PrivateBin logo

PrivateBin

Share text snippets securely

Alternative to: Pastebin


About Versions (43)

2.0.6

2026-08-08

This release improves security by implementing stricter MIME type validation to prevent XSS and updates dependencies and error handling.

2.0.5

2026-07-11

This release fixes security vulnerabilities related to unsafe attachment rendering and JSON API responses, alongside general bug fixes and UI improvements.

2.0.4

2026-05-03

Adds Swedish and Persian translations; deduplicates and refactors translation and exception messages; upgrades libraries; removes X-XSS-Protection header; fixes: some exceptions not translated, attachment disappearing after paste, and content format not reset on new document.

1.7.9

2025-11-13

Upgrades libraries (base-x, bootstrap, DOMPurify, ip-lib, kjua), rewrites DOM creation in plain JS, and fixes security issues (template-switching file inclusion, malicious filenames/self-XSS, sanitization) with guidance to upgrade to 2.x.

2.0.3

2025-11-12

Fixes for: preventing arbitrary PHP file inclusion via template switching (CVE-2025-64714), sanitizing filenames to prevent self-XSS/HTML injection during drag-and-drop (CVE-2025-64711), and enabling new paste creation from clones when a JSON attachment is present (#1585).

2.0.2

2025-10-28

Upgrades DOMpurify to 3.3.0, refactors DOM creation to plain JS, fixes filename sanitization in attachment size hints (CVE-2025-62796) and makes PHP OPcache optional again, plus bootstrap template password peek display; addresses file-name sanitation per advisory.

2.0.1

2025-10-12

Adds auto URL shortening (default config), new shortenviashlink endpoint with shlink config, and password peek; updates Bootstrap 5.3.8, DOMPurify 3.2.7, ip-lib 1.21.0; fixes paste/decrypt, copy shortened links, CSP frame-ancestors, URL extraction, and opcache traffic limiter.

2.0.0

2025-07-28

This release switches default template to bootstrap5, uses Jdenticons, displays data sizes in SI units, renames pastes to documents, removes page template and pre-v1.3 compatibility, requires PHP 7.4, and drops unused columns; the v2 format remains.

1.7.8

2025-06-30

Fixed duplicate attachments per comment, fixed attachments with empty filenames, and corrected page template scripts loading order.

1.7.7

2025-06-28

1.7.6

2025-02-01

Adds copy-to-clipboard via icon/shortcut, enables Ctrl+M/Esc tab navigation, switches to WASM streaming with wasm-unsafe-eval CSP (requires application/wasm MIME), updates to str_starts_with/str_contains with polyfills, buttonized paste delete, library upgrades, Bootstrap5 UI tweaks, and fixes language redirect.

1.7.5

2024-11-16

Adds non-persistent SQL connections and a delete-paste alert redirect button; UI/footer tweaks; simpler PostgreSQL lookup; configurable SRI hashes; library upgrades (DOMpurify, ip-lib, cloud-storage, aws-sdk-php); fixes numeric array key casting under strict mode.

1.7.4

2024-07-09

Release improves markdown saving extension to .md, enables strict PHP typing, tweaks bootstrap5, fixes password field, allows DB upgrade skipping versions, stabilizes dark mode toggle, and blocks YOURLS proxy URL bypass per security advisory.

1.7.3

2024-05-13

Changed: several tweaks to the bootstrap5 template per community feedback; Upgraded libraries to DOMpurify 3.1.3; Fixed: expiration selection not applied when using the bootstrap template (#1309).

1.7.2

2024-05-05

Caution: do not update to this release due to a critical bug; changes include allow shorten via query params, input sanitation, optional Bootstrap 5 template, label change to 'Create', PHP 7.3 min, library updates, API tweaks, and CSP guidance.

1.7.1

2024-02-11

Fixed the wasm file reference for zlib 1.3.1.

1.7.0

2024-02-11

Adds Romanian translations and damaged-paste detection; prompts before loading burn after reading pastes; improves modal password focus; upgrades DOMPurify 3.0.8 and zlib 1.3.1; fixes URL shorteners (incl. IDN), language-URL, email TZ overlap, and needless reload.

1.6.2

2023-12-15

Fixed English not selectable when languageselection is enabled; fixed SRI mismatch caused by a cached file change.

1.6.1

2023-12-04

Adds Right-To-Left (RTL) support for Arabic and Hebrew and upgrades DOMPurify to version 3.0.6.

1.6.0

2023-09-11

Adds Japanese & Arabic translations, makes the Email button configurable (enabled by default), raises the minimum PHP version to 7.3 due to PHPUnit upgrade, and drops the PHP 5 random_bytes polyfill.

1.5.2

2023-07-09

This release enables S3 to use the AWS default credentials provider chain, updates DOMpurify and jQuery with security fixes, fixes PHP 8.2 deprecations, and exposes JSON-LD types in the API.

