Image Editor 7.x-1.x, xxxx-xx-xx (development version)
-----------------------

Image Editor 7.x-1.14, 2026-08-12
-----------------------
- Security: Addresses local file disclosure via an unrestricted cURL at-file upload path in the image upload AJAX callback.- Security: Addresses local file disclosure via an unrestricted cURL at-file upload path in the image upload AJAX callback
- Security: Addresses the insecure default in the Image Editor Inline submodule that allows unauthorized overwriting of arbitrary site images.
- Security: Addresses reflected cross site scripting in the Snipshot and FotoFlexer editor save callbacks.
- Security: Addresses cross-site request forgery in the image upload and inline save AJAX callbacks.

Image Editor 7.x-1.13, 2026-04-29
-----------------------
- Security fix: Server-Side Request Forgery (SSRF) via unvalidated image URLs in editor save callbacks.
