BookStack logo

BookStack

Simple, self-hosted platform for organising documentation and knowledge

Alternative to: confluence, notion, gitbook


About Versions (100)

v26.05.3

2026-07-29

This security release addresses multiple vulnerabilities including external authentication mismatches, login timing attacks, PDF rendering issues, and API information disclosure.

v26.05.2

2026-07-02

Security release addressing URL filtering, redirect handling, and permission vulnerabilities, alongside dependency updates and the addition of the Serbian language.

v26.05.1

2026-06-09

Security release addressing vulnerabilities related to attachment metadata leaks, file protocol abuse on Windows, and search system errors.

v26.05

2026-05-28

This release introduces a page contents view in the editor, Thai language support, new API endpoints for tags, and separate permission controls for revision viewing.

v26.03.5

2026-05-21

This security release addresses a brute-force vulnerability in multi-factor authentication and updates project libraries to prevent potential vulnerabilities.

v26.03.4

2026-04-30

Security release improving attachment permission checks, webhook URL validation, and fixing a search term negation issue.

v26.03.3

2026-04-05

This release updates translations via Crowdin and refreshes PHP dependency versions.

v26.03.2

2026-03-23

v26.03.1

2026-03-17

This security release fixes a vulnerability where restricted page content could be visible during markdown exports and updates PHP packages.

v26.03

2026-03-15

Introduces a new theme module system, adds several theme events for customization, and updates SMTP HELO domain handling and API endpoints.

v25.12.9

2026-03-12

This security release addresses a vulnerability allowing style code to manipulate page content in revision views and includes dependency updates.

v25.12.8

2026-02-27

This release fixes content filtering issues affecting link target attributes and user references in comments, and updates PHP package versions.

v25.12.7

2026-02-19

Fixed an error occurring when loading the editor for pages with blank content created by different users.

v25.12.6

2026-02-18

Fixes an issue where content filtering rules could make drawio diagrams non-editable.

v25.12.5

2026-02-17

Fixes server filesystem permission issues related to filter caching folder handling introduced in v25.12.4.

v25.12.4

2026-02-17

This security release addresses a style code vulnerability in page content and introduces more aggressive content filtering and a new filtering option.

v25.12.3

2026-01-29

This security release fixes a vulnerability allowing privileged users to be tricked into making API requests and removes most form content from page rendering.

v25.12.2

2026-01-24

This release updates translations via Crowdin and refreshes PHP dependency versions.

v25.12.1

2025-12-30

Security release adding search operation limits and ZIP import size checks to prevent resource abuse, alongside PHP dependency and translation updates.

v25.12

2025-12-24

This release introduces user mentions for comments, slug history tracking, an initial developer API for the new WYSIWYG editor, and various performance and UI improvements.

v25.11.6

2025-12-09

This security release updates PHP dependencies to fix a vulnerability in XML handling that could allow SAML authentication request replays.

v25.11.5

2025-12-03

This release includes fixes for OIDC state handling in Chromium browsers, session history redirects, and updates to PHP dependency versions.

v25.11.4

2025-11-25

This release corrects a versioning error, fixes a comment notification error, and updates PHP dependency versions.

v25.11.3

2025-11-21

This release fixes image access permission issues when using secure storage and updates PHP dependencies.

v25.11.2

2025-11-19

This release includes fixes for image permission checking in ZIP exports, updated translations, test environment improvements, and updated PHP dependencies.

v25.11.1

2025-11-11

Fixes database query errors affecting MySQL versions 5.7 and below.

v25.11

2025-11-09

This release updates the framework to Laravel 12, introduces new API endpoints for comments and image data, adds Groovy syntax highlighting, and implements several database and UI improvements.

v25.07.3

2025-10-05

This release updates translations and PHP packages while fixing PWA manifest access for users behind authenticated proxies.

v25.07.2

2025-08-28

This release improves the WYSIWYG editor, updates translations and PHP dependencies, and fixes issues with ZIP imports and shelf permissions.

v25.07.1

2025-08-11

This release includes translation updates, PHP package upgrades, and fixes for open redirects, ZIP import logout issues, and menu accessibility.

v25.07

2025-07-30

This release introduces a plaintext markdown editor, ZIP import/export API endpoints, an updated WYSIWYG editor for comments and descriptions, and various usability and performance improvements.

v25.05.2

2025-07-07

This release adds the Nepali language, updates translations and PHP packages, improves content diffs for non-ASCII characters, and fixes OpenSearch and test case errors.

v25.05.1

2025-06-17

This release improves the WYSIWYG editor with various media and table fixes, corrects comment notification text, fixes a search system bug, and updates translations.

v25.05

2025-05-31

This release introduces comment section referencing, comment archiving, AVIF image support, a new system info API endpoint, and OIDC avatar fetching.

