v7.10.0 What's Changed 🏕 Features Strip completely at the php level to avoid xss by @ildyria in #4789 Add CAN_MOVE rights by @ildyria in #4787 fix(security): block all IPv6-transition spellings that embed an internal IPv4 by @anzal1 in #4791 Configurable size variant format (WebP) and lossless quality by @NikitaTH in #4790 Translations update from LycheeOrg - Weblate by @ildyria in #4793 Refactor agentic to reduce the number of merge conflicts by @ildyria in #4796 Fixes advisories crash when on internal network without internet access by @ildyria in #4798 Global password gallery setting by @ildyria in #4799 Avoid XSS in GPX tracks by @ildyria in #4804 Fix dock being visible when user has not edit rights by @ildyria in #4806 Avoid uploading a picture of another user and getting extra perks by @ildyria in #4805 Add support for video loop attribute by @ildyria in #4807 Fix video player? by @ildyria in #4808 Version 7.10.0 by @ildyria in #4800 👒 Dependencies chore(deps): bump node from dbaa92e to 0b36e8c by @dependabot[bot] in #4810 chore(deps): bump composer from a5f59b9 to 9715c7f by @dependabot[bot] in #4812 chore(deps): bump dunglas/frankenphp from f92d81e to 81231b5 by @dependabot[bot] in #4813 chore(deps): bump debian from d7e1218 to a99cfc5 by @dependabot[bot] in #4811 chore(deps): bump the actions-deps group with 4 updates by @dependabot[bot] in #4817 chore(deps): bump the production-dependencies group with 6 updates by @dependabot[bot] in #4815 chore(deps-dev): bump the development-dependencies group with 6 updates by @dependabot[bot] in #4816 New Contributors @anzal1 made their first contribution in #4791 @NikitaTH made their first contribution in #4790 v7.8.5 Latest What's Changed 🏕 Features Fix language by @ildyria in #4757 v7.8.4 What's Changed 🏕 Features Trivy ignore CVE-2026-84304 by @ildyria in #4714 Ergonomic update with escape and space keys by @jphuguet in #4707 Trivy ignore CVE-2026-84445 by @ildyria in #4727 Show album cover art while password-protected by @matthewbolding in #4704 Improve Ux by @ildyria in #4730 Fix cves by updating dependencies by @ildyria in #4737 Fix folder multi processing by @ildyria in #4736 Send the origin on openstreetmap.org by @ildyria in #4739 Fix dock on smart album by @ildyria in #4741 Switch from === to hash_compare for time sensitive comparisons by @ildyria in #4743 Improve maps by @ildyria in #4751 Add Width and Height to the meta info when loading a page by @ildyria in #4752 Version 7.8.4 by @ildyria in #4755 👒 Dependencies chore(deps): bump the actions-deps group with 3 updates by @dependabot[bot] in #4725 chore(deps-dev): bump the development-dependencies group with 5 updates by @dependabot[bot] in #4723 chore(deps): bump the production-dependencies group with 3 updates by @dependabot[bot] in #4721 chore(deps): bump the production-dependencies group with 3 updates by @dependabot[bot] in #4720 chore(deps-dev): bump the development-dependencies group with 4 updates by @dependabot[bot] in #4722 chore(deps): bump composer from 2.10.2 to 2.10.3 by @dependabot[bot] in #4724 chore(deps-dev): bump composer/composer from 2.10.2 to 2.10.3 by @dependabot[bot] in #4726 chore(deps): bump the actions-deps group with 4 updates by @dependabot[bot] in #4749 chore(deps): bump node from 2d984a1 to ef24c50 by @dependabot[bot] in #4748 chore(deps-dev): bump the development-dependencies group with 4 updates by @dependabot[bot] in #4747 chore(deps): bump the production-dependencies group across 1 directory with 8 updates by @dependabot[bot] in #4750 chore(deps): bump the production-dependencies group with 3 updates by @dependabot[bot] in #4744 v7.8.3 Released on September 1st, 2026 fix #4687 : Avoid naughty pdf uploaders by @ildyria. A user could upload a pdf crafted to exhaust the computational power of the server and cause a denial of service. This is now fixed. There was already mitigations in place, but they were not sufficient to avoid this issue. fix #4696 : Fix replay upload in the same chunk by @ildyria. A malicious user with upload access could replay the upload of chunks and subsequently fill the storage of the server without limit. We now ensure that the chunks are processed in order and that the same chunk cannot be uploaded twice. fix #4698 : Avoid email oracle on registration by @ildyria. When regitration page is disabled, a user could still send requests to the endpoint and try url. As the check for the authorization of the request was after the check of uniqueness of the email, an attacker could infer whether the email was used or not. This is now fixed. fix #4700 : Prevent editing pictures if they are not validated yet by @ildyria. When a photo is flagged for moderation, a user could still send a request to put the unvalidated photo as a cover of an album. This is now fixed. v7.8.2 Released on August 30th, 2026 fix #4685 : Fix photo ordering on albums by @ildyria.