NUKEVIET 4.6.02
- Fix reflected XSS via double URL decoding of search keyword in news module (CVE-2026-94599). Thanks Thế from GitHub @Pbat6
- DOMPurify v3.4.15
- Fix stored XSS via internal marker injection in iframe srcdoc (CVE-2026-94598). Thanks Thế from GitHub @Pbat6
- Fix RCE via image upload bypass chain (CVE-2026-94597). Thanks CAN QUANG HIEU from GitHub @canhieu
- Fix a security vulnerability in the SVG file upload (CVE-2026-94567). Thanks Nguyễn Huy Hoàng from GitHub @hoanggxyuuki
- Fix SSRF vulnerabilities in the upload functions, the Image class, and sitemap ping. Thanks canhieu from GitHub @canhieu.
- Fix dangerous functions accessible via the GET method. Thanks archnexus707 from GitHub @archnexus707
- Fix a security vulnerability in the module language write functionality. Thanks phuongmai1212 from GitHub @phuongmai1212 and AuQuangDuc from GitHub

NUKEVIET 4.6.01
- Fix XSS in class Request. Thanks mrlihd from GitHub @mrlihd
- Select2 v4.1.0, DOMPurify v3.4.13.
- guzzlehttp/guzzle v7.15.2
- Fix numeric-entity leading-zero bypass in Request XSS sanitizer. Thanks Mai Đăng Khoa from GitHub @dkoazw
- Restrict users custom field callback to prevent RCE. Thanks Nguyễn Hồng Giáp from GitHub @PinkArmor
- Fix pre-auth SSRF via spoofed Host header in set_ini_file server info request. Thanks prat1kz from GitHub @prat1kz
- Fix arbitrary file write via S/MIME certificate CN in SMTP settings. Thanks Jace from GitHub @manus-use
- Fix a permission issue when changing comment status
- Prevent SSRF DNS rebinding in Files\Upload URL import

NUKEVIET 4.6.00
- Fixed an issue where figure tags were removed from tables in the editor.
- Updated the password hashing and cookie encryption mechanisms
- Use CSPRNG (random_int) for TOTP and nv_genpass security tokens
- Fix second-order SQL injection in users sql_choices custom field
- Harden deserialization and TLS verification across the system
- Fixed issues related to HTML popovers
- Fix PHP code injection in robots.php via unfiltered filename keys
- Update guzzlehttp/guzzle 7.12.1, guzzlehttp/psr7 2.12.1
- Refactor nv_check_dump_path function to enhance file extension validation and improve directory checks
- Fixed an issue where some valid uploaded images were incorrectly blocked
- Require PHP >=7.4.00

NUKEVIET 4.5.08
- Remove abandoned package true/punycode
- Remove the and/oauth package, which has long been unmaintained, and replace it with league/oauth2-client
- Remove SDK of social network like/share button tools and replace with pure HTML/JS
- Fix XSS bug. Thanks Nguyễn Quang Bằng from WhiteHub#4394
- Support PHP 8.5
- Add a strict permission-checking mode for uploading application packages #3910
- Prevent CKEditor 5 UI buttons from triggering parent form submission #3916
- Fix CSS content conflicts between CKEditor 4 and CKEditor 5
- Fix voting popup
- Ckeditor 5 v47.6.2
- Jquery UI v1.14.2
- DOMPurify 2.5.9 and 3.4.0

NUKEVIET 4.5.07
- CKEditor 5 v47.0.0 and remove CKEditor 4
- PDF.js 3.11.174
- Fix warning error in nv_is_image function when checking webp files
- Fix download database backup files during upgrade
- Add feature to force re-login when editing account in admin area
- Adjust the explanation for the "Developer Mode"
- Fix the error in viewing attachments in the module news
- Add custom block position feature
- Add http_response_code before trigger_error
- Fix banner module error when installing a new language
- Improved source display in the admin panel of the news module
- Improve the configuration for inserting logos into images
- Fix the error in counting article views
- Improved article review workflow in the news module
- Fix password reset issue when using Recaptcha 3
- Enhance the permission system for the Zalo module
- Jquery UI 1.14.1
- Update the versions of Composer libraries
- DOMPurify 3.2.7 and 2.5.7
- Remove function searchKeywordforSQL