Skip to content

Changelog

FOSSBilling publishes release notes and tagged versions on GitHub. Use the links below to review new features, fixes, and upgrade notes before you update.

GitHub Releases

View all FOSSBilling releases with detailed changelogs on GitHub Releases.

Version History

Browse the complete commit history to see all changes.

For the latest changes, start with the most recent release.

AreaSummary
SecurityRate limiting on guest invoice, PDF, and payment APIs with per-hash and per-IP limits; invoice hash format validated (30–60 hex chars) and hashes expire after configurable period; guest cron endpoint now requires security hash; extension uninstall paths validated against directory traversal; fixed reverse tabnabbing vulnerability in Theme service; password values no longer echoed in login templates
Rate LimitingNew invoice_get_ip, invoice_get_hash, invoice_pdf_ip, invoice_pdf_hash policies; invoice hashes expire by default after 90 days (invoice_hash_lifetime_days)
Email TemplatesBuilt-in syntax validation with error tracking in admin panel; new last_error / error_checked_at columns for tracking rendering failures; bulk actions and batch delete
Payment GatewaysOne-time payment enforcement per gateway; gateway keys required based on operating mode; update readiness checks in gateway settings UI
PerformanceDoctrine ORM metadata now cached on filesystem
UpdatesPre-flight filesystem permission checks before applying updates
WidgetsLogin forms now support widget slots for extension injection
MaintenanceLeftover Paidsupport and Servicemembership module files fully cleaned from disk

View the full 0.8.2 release notes for the complete list of changes.

AreaSummary
SecuritySanitized admin ticket replies, validated downloadable stored filenames, hardened license doc links, prevented subdomain override, refreshed OPcache after config preservation, hardened UpdatePatcher SQL safety
HostingFree subdomain option with duplicate protection
Anti-spamreCAPTCHA v3 score-based bot detection on public forms
Client signupAuto-login after registration; separate last name field
UpdatesTwo-phase update finalization process (install then finalize patches); maintenance mode enabled during updates
ProxyPre-config proxy detection and admin proxy candidate settings UI for reverse proxy setups
Downloadablestored_filename attribute for safer file tracking and orphan cleanup
AdminActive menu highlighting, Massmailer autocomplete test client selector, tab-targeted redirects

View the full 0.8.1 release notes for the complete list of changes.

For older releases, browse the full release history on GitHub.

Before updating, review the release notes for any breaking changes or manual follow-up steps. We call these out in each release whenever they apply.

Security-related changes are also published through our GitHub security advisories. If you run FOSSBilling in production, subscribe to release notifications and security alerts.