Bug Tracker

Report a Bug
There are 2036 issues 2036
02405 Report #2405 — not public until reviewed by an administrator.
02404 Report #2404 — not public until reviewed by an administrator.
02403 Report #2403 — not public until reviewed by an administrator.
02402 Report #2402 — not public until reviewed by an administrator.
02401 Report #2401 — not public until reviewed by an administrator.
02400 Report #2400 — not public until reviewed by an administrator.
02399 Report #2399 — not public until reviewed by an administrator.
02398 Report #2398 — not public until reviewed by an administrator.
02397 [ACP Code] TOTP QoL issues
Created: 2026-09-26 10:20:51 / Last Updated: 2026-09-26 10:24:46
02396 [ACP Code] More work on oauth client and server
Created: 2026-09-26 10:16:03 / Last Updated: 2026-09-26 10:18:08
02394 [ACP Code] Stop recording failed email send as a login failure in rate limits
Created: 2026-09-26 08:43:22 / Last Updated: 2026-09-26 08:44:55
02395 [ACP Code] Add lazy cleanup to rate limit logs
Created: 2026-09-26 08:43:45 / Last Updated: 2026-09-26 08:44:19
02392 [Triage] File log viewer: missing quote in data-uid breaks table and user lookup
Created: 2026-09-06 14:57:16 / Last Updated: 2026-09-11 09:47:55
02393 [Plugins] Payments 1.0.5: displayPayment() renders Submit Payment outside its form
Created: 2026-09-06 15:44:41 / Last Updated: 2026-09-11 09:47:34
02391 [ACP Code] UserSpice's random_password() emits passwords its own login form cannot accept. login.php compares htmlspecialchars($_POST['password'], ENT_QUOTES), and User::loginEmail() only retries with the raw string below cost 13 which admin-created users are not. The alphabet contains &, so about one generated password in five was simply unusable
Created: 2026-09-02 13:24:24 / Last Updated: 2026-09-11 09:47:17
02389 [ACP Code] Add UserSpice nonce to <style> tags
Created: 2026-08-31 10:13:59 / Last Updated: 2026-08-31 19:12:46
02390 Report #2390 — not public until reviewed by an administrator.
02388 [ACP Code] Add better cloudflare/proxy awareness and move the proxy ip somwhere smarter and more obvious.
Created: 2026-08-31 09:48:40 / Last Updated: 2026-08-31 10:08:08
02375 [Plugins] No sample file in Hooker plugin
Created: 2026-06-25 19:31:23 / Last Updated: 2026-08-18 09:35:22
02386 [ACP Code] See if we can better detect permission errors on totp_key.php or fail clean
Created: 2026-08-07 13:25:43 / Last Updated: 2026-08-18 09:33:10
02387 [ACP Code] Potential db class change
Created: 2026-08-07 19:05:38 / Last Updated: 2026-08-18 09:13:49
02385 [ACP Code] Allow to set site name/copyright during install so it doesn't get shared with UserSpice the first time. Ask if new reg should be enabled. - A not required but nice to have section
Created: 2026-08-04 10:31:04 / Last Updated: 2026-08-18 08:59:28
02384 [ACP Code] Enable strong force password rules by default....
Created: 2026-08-04 10:09:31 / Last Updated: 2026-08-18 07:20:22
02383 [Triage] users/updates/ applies database migrations without any authentication check
Created: 2026-08-03 07:11:50 / Last Updated: 2026-08-03 08:57:48
02382 [ACP Code] Add null coalescing to the return of function trustedHtml() - Ellie
Created: 2026-07-22 10:41:45 / Last Updated: 2026-07-22 17:55:33