---
title: "Note di rilascio di Django 1.8.14"
version: 6.0
locale: it
source: https://docs.djangoproject.com/it/6.0/releases/1.8.14/
canonical: https://djangodocs.dev/it/6.0/releases/1.8.14/
---
# Note di rilascio di Django 1.8.14

*18 Luglio 2016*

Django 1.8.14 risolve un problema di sicurezza e un bug in 1.8.13.

## XSS in admin’s add/change related popup

Unsafe usage of JavaScript’s `Element.innerHTML` could result in XSS in the
admin’s add/change related popup. `Element.textContent` is now used to
prevent execution of the data.

The debug view also used `innerHTML`. Although a security issue wasn’t
identified there, out of an abundance of caution it’s also updated to use
`textContent`.

## Correzioni di bug

- Fixed missing `varchar/text_pattern_ops` index on `CharField` and
  `TextField` respectively when using `AddField` on PostgreSQL
  ([#26889](https://code.djangoproject.com/ticket/26889)).
