What's Changed
- security: Escape
ImageColumnandImageEntryURLs by @danharrin in #19885 - security: Temporary file uploads available on auth pages by @danharrin in #19886
- security: Prevent user enumeration on login page by @danharrin in #19887
- security: Prevent 2FA concurrent recovery code reuse by @danharrin in #19891
- Improve Str::sanitizeUrl to reject malformed javascript URLs by @ukeloop in #19892
Full Changelog: v4.11.4...v4.11.5