v25.02.5

2025-05-17

This release fixes image directory permissions, updates translations and PHP packages, and improves system CLI credential and vendor command handling.

v25.02.4

2025-05-08

Updated PHP dependency package versions to resolve compatibility issues with recent libxml versions on some systems.

v25.02.3

2025-05-05

This release includes image permission error handling improvements, export style fixes, updated translations, and PHP dependency updates.

v25.02.2

2025-04-02

This release improves name sorting for accented characters, updates translations and dependencies, and fixes several bugs in the new WYSIWYG editor and comment timestamps.

v25.02.1

2025-03-16

This release adds IPv6 database host support, updates the system CLI with new commands and improvements, updates translations, and refreshes PHP dependencies.

v25.02

2025-02-26

Updates the app framework to Laravel 11, introduces automatic book sorting, improves search indexing, and upgrades the minimum PHP version to 8.2.

v24.12.1

2025-01-04

This release improves export logic and rate limiting, updates translations and PHP dependencies, and fixes a markdown editor focus issue.

v24.12

2024-12-23

Introduces a new portable ZIP import/export format, enhances LDAP attribute support, improves API search results, and updates the WYSIWYG editor.

v24.10.3

2024-11-29

This release includes PHP dependency updates, translation improvements, and bug fixes for Chrome video support, page includes, OIDC handling, and dark mode styling.

v24.10.2

2024-11-13

This security release addresses a vulnerability in PHP dependencies that could allow application configuration manipulation under specific server settings and updates translations.

v24.10.1

2024-11-08

This release includes updates to the System CLI, fixes for the update-url command and user input validation, and improvements to setting categories and translations.

v24.10

2024-10-09

Introduces a new Lexical-based editor, OpenSearch support, expanded search operators, and updated libraries and language support.

v24.05.4

2024-08-29

This security release fixes LDAP group syncing role assignments and resolves a permission vulnerability in the book-show API responses.

v24.05.3

2024-07-14

This release includes translation updates, dependency upgrades, and various fixes for diagrams.net loading, OIDC authentication, image replacement, and code block highlighting.

v24.05.2

2024-06-10

This release includes various bug fixes, updated translations, improved role validation, and optimizations for GIF thumbnail generation.

v24.05.1

2024-05-21

This security release introduces rate-limiting for unauthenticated forms, prevents email existence enumeration, and includes various bug fixes and dependency updates.

v24.05

2024-05-11

This release updates the app framework to Laravel 10, adds command-based PDF exports and OIDC userinfo support, and increases minimum requirements for PHP and Composer.

v24.02.3

2024-04-05

This release fixes issues with the 'Open Link In' option, reference loading from the recycle bin, code block rendering, and page editor content widths.

v24.02.2

2024-03-11

This release addresses missed version and asset changes from v24.02.1.

v24.02.1

2024-03-10

This release includes translation updates, improved breadcrumb ordering, MFA input refinements, and fixes for page navigation and non-breaking spaces.

v24.02

2024-02-28

Introduces a WYSIWYG comment editor, PKCE support for OIDC authentication, and various improvements to the WYSIWYG editor and page templates.

v23.12.3

2024-02-26

This security release addresses a blind server-side-request forgery vulnerability in PDF generation and updates PHP dependencies.

v23.12.2

2024-01-24

This release fixes issues with attachment inline opening and entity selector search pre-filling, and updates translations via Crowdin.

v23.12.1

2024-01-16

This release fixes a missing book_slug field in the chapter API and updates translations via Crowdin.

v23.12

2023-12-29

This release introduces a simple WYSIWYG for description fields, book template options, OIDC RP-initiated logout, and improvements to page include handling and the WYSIWYG editor.

v23.10.4

2023-11-20

This release fixes the application version number as a follow-up to v23.10.3.

v23.10.3

2023-11-20

This security release fixes a vulnerability in image handling that could allow server-side requests or unauthorized file access and corrects missing permission checks during image creation.

v23.10.2

2023-11-07

This release fixes audit log dropdown behavior and manifest endpoint redirects, and updates translations.

v23.10.1

2023-11-02

This release introduces PHP 8.3 support, adds Norwegian Nynorsk language options, and includes several UI fixes and a new JavaScript event for codemirror customization.

v23.10

2023-10-30

This release introduces a new My Account area, a redesigned page editor, basic PWA support, and various UI improvements and bug fixes.

v23.08.3

2023-09-15

This release fixes issues with comment reply notifications, JavaScript permission errors, and updates various translations.

v23.08.2

2023-09-04

This release fixes a WYSIWYG filtering issue that hindered page editing and drawing, and updates translations via Crowdin.

v23.08.1

2023-09-03

This release includes UI improvements to preferences, WYSIWYG editor filtering updates, translation updates, and several bug fixes regarding notifications and documentation.

