This release includes 1 security fix for security teams reviewing exposed deployments.
Topics
+12 more
Affected surfaces
ReleasePort's take
Moderate signalThe release prevents XSS via event titles in inline script contexts and blocks purchase of hidden products through the public checkout flow.
Why it matters: Mitigates high-severity (severityβ―90) crossβsite scripting risk and stops exploitation of hidden product purchases, directly protecting user data and revenue integrity.
Summary
AI summaryUpdates ποΈ Ticketing & Checkout, π Translations & Localization, and π Security & Privacy across a mixed release.
Changes in this release
| Type | Severity | Summary | CVE |
|---|---|---|---|
| Security | Critical |
Prevented XSS via event titles in inline script contexts Prevented XSS via event titles in inline script contexts Source: llm_adapter@2026-07-16 Confidence: high |
β |
| Feature | Low |
Added Slovak (`sk`) translation and fixed missing strings across all locales Added Slovak (`sk`) translation and fixed missing strings across all locales Source: llm_adapter@2026-07-16 Confidence: high |
β |
| Feature | Low |
Rendered offline payment instruction tokens Rendered offline payment instruction tokens Source: llm_adapter@2026-07-16 Confidence: high |
β |
| Feature | Low |
Prefilled public checkout from URL query params (name, email, optional locking) Prefilled public checkout from URL query params (name, email, optional locking) Source: llm_adapter@2026-07-16 Confidence: high |
β |
| Feature | Low |
Exposed SMTP TLS controls for local relays Exposed SMTP TLS controls for local relays Source: llm_adapter@2026-07-16 Confidence: high |
β |
| Bugfix | Medium |
Prevented purchase of hidden products via public checkout Prevented purchase of hidden products via public checkout Source: llm_adapter@2026-07-16 Confidence: low |
β |
Full changelog
What's Changed
π Translations & Localization
- Added Slovak (
sk) translation and fixed missing strings across all locales by @pipozzz in https://github.com/HiEventsDev/Hi.Events/pull/1210 - Improved French translation by @lionep in https://github.com/HiEventsDev/Hi.Events/pull/1240
ποΈ Ticketing & Checkout
- Prevented purchase of hidden products via public checkout by @daveearley in https://github.com/HiEventsDev/Hi.Events/pull/1259 (Thanks to @0xh3lix for the report.)
- Rendered offline payment instruction tokens by @realicon23 in https://github.com/HiEventsDev/Hi.Events/pull/1235
- Prefilled public checkout from URL query params, including name, email, and optional locking by @skvost in https://github.com/HiEventsDev/Hi.Events/pull/1234
π Security & Privacy
- Prevented XSS via event titles in inline script contexts by @daveearley in https://github.com/HiEventsDev/Hi.Events/pull/1260 (Thanks to @0xh3lix for the report.)
βοΈ Configuration & Infrastructure
- Exposed SMTP TLS controls for local relays by @realicon23 in https://github.com/HiEventsDev/Hi.Events/pull/1244
New Contributors
- @pipozzz made their first contribution in https://github.com/HiEventsDev/Hi.Events/pull/1210
- @lionep made their first contribution in https://github.com/HiEventsDev/Hi.Events/pull/1240
- @skvost made their first contribution in https://github.com/HiEventsDev/Hi.Events/pull/1234
Full Changelog: https://github.com/HiEventsDev/Hi.Events/compare/v.1.10.0-beta...v.1.11.0-beta
Security Fixes
- Prevented XSS via event titles in inline script contexts
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About Hi.Events
Open-source event management and ticket selling platform β perfect for concerts, conferences, and everything in between If you find this project helpful, please consider giving us a star β
Beta — feedback welcome: [email protected]