New release is available
What's Changed
Authenticated Remote code execution (CVE-2025-24801)
SQL injection through the rules configuration (CVE-2025-21619)
Open Redirection (CVE-2024-11955)
Exposure of sensitive information in the status.php endpoint (CVE-2025-21626)
Plugins disabled by unauthenticated user (CVE-2025-23024)
Full Changelog: v1.6.9...v1.6.10