bootstrap 3 based themes in the form of a new date/time picker widget, and a new photoalbum slideshow/carousel widget. There are a few other tweaks and fixes found in this patch. Unlike previous patches, this patch file also includes all the 'installation' files in the event you secured your site by deleting or renaming the /install folder. Patch #3 to v2.3.7 is found at http://sourceforge.net/projects/exponentcms/files/exponent-2.3.7-patch-3.zip/download (read more)

Security Notice: Closing an Exponent Security Vulnerability

January 14, 2016 Tags: security

We've been notified of a security vulnerability which could compromise your Exponent CMS installation.  This vulnerability applies to all versions of Exponent 2.x up to v2.3.7 patch #2.  The immediate fix is to rename the /install folder to something else, or remove/delete it. Though we've been working hard to close Cross-Site Scripting (XSS) vulnerabilities, this one could be more permanent and seems to result from an anomaly within PHP which allows a string variable to be internally interpreted and processed as an array thereby masking the payload. (read more)

Patch #2 Released for V2.3.7

January 9, 2016 Tags: patch, release, bugs

This patch fixes several issues in the v2.3.7 release and the v2.3.7 patch #1 and provides several tweaks and even some new features. The main fix is for a regression problem in v2.3.7 which prevented editing or copying existing calendar events. It must be noted that this patch will break any custom text module view templates using in-place editing.  While you will not lose any data, the results of saving the first in-place change will break the javascript on the page...therefore you must remove any such custom templates, or create a new one based on the system ones included in this patch.  Patch #2 to v2.3.7 is found at http://sourceforge.net/projects/exponentcms/files/exponent-2.3.7-patch-2.zip/download (read more)

v2.3.7/v2.3.7 Patch #1 Bug

January 4, 2016 Tags: bugs, preview

You can expect a v2.3.7 patch #2 to be released later this week (1st full week of 2016) to fix a v2.3.7 regression bug which prevents editing or copying calendar events.  There is no work-around for this bug, however it doesn't affect creating new events.  The patch will also fix some styling issues with bootstrap 3 based themes, clean up the optional ajax paging urls, and remove some warnings which prevent some ajax calls and xmlrpc from working when error reporting is turned on. (read more)

Patch #1 Released for V2.3.7

January 2, 2016 Tags: patch, release, bugs

This patch fixes a few issues in the v2.3.7release. The main fix is for a regression problem in v2.3.7 which prevented using the 'Quick Upload' feature because uploaded files would be truncated to zero bytes.. Patch #1 to v2.3.7 is found at http://sourceforge.net/projects/exponentcms/files/exponent-2.3.7-patch-1.zip/download (read more)

Try a 'Fresh Fix' for 2016

December 31, 2015 Tags: release, bugs

After a failed attempt to get something under the tree for Christmas, we now release v2.3.7 specifically to address the fatal flaws within the pulled v2.3.6 release.  These include: (read more)

v2.3.6 pulled for critical error!

December 26, 2015 Tags: bugs

We've pulled the v2.3.6 release package and recommend you NOT install it!  Due to the holidays, v2.3.7 will not be released until after January 1st.  The new security fix unexpectedly removes all styling from edited WYSIWYG text when saved...which is basically how the WYSIWYG editor does most of its magic. Additionally, activating the new enhanced password hashing (also in v2.3.5) will corrupt passwords and prevent logging on after the password is updated (a database structure issue)  We already have fixes for these issues and will release a version 2.3.7 with the fixes and possibly another ajax paging fix.  We are sorry for this inconvenience. (read more)