Please rate how useful you found this document:
Release Date: August 4th, 2026
This document contains release notes for ProcessMaker 3.9.11. Release Notes are cumulative, and document bug fixes and improvements associated with this release unless otherwise noted. A list of older ProcessMaker Release Notes is included at the end of this document.
Improvements
ProcessMaker 3.9.11 includes the following improvement:
- Added an environment variable to control session hijacking validation, providing administrators with greater flexibility when managing security behavior in supported environments.
- Added
disable_hijacking_verification, set to0by default. - Setting the value to
1disables session hijacking validation.
- Added
Bug Fixes
ProcessMaker 3.9.11 includes the following bug fixes:
- Custom plugin validation messages no longer expose server file paths, and longer error details remain readable long enough for administrators to review why a plugin import was blocked.
- Code Scanner whitelist validation now displays the correct error message for trigger code that contains methods or functions not included in
whitelist.ini, including the affected name and line number.
Previous Release Notes
Refer to the previous Release Notes from ProcessMaker versions 3.2 through 3.9.8:
- 3.9.8
- 3.9.6
- 3.9.5
- 3.9.4
- 3.9.3
- 3.9.2
- 3.9.1
- 3.9.0
- 3.8.3
- 3.8.2
- 3.8.1
- 3.8.0
- 3.7.7
- 3.7.6
- 3.7.5
- 3.7.4
- 3.7.3
- 3.7.2
- 3.7.1
- 3.7.0
- 3.6.5
- 3.6.4
- 3.6.3
- 3.6.2
- 3.6.1
- 3.6.0
- 3.5.11
- 3.5.10
- 3.5.9
- 3.5.8
- 3.5.7
- 3.5.6
- 3.5.5
- 3.5.4
- 3.5.3
- 3.5.2
- 3.5.1
- 3.5.0
- 3.4.11
- 3.4.10
- 3.4.9
- 3.4.8
- 3.4.7
- 3.4.6
- 3.4.5
- 3.4.4
- 3.4.3
- 3.4.2
- 3.4.0
- 3.3.17
- 3.3.16
- 3.3.15
- 3.3.14
- 3.3.13
- 3.3.12
- 3.3.11
- 3.3.10
- 3.3.9
- 3.3.8
- 3.3.7
- 3.3.6
- 3.3.5
- 3.3.4
- 3.3.3
- 3.3.2
- 3.3.1
- 3.3.0
- 3.2.4
- 3.2.3
- 3.2.2
- 3.2.1
- 3.2

