Skip to content

BookStack

v26.05 Feature

This release adds 5 notable features for engineering teams evaluating rollout.

Published 6d Productivity & Wikis
✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →

✓ No known CVEs patched in this version

Topics

bookstack documentation laravel php self-hosted wiki

Affected surfaces

auth rbac

Summary

AI summary

Broad release touches Full List of Changes, Links, Upgrade Notices, and https://foss.video/w/gy87ixrPn61DpWGWbCVTp7.

Changes in this release

Feature Low

Added page contents view to page editor.

Added page contents view to page editor.

Source: llm_adapter@2026-05-28

Confidence: high

Feature Low

Added API endpoints for browsing tags.

Added API endpoints for browsing tags.

Source: llm_adapter@2026-05-28

Confidence: high

Feature Low

Added custom font load handling for default PDF renderer.

Added custom font load handling for default PDF renderer.

Source: llm_adapter@2026-05-28

Confidence: high

Feature Low

Added in-UI option to reset user multi-factor authentication methods.

Added in-UI option to reset user multi-factor authentication methods.

Source: llm_adapter@2026-05-28

Confidence: high

Feature Low

Added specific permission for revision viewing.

Added specific permission for revision viewing.

Source: llm_adapter@2026-05-28

Confidence: high

Feature Low

Added new image and CSS CSP controls.

Added new image and CSS CSP controls.

Source: llm_adapter@2026-05-28

Confidence: high

Feature Low

Added Thai language support.

Added Thai language support.

Source: llm_adapter@2026-05-28

Confidence: high

Bugfix Medium

Fixed misaligned link attachment validation rules.

Fixed misaligned link attachment validation rules.

Source: llm_adapter@2026-05-28

Confidence: high

Bugfix Medium

Fixed non-ascii character issues in headers on PDF exports.

Fixed non-ascii character issues in headers on PDF exports.

Source: llm_adapter@2026-05-28

Confidence: high

Refactor Low

Updated codebase to meet PHPStan Level 4.

Updated codebase to meet PHPStan Level 4.

Source: llm_adapter@2026-05-28

Confidence: high

Full changelog

Links

Upgrade Notices

  • Folder Permissions - Due to some changes in how fonts are used for exports, after updating you may need to ensure that the storage/fonts folder (and all folders within that) are accessible & writable by the web-server. If you start seeing errors on PDF export after updating, it's likely this issue. See this page for guidance on setting permissions.
  • Revision Access - Revision access & visibility is now controlled separately to pages. In some cases, after upgrading, users may no longer be able to access revisions by default (for example, where users had access to view page content but had no role-level view permissions).

Full List of Changes

  • Added page contents view to page editor. (#6131, #4218)
  • Added API endpoints for browsing tags. (#6095, #5835)
  • Added custom font load handling for default PDF renderer. (#6109, #148, #719, #5770)
  • Added in-UI option to reset user multi-factor authentication methods. Thanks to @clauvaldez. (#6056)
  • Added hints to sort rule selection alongside empty lists. (#5967)
  • Added specific permission for revision viewing. (#6108, #4526)
  • Added new image and CSS CSP controls. Thanks to @Zhey-on. (#6071, #6033)
  • Added Thai language support. (#6105)
  • Updated codebase to meet PHPStan Level 4. (#6085)
  • Updated comment/description WYSIWYG editor to support inline code. (#6100, #6003)
  • Updated HTML to plain text conversion handling. (#6083)
  • Updated image upload handling to validate referenced page. (#6126)
  • Updated JavaScript packages. (#6090)
  • Updated module install command with usability improvements. (#6094, #6066)
  • Updated new WYSIWYG editor with a range of fixes. (#6119, #5631)
  • Updated translations with latest Crowdin changes. (#6084)
  • Fixed misaligned link attachment validation rules. (#6093)
  • Fixed non-ascii character issues in headers on PDF exports. Thanks to @alexwoo-awso. (#6069, #6107)

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track BookStack

Get notified when new releases ship.

Sign up free

About BookStack

A platform to create documentation/wiki content built with PHP & Laravel

All releases →

Related context

Related tools

Beta — feedback welcome: [email protected]