{ "canonical_id": "discourse--703d073816", "system_id": "discourse", "display_name": "Discourse", "category": "cms", "advisory_mode": "core", "title": "3.5.0.beta2: Review Queue, Welcome Banner, Admin Interface, and more", "summary": "
We have begun making a series of improvements to the review queue, where moderators can review and handle flagged content.
\nWe have added a new welcome banner feature, to welcome members and allow them to search site content. To turn it on, select the Enable welcome banner site setting.
We continue to make improvements to the admin interface at a rapid pace. Three improvements to highlight:
\nWhen editing your theme\u2019s color palettes (formerly known as color schemes) you can now specify color hex codes in addition to the usual color picker.
\nIf you like to get into your theme\u2019s code to edit HTML and CSS, you will enjoy the newly improved theme editing interface. We hid seldom used fields behind a toggle, added better descriptions, and always display descriptions at the top rather than behind tooltips.
\nThis release includes fixes for these security issues reported by our community and HackerOne.
\n2 posts - 2 participants
\n ", "published_at": "Wed, 26 Mar 2025 02:46:32 +0000", "updated_at": "Wed, 26 Mar 2025 02:46:32 +0000", "severity": "unknown", "cvss_score": null, "exploit_status": "unknown", "source_confidence": "official", "official_source_url": "https://meta.discourse.org/t/3-5-0-beta2-review-queue-welcome-banner-admin-interface-and-more/358151", "secondary_source_urls": [], "aliases": [], "cve_ids": [], "ghsa_ids": [], "osv_ids": [], "affected_versions": [], "fixed_versions": [], "package_name": null, "render_markdown": false, "case_path": null, "secure_code_topics": [ "authz-server-side-recheck", "xss-output-encoding", "plugin-extension-trust-policy", "file-upload-validation", "dependency-upgrade-policy" ], "status": "triage", "triage_reasons": [ "missing affected/fixed version details" ], "verification_status": "triage-manual", "verification_mode": "synthetic", "last_verified_at": null, "last_run_id": null, "evidence_bundle": null, "historical_status": null, "latest_status": null, "browser_evidence": { "required": false, "present": false, "refs": [] }, "repro_profile_id": "xss-generic", "artifact_mode": "synthetic", "blocked_reason": null, "metadata": { "source_names": [ "Discourse Release Notes RSS" ], "source_kinds": [ "rss-feed" ], "candidate_count": 1 } }