Jump to main content Jump to doc navigation

MODX Revolution 2.8.0 (October 2020) focuses on manager security, file handling, and library updates. Read the 2.8.2 / 2.8.3 notes before you install a later 2.8 release.

Release overview: MODX Revolution 2.8.

Before you upgrade

  • Install the latest 2.8.x patch available. Do not stop at 2.8.0.
  • Update Extras, clear core/cache, flush sessions, and back up the database and files.
  • Merge the complete release tree before setup. 2.8.0 fixes a fatal error when upgrading from 2.5.x or earlier, but setup still needs every current core file.
  • List the media sources available to each limited manager user. The new permission checks may remove file access that the user previously had by mistake.

Security and permissions

2.8.0 closes several manager-side stored XSS issues and hardens file operations:

  • Limited manager users can only interact with files in media sources they can access.
  • File upload and file-tree values receive stronger XSS protection.
  • modRestService blocks a potential XXE path.
  • Registry messages block path traversal.
  • Template names are escaped in template and TV access grids.

These fixes affect authenticated manager users. Re-test custom manager pages, file browsers, and ACLs with a non-administrator account.

File and image handling

  • webp joins the default uploadable file and image types.
  • Upload handling checks whether a file already exists and fixes path selection.
  • The login screen gets responsive styles.
  • phpThumb is updated to 1.7.15.

If you maintain a custom upload allowlist, add webp only when the server and your image pipeline support it.

Template Variables and settings

  • URL, RichText, Image, and File TVs gain an Allow Blank option.
  • Listbox (Multi-Select) TVs can accept custom values.
  • System Settings gain a number field type.

Review validation for TVs where an empty value must remain forbidden. The new option makes that rule explicit.

Library updates

2.8.0 updates:

  • xPDO to 2.8.1
  • Smarty to 3.1.36
  • PHPMailer to 5.2.28
  • phpThumb to 1.7.15

Test custom Smarty plugins, mail integrations, and image processing after setup.

After setup

Log in as an administrator and as each limited manager role. Check media source access, uploads, TV validation, resource trash, email delivery, and manager pages supplied by Extras.

Before moving past 2.8.1, read Upgrading to 2.8.2 and 2.8.3. Those releases tighten static-resource paths and permissions and may require configuration changes.

Support the team building MODX with a monthly donation.

The budget raised through OpenCollective is transparent, including payouts, and any contributor can apply to be paid for their work on MODX.

Backers

  • modmore
  • STERC
  • Digital Penguin
  • Jens Wittmann – Gestaltung & Entwicklung
  • CrewMark
  • Fabian Christen
  • Sepia River Studios
  • Dannevang Digital
  • Alex
  • A. Moreno
  • Chris Fickling
  • Stéphane Jäggi
  • Murray Wood
  • Anton Tarasov
  • deJaya
  • JT Skaggs
  • Lefthandmedia
  • eydolan
  • Following Sea
  • Guido Gallenkamp
  • YJ
  • Raffy
  • Snow Creative
  • Nick Clark
  • Guest
  • Helen
  • krisznet
  • Yanni
  • Richard

Budget

$204 per month—let's make that $500!

Learn more