v23.08

2023-08-30

Introduces a content notification system, browser-based drawing backup storage, and a host allow list for server-side requests alongside various API and UI fixes.

v23.06.2

2023-07-12

This release re-introduces shelf create permissions, fixes delete-based action webhooks, and updates translations.

v23.06.1

2023-07-05

This release updates email TLS configuration, refreshes translations, and fixes bugs related to image timestamps, role page loading, and audit log formatting.

v23.06

2023-06-30

This release introduces visual comment threading, an updated image manager, and accessibility improvements, alongside changes to email encryption and font customization methods.

v23.05.2

2023-05-23

This release includes improvements to the System CLI, multi-file upload support for images and attachments, and updates to code block highlighting and translations.

v23.05.1

2023-05-08

This release includes system CLI improvements, translation updates, and various fixes for the WYSIWYG editor and code block formatting.

v23.05

2023-05-03

This release introduces a system CLI for admin operations, updates the markdown editor to CodeMirror 6, adds nested include tags, and expands API endpoints for image galleries and content permissions.

v23.02.3

2023-04-07

This release includes fixes for user deletion and Safari tag selection, alongside updated translations via Crowdin.

v23.02.2

2023-03-25

This release fixes role deletion errors, resolves user ownership migration issues, and updates translations via Crowdin.

v23.02.1

2023-02-27

This release fixes a language loading issue and updates translations via Crowdin.

v23.02

2023-02-26

This release updates the framework to Laravel 9, introduces user roles API endpoints, and improves the shelf book management interface and editor performance.

v23.01.1

2023-02-02

This security release updates the PDF library to fix a vulnerability allowing server-side requests or PHP code execution, and includes translation updates and a minor icon fix.

v23.01

2023-01-31

This release introduces customizable app icons and dark mode colors, expanded code highlighting, OIDC ID claim configuration, and updates to the permission system.

v22.11.1

2022-12-16

This release adds Smarty and Twig template code language support, updates translations, and fixes issues with global search focus, editor sidebar scrolling, and user role removal.

v22.11

2022-11-30

This release introduces UI shortcuts, global search live previews, expanded language support for code blocks, and updated tabular list views.

v22.10.2

2022-11-02

Updated translations with the latest changes from Crowdin.

v22.10.1

2022-10-21

Fixed an issue with generation permissions when a chapter is in the recycle bin.

v22.10

2022-10-21

This release introduces a redesigned content permissions interface, adds Greek language support and MATLAB syntax highlighting, and includes various UI improvements and bug fixes.

v22.09.1

2022-09-20

This release includes PHPCS for formatting, improved SAML error handling, updated translations, and locale setting fixes for Windows.

v22.09

2022-09-08

Introduces cross-item link reference tracking, OIDC group sync, a new secure image storage option, and updates to revision visibility and limits.

v22.07.3

2022-08-11

This security release implements additional HTML filtering to prevent XSS techniques and updates API and security documentation regarding external content use.

v22.07.2

2022-08-09

This release introduces export template partials, activity recording for revisions, translation updates, and bug fixes for user validation and audit logs.

v22.07.1

2022-08-02

This release fixes a WYSIWYG editor caching issue and updates translations via Crowdin.

v22.07

2022-07-28

This update introduces chapter sorting, WYSIWYG editor enhancements including TinyMCE 6, improved shelf management, and performance optimizations to the permission system.

v22.06.2

2022-06-28

This release includes updated translations and bug fixes for LDAP/SAML2 group mapping and the link selector popup.

v22.06.1

2022-06-25

This release includes bug fixes for tag saving, layout issues in Custom Head settings, and updates to translations and the entity selector popup.

v22.06

2022-06-24

Introduces content conversion tools, auto-initiation for SAML/OIDC login, expanded code editor language support, and various UI and performance improvements.

v22.04.2

2022-05-09

This release adds Persian language support, updates API documentation and translations, fixes attachment downloads and LDAP errors, and updates PHP dependencies.

v22.04.1

2022-05-04

This release fixes a URL double-slash issue causing 404 errors and updates translations via Crowdin.

v22.04

2022-04-29

This release introduces per-page editor switching, new recycle bin API endpoints, improved file streaming for efficiency, and updated URL handling for better stability in sub-path scenarios.

v22.03.1

2022-03-30

This release includes fixes for settings redirects and custom HTML head content, updated translations, and updated PHP dependencies.

v22.03

2022-03-30

Introduces WYSIWYG checkbox tasklists, Basque language support, and a reorganized settings layout, along with various bug fixes and webhook enhancements.

v22.02.3

2022-03-07

This security release introduces an allow-list for embedded iframe sources to prevent malicious content, adding a new ALLOWED_IFRAME_SOURCES configuration option.