| Name | Modified | Size | Downloads / Week |
|---|---|---|---|
| Parent folder | |||
| FOSSBilling-0.8.8.zip | 2026-10-03 | 30.4 MB | |
| 0.8.8 source code.tar.gz | 2026-10-03 | 10.5 MB | |
| 0.8.8 source code.zip | 2026-10-03 | 11.1 MB | |
| README.md | 2026-10-03 | 7.3 kB | |
| Totals: 4 Items | 51.9 MB | 5 | |
0.8.8 (2026-10-03)
This patch release hardens payment handling, checkout, and session management, and fixes client signup, invoicing, and domain ordering flows. It includes several security fixes, so users should update as soon as possible.
⚠️ Potentially Breaking Changes
- Stored values are no longer HTML-escaped before saving; escaping now happens at the rendering boundary, and a database patch repairs rows that were previously stored double-escaped. Custom themes or modules that pre-escape output, or that rely on stored escaped values, should verify their rendering after updating. (#4307)
🔐 Security
- Bound PayPal payment notifications to their invoice with signed callback URLs, so a genuine payment can no longer be credited to a different invoice by editing the callback. Existing recurring profiles, delayed completions, and refunds keep working.
- Verified Stripe redirect PaymentIntent ownership and currency before applying it, rejecting PaymentIntents minted for another invoice, gateway, or currency. (#4320)
- Validated PayPal IPN currencies, including the newer-flow
amount_currencyalias, rejecting payments whose currency is missing or does not match the invoice before crediting. (#4324) - Restricted gateway cancellations to the stored subscription, ignoring caller-supplied IDs so a crafted update cannot steer a cancellation toward another subscription. (#4336)
- Fixed a once-per-client promo race in checkout so concurrent checkouts cannot redeem a single-use promo more than once. (#4351)
- Fixed client-bound template emails ignoring the client's registered address when a generic recipient was supplied, which could redirect another client's rendered data. (#4347)
- Fixed a reCAPTCHA v3 bypass on fast form submission. (#4280)
- Stopped malformed signup submissions from draining another address's per-email signup quota, recording quota only after client validation succeeds. (#4344)
- Invalidated admin and client sessions when API tokens are rotated, matching the existing password-change behavior. (#4301)
- Fixed session invalidation missing sessions when the identity key is not the first entry in stored session data, and rejected crafted non-string session cookie values before lookup. (#4340)
- Restricted promo redemption history to authorized access, and limited client details exposed in order lists and staff ticket notifications. (#4337, [#4330], [#4326])
- Made the
cron.phpentry point refuse non-CLI execution, closing direct HTTP triggering of the scheduler script. The hash-protected guest cron endpoint (cron/run) remains available when enabled in Cron Settings. Non-entry-point PHP access is also denied in the DDEV nginx config. (#4348) - Protected nested theme configuration directories from direct access. (#4346)
- Removed the installer from production debug deployments so production installs always delete the install directory. (#4322)
- Fixed guest ticket rate-limit ordering, bounded knowledge-base search queries, and bounded domain expiration sync retries. (#4342, [#4341], [#4343])
- Rejected multi-label and overlong punycode (
xn--) SLDs subject to the same checks as other labels, and fixed a quantity validation integer overflow. (#4312, [#4319]) - Rejected private-range results when detecting the server's external IP, so a private address can no longer be adopted as the install's public IP.
- Normalized system setting keys before the permission check so the guard and the setting lookup agree.
- Sanitized unexpected guest API errors instead of leaking internals.
📈 Enhancements
- Showed open hosting plan limits as "Unlimited" instead of "unlimited MB" in plan and service pages. (#4314)
- Allowed domain transfers through the Email and Custom registrars, mirroring each adapter's own availability check with RDAP handling. (#4304)
- Collected transfer codes for hosting domain orders, with guards against stale domain-check responses overwriting the UI. (#4339)
➕ New Features
- Added addon quantity selection: the requested addon quantity is validated against the addon's flag and stored on the addon order, with an order-form quantity input and admin toggles. (#4385)
🐛 Bug Fixes
- Fixed client signup always failing CAPTCHA verification: single-use CAPTCHA tokens were verified twice for genuine registrations, rejecting every signup. Signup now verifies exactly once. (#4265)
- Fixed multi-item cart orders missing from the client order list: only the first cart item was treated as group master, hiding additional orders. (#4335)
- Fixed invoice PDF generation failing when company address lines are unconfigured, and hardened invoice party data against missing keys. (#4311)
- Fixed a
TypeErrorinServer_Manager::getPasswordLength()that was fatal to whole cron runs when stored server configs carried a numeric string. (#4268) - Fixed promo redemption history failing with "Unknown column 'serie_nr'" by building the value from the stored
serieandnrcolumns. (#4279) - Restored the "Allow quantity selection" toggle on the admin product form. (#4282)
- Guarded against a missing nameserver list in Namecheap domain details. (#4285)
- Preserved Plesk credentials during package updates. (#4325)
- Prevented renewal of orders with scheduled cancellations. (#4327)
- Recorded balance transactions for positive invoice credit payments, and compared balances at two-decimal scale so fully funded invoices are not rejected over float rounding. (#4328, [#4329])
- Credited the client balance when an admin marks an Add Funds (deposit) invoice as paid, and stopped deposit line items from being created outside the Add Funds flow. (#4448, [#4449])
- Fixed support tickets crashing for clients without a last name, orphaned service hostings blocking server and plan deletion, gateway-less invoices that could not be marked as paid, PayPal payments stuck on processing from double claims, and automatic hosting activation during checkout.
- Hardened invoice tax math against non-numeric rates so a malformed saved rate no longer fatals invoice reads.
- Kept Tabler
data-tblr-*positioning rules when purging theme CSS so admin navbar dropdown menus open below their toggle. (#4310) - Fixed two PHP warnings on domain pricing for installs missing the
periodscolumn and on invoice-item tax for unset prices. (#4276) - Normalized the Cookie consent navigation label casing and forwarded the suspension reason and details to DirectAdmin on suspend. (#4299, [#4072])
- Handled empty custom-payment IPN data and hardened admin templates and Formbuilder defaults.
- Hardened a range of admin and client pages, update finalization, transaction refunds, and mail sending against missing or null data so affected flows render or fail gracefully instead of crashing.
📝 Changes
- Template-cache write failures (for example, an unwritable
data/cachedirectory) now render a proper error page instead of a raw 500, and are no longer reported as code bugs. (#4276) - Expected cache-backend configuration errors (for example, selecting Redis/Memcached without the PHP extension installed or with wrong connection details) are surfaced as settings-form validation errors rather than reported as bugs. (#4275)