major

TableComponent: ConfigKey should be customizable
User-specified CSS classes cannot override default numeric alignment in table columns
JSON Schema Support for Typed Configuration
Multi-factor authentication and self-service account management

minor

Upload/update workflows at application startup
No fixed reference to tl-build-processor in tl-parent-build
TreeGrid Modelbuilder API: Node predicate does not get component model

nice-to-have

Making REST client JSON parser robust against empty content

critical

Unwanted row objects in tables with changes from other sessions
XSS vulnerability in /jsp/openapi/server/displayAPISpec.jsp

major

Security issues in the UMLJS project
Accounts with reused contact have no authorization
Filters of dynamic columns ignore the attribute type
Error in column filter for double values
StackOverflowError when rolling back in the transaction monitor
JavaDoc-based I18N generation ignores custom ResKey in I18NConstants

minor

Modelleditor swallows classification with a less-than sign in the name
Reference to missing files in subsession.jsp
Immutable/Disbled Boolean fields accessible/focusable via tab
Unnecessary space for inline tables
Pointless scroll bar in the help editor
TL-Script: format() with null input returns IllegalArgumentException
Missing replacement of KnowledgeItem by ObjectKey in Collections in Queries
"SafeHTML not started" error with scripted tests
A calculated attribute of the type "General search expression" cannot return a closure
Abstract attributes can be accessed in transient objects
The form data of a component cannot be accessed in a value transformation of a component channel
After changing the model, calculated attributes that have become invalid can no longer be edited
API key in REST interface configuration is not hidden
Incorrect access to the D&D cache in the browser
Values of a composition attribute cannot be edited if previously used in the same form
Error when restarting the KnowledgeBase
Update minimatch and serialize-javascript to fix CVE-2026-27903, CVE-2026-27904, and GHSA-5c6j-r48x-rmvq
Eclipse error after dependency update: maven-jar-plugin 3.5.0 causes "outside of a scoping block" error in m2e

major

Filters of dynamic columns ignore the attribute type

minor

Unnecessary space for inline tables
Pointless scroll bar in the help editor
Incorrect access to the D&D cache in the browser
Values of a composition attribute cannot be edited if previously used in the same form

critical

Unwanted row objects in tables with changes from other sessions

major

Accounts with reused contact have no authorization
Multi-factor authentication and self-service account management
JavaDoc-based I18N generation ignores custom ResKey in I18NConstants

minor

Upload/update workflows at application startup
Abstract attributes can be accessed in transient objects
Error when restarting the KnowledgeBase