Bug Tracker

Report a Bug
There are 2038 issues 2038
02407 Report #2407 — not public until reviewed by an administrator.
02305 [ACP Code] check on database-navigation.php for 5.8.4 to 6.0 upgrades
Created: 2026-03-19 19:43:57 / Last Updated: 2026-09-29 10:58:04
02392 [Triage] File log viewer: missing quote in data-uid breaks table and user lookup
Created: 2026-09-06 14:57:16 / Last Updated: 2026-09-29 10:57:19
02391 [ACP Code] UserSpice's random_password() emits passwords its own login form cannot accept. login.php compares htmlspecialchars($_POST['password'], ENT_QUOTES), and User::loginEmail() only retries with the raw string below cost 13 which admin-created users are not. The alphabet contains &, so about one generated password in five was simply unusable
Created: 2026-09-02 13:24:24 / Last Updated: 2026-09-29 10:51:04
02398 [Triage] totp_verification.php can cause a fatal error by trying to instantiate TOTPHandler on PHP < 8.2
Created: 2026-09-27 23:14:00 / Last Updated: 2026-09-29 10:46:32
02399 [Triage] socialLogin() function does not handle exceptions from User::create()
Created: 2026-09-27 23:14:06 / Last Updated: 2026-09-29 10:34:51
02400 [Triage] logins counter is incremented twice during socialLogin() flows
Created: 2026-09-27 23:14:11 / Last Updated: 2026-09-29 10:31:40
02401 [Triage] Login database records (last_login, logins counter) updated regardless of TOTP success
Created: 2026-09-27 23:16:17 / Last Updated: 2026-09-29 10:26:55
02402 [Triage] malformed HTML structure breaks the "Mark All Users as Verified" feature
Created: 2026-09-27 23:27:34 / Last Updated: 2026-09-29 10:22:20
02403 [Triage] login counter is incremented twice during a successful TOTP login
Created: 2026-09-28 01:03:15 / Last Updated: 2026-09-29 10:19:41
02406 [ACP Code] Added some extra hardening around logging metadata in admin logs view (UniBrain/Kratos)
Created: 2026-09-29 09:51:36 / Last Updated: 2026-09-29 10:18:04
02404 [Triage] Sessions are incorrectly marked as re-authenticated after password validation before TOTP verification
Created: 2026-09-28 01:04:26 / Last Updated: 2026-09-29 10:15:52
02405 [Triage] Plugin installation fails on fresh deployments
Created: 2026-09-28 01:05:19 / Last Updated: 2026-09-29 10:02:27
02397 [ACP Code] TOTP QoL issues
Created: 2026-09-26 10:20:51 / Last Updated: 2026-09-26 10:24:46
02396 [ACP Code] More work on oauth client and server
Created: 2026-09-26 10:16:03 / Last Updated: 2026-09-26 10:18:08
02394 [ACP Code] Stop recording failed email send as a login failure in rate limits
Created: 2026-09-26 08:43:22 / Last Updated: 2026-09-26 08:44:55
02395 [ACP Code] Add lazy cleanup to rate limit logs
Created: 2026-09-26 08:43:45 / Last Updated: 2026-09-26 08:44:19
02393 [Plugins] Payments 1.0.5: displayPayment() renders Submit Payment outside its form
Created: 2026-09-06 15:44:41 / Last Updated: 2026-09-11 09:47:34
02389 [ACP Code] Add UserSpice nonce to <style> tags
Created: 2026-08-31 10:13:59 / Last Updated: 2026-08-31 19:12:46
02390 Report #2390 — not public until reviewed by an administrator.
02388 [ACP Code] Add better cloudflare/proxy awareness and move the proxy ip somwhere smarter and more obvious.
Created: 2026-08-31 09:48:40 / Last Updated: 2026-08-31 10:08:08
02375 [Plugins] No sample file in Hooker plugin
Created: 2026-06-25 19:31:23 / Last Updated: 2026-08-18 09:35:22
02386 [ACP Code] See if we can better detect permission errors on totp_key.php or fail clean
Created: 2026-08-07 13:25:43 / Last Updated: 2026-08-18 09:33:10
02387 [ACP Code] Potential db class change
Created: 2026-08-07 19:05:38 / Last Updated: 2026-08-18 09:13:49
02385 [ACP Code] Allow to set site name/copyright during install so it doesn't get shared with UserSpice the first time. Ask if new reg should be enabled. - A not required but nice to have section
Created: 2026-08-04 10:31:04 / Last Updated: 2026-08-18 08:59:28