9.5.4 arrives faster than usual, and that's on us. Two bugs shipped in 9.5.3 that shouldn't have.
Concrete CMS 9.5.4 Is Available
What 9.5.3 Broke
Dragging and dropping pages in the sitemap threw an invalid token error, so reordering your site tree just didn't work. Attributes wouldn't save through the composer panel. Both are fixed. If either of those has been driving you up a wall for the past few days, this is your release.
Two more 9.5.3 problems while we're at it. Rescan Locale was stripping every content block page link and crashing on stack pages, and the mail service was still encoding From and Subject headers on the dashboard logs page. Fixed and fixed.
Security
Five advisories closed, the highest rated 7.7. We also tightened SVG sanitization checking on upload. Details and risk rankings are in the release notes.
Smaller Improvements
Test mail settings now shows the email sender and links out to the relevant configuration pages instead of leaving you to hunt for them. The SEO bulk report stopped rescanning paths for every single page it lists, which makes a real difference on big sites. Express object dashboards return an actual error on validation failure rather than a 500, and delete_entries() has the permission check it should have had all along. Translate Site Interface can save to file on a non-default site without complaining about an invalid language identifier.
On the developer side, the documented types on attribute value objects are correct now, and some vestigial code is gone.
Getting It
SaaS hosting is already updated. Self-hosted sites can grab it from concretecms.org or update through Composer. The full 9.5.4 release notes have every change.
Patrick, J. (n.d.). Painted bunting [Photograph]. U.S. Fish and Wildlife Service. Public domain. https://www.fws.gov/media/painted-bunting