MediaWiki 1.31.14
12 April 2021
MediaWiki version 1.31.14 is now available (security release).
Upgrading to MediaWiki 1.31.14
MediaWiki 1.31.14 can be upgraded to (or installed) using any of Installatron's products. Use Installatron's optional Automatic Update feature to automatically apply MediaWiki updates as new versions are released, or use Installatron's Clone feature to duplicate an existing MediaWiki install to test the 1.31.14 upgrade prior to applying it live. Get started managing your MediaWiki installations with Installatron
What's New in MediaWiki 1.31.14
1.31.14
Bug Fixes
- The 1.31.14 version fixes an issue with the backports in the 1.31.13 release.
1.31.13
Security
- Escape mediastatistics-header-* messages on Special:NewFiles.
- Allow user to only apply protection they have right to do so via action=protect.
- Non-admin deleted enwiki page in fast double move.
- ContentModelChange: Check that user can create pages.
- SyntaxHighlight_GeSHi: Various lexers have been disabled due to DoS vectors.
- Allow blocked users to access Special:ResetTokens.
- Escape rcfilters-filter-* messages on ChangesList pages.
Changes
- resourceloader: CSSMin::getLocalFileReferences now strips anchors.
- Updating php-parallel-lint/php-parallel-lint (0.9.2 => 1.0.0).
- Updating mediawiki/codesniffer (19.1.0 => 19.4.0).
- DefaultSettings.php: Update $wgPingback documentation.
- PHPVersionCheck: The PHP Group only supports PHP >= 7.3.0.
- Escape wikitext in the title in invalid title error messages.
- pageExist.php: Output trailing newlines.
- HTMLFormField: Use non namespaced class name rather than static::class.
- Switch to new MediaWiki logo by Serhio Magpie.
- Expand config-pingback-help, link to privacy policy in config-pingback.
- Fix documentation of user-global in $wgRateLimits.
- BackupDumper: Add -o as shortcode for --output.