New maintenance releases for the Redmine 7.0, 6.1, and 6.0 series are now available to Download . These releases address multiple security vulnerabilities along with various bug fixes and improvements. Security Fixes All three versions (7.0.1, 6.1.4, and 6.0.11) include the following security fixes: Defect #44249: API requests can affect a user’s session and circumvent security policies Defect #44308: Stored XSS in Redmine Textile Formatter via Tag-Restoration (“Frankenstein tag”) Defect #44309: Nested issue-relations endpoints bypass source issue visibility Defect #44310: Child project inheri