1.5.1

2022-12-24

This release reverts the filesystem purge to a limited randomized lookup, adds an administration script for managing pastes and statistics, handles JSON decode errors, and updates GCS/S3 libraries.

1.5.0

2022-12-11

Adds S3 storage backend, a data-migration script, four new translations, Jdenticons for comments, updated libraries, removes SUPER privilege for sql_mode, and improved index handling with YOURLS proxy integration.

1.4.0

2022-04-09

This release improves SVG attachment preview safety, adds Google Cloud Storage and Oracle database backends, and expands translations (Corsican, Estonian, Finnish, Lojban).

1.3.5

2021-04-05

This 1.3.5 release fixes numerous issues, adds Hebrew, Lithuanian, Indonesian and Catalan translations, updates libraries, makes project info configurable, and opens links in new windows by default.

1.3.4

2020-03-22

Release 1.3.4 fixes HTML entity encoding, enables custom email expiration options, fixes pasting password with attachments, updates identicon to 2.0.0, and raises minimum PHP to 5.6.

1.3.3

2020-02-16

Fixes HTML entity double-encoding from 1.3.2, expands server-side XSS protection, updates DOMPurify to 2.0.8, and refreshes translations.

1.2.3

2020-02-16

This release fixes HTML entity double-encoding from 1.3.2/1.2.2, strengthens server-side XSS protection, and updates DOMpurify to 2.0.8.

1.3.2

2020-01-11

This release patches a persistent XSS via attachment filenames, fixes HTML injection, upgrades libraries (base-x, DOMpurify, Showdown), and advises upgrading 1.3/1.3.1/1.2/1.2.1; backport is available for older browsers.

1.2.2

2020-01-11

Fixes a persistent XSS through unescaped attachment filenames; updates core libraries (Bootstrap, DOMPurify, jQuery, kjua, Showdown, SJCL) and recommends upgrading 1.3/1.2 series; backport is available for legacy browsers.

1.3.1

2019-09-22

Release 1.3.1 enhances error messaging for unsupported browsers, adds Bulgarian translation, UI improvements for drag-and-drop/file upload and URL shortener, increases default size limit to 10 MiB, updates libraries, and patches numerous stability fixes.

1.3

2019-07-09

This release switches to browser WebCrypto and zlib wasm for crypto/compression, enables blob-based attachments up to >2 MiB, fixes URL/paste mangling (Facebook/Outlook), adds Czech translation, and introduces config options (compression, httpwarning) with broader security/compatibility updates.

1.2.1

2018-08-11

This release re-enables legacy browser support and fixes the low-entropy key vulnerability in PrivateBin prior to 1.2, ensuring keys have sufficient entropy; legacy support will be dropped in 1.3, and a new signing key is used.

1.2

2018-07-22

This release adds QR code generation, inline display of videos, audio and PDFs, new translations, and a major JavaScript refactor with modularization and property-based tests, plus library upgrades and a new site name option.

1.1.1

2017-10-10

This release fixes a data leak by converting configuration and paste data from INI/JSON to PHP files, protecting against exposure on non-Apache setups (or when AllowOverride is disabled), with automatic conversion on next access.

1.1

2016-12-26

Adds Italian and Russian translations; fixes XSS in raw markdown pastes and automatic purging of non-expiring pastes when using the database store; introduces a loading message and a Dockerfile, and updates CSP headers.

1.0

2016-08-25

PrivateBin 1.0 is the renamed ZeroBin release with major security upgrades (AES-GCM, CSP, SRI, new random sources), code quality and UI/template updates, new translations, optional URL shortener, preview, auto-purge, and compatibility options.

0.22

2016-07-09

Adds tab input, dark

0.21.1

2016-07-09

Minor release fixes DB model metadata loss and mobile navbar on load, adds a meta column to the paste table, and widens the Bootstrap template navbar on large screens. Please update if you use the DB model.

0.21

2016-07-09

Adds German/French/Polish translations, optional file upload/image display, Markdown support, a compact bootstrap template, responsive fixes; switches to generic formatter_options with defaultformatter (plaintext) and deprecates syntaxhighlighting; major zerobin.js refactor; new wiki pages.

0.20

2016-07-09

Adds password-protected pastes, extensive config options (highlighting, password, discussions, expiration, rate limits), JSON-only retrieval, and a Bootstrap-based template; burns-after-reading now occurs post-decryption, discussion toggle refined, numerous option fixes, library upgrades, and improved docs.

0.19

2016-07-09

Fixed XSS vulnerability and spacing issues in IE<10; other browsers unaffected.

0.18

2016-07-09

Adds auto-copy URL after Send, 53-language syntax highlighting, 5-minute/1-week expirations, Raw text button, library upgrades (jQuery, sjcl, base64.js), fixed local dates, robot meta tags, improved JSON checks, cache-busting asset versions, and burn-after-reading moved to a separate checkbox.