# Discourse 2.3.0.beta8 Release Notes

**URL:** https://meta.discourse.org/t/discourse-2-3-0-beta8-release-notes/113788
**Category:** Announcements
**Tags:** release-notes
**Created:** [April 8, 2019, 6:55pm UTC](https://meta.discourse.org/t/discourse-2-3-0-beta8-release-notes/113788 "2019-04-08T18:55:34Z")
**Posts on this page:** 1
**Page:** 1

<div class="post-metadata">

### Author: ![jomaxro](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/jomaxro/32/126216_2.png) [@jomaxro](https://meta.discourse.org/u/jomaxro)
#### Post date: [April 8, 2019, 6:55pm UTC](https://meta.discourse.org/t/discourse-2-3-0-beta8-release-notes/113788/1 "2019-04-08T18:55:34Z")

</div>

# New features in 2.3.0.beta8

_beta8 is a security update to beta7 released Friday_

This beta includes 1 security fix for issues reported by our community and [HackerOne](https://hackerone.com/discourse).

- Remove XSS in composer preview when applying image scale buttons.

### Even more!

But wait, there’s more! We do our best to highlight new features and changes for you, but there’s always too many changes to detail. For a full list of new features, bug fixes, UX improvements, and more, be sure to review the Additional Features and Fixes listed below.

### Additional Features and Fixes

> **Click to expand**
>
> ### New Features
> 
> ### Bug Fixes
> 
> - Sometimes queued post would have a string for a category
> - Queued Posts were not saving tags properly
> - ‘currentUser’ is a property of the ‘widget’
> 
> ### UX Changes
> 
> - Only highlight close icon on hover, not lock
> - Add “consecutive” to visit badge short descriptions
> - Better close button positioning in alerts, some cleanup
> - Show tags on flags too
> 
> ### Performance
> 
> - Use joins for `Post.for_mailing_list` instead of `NOT IN`.
