Release 3.6.2

Markdown fields and RSS feed settings

5 October 2026

This one's a bigger patch than the number suggests. The headline is two new ways to write in Markdown, plus a round of fixes in the Mailer, Sync, RSS feeds and sign-in — several of them things you told us about. Thank you for the reports.

Write in Markdown, your way

Two new field types store your content as Markdown:

  • Markdown is a source editor. You type Markdown, with a toolbar that inserts the syntax for you, a live preview, and a fullscreen mode that puts the source and the preview side by side. Image and file uploads drop straight in as Markdown.
  • Styled Markdown is the Styled Text editor you already know, but it saves Markdown instead of HTML. Switch to source view whenever you want to see what's underneath.

Both store exactly what you wrote, and both save the same thing, so you can switch a field between them later without touching your content. Render either with the markdown filter.

RSS feeds have moved into collection settings — please read this one

Each collection now has its own RSS Feed card where you set the feed's title, description, which fields become the title, content, date and author, and so on. Feeds are also now off by default: a collection publishes a feed only when you switch it on.

On upgrade, blog and feed collections are switched on for you. Any other collection that had a feed will return a 404 until you turn it on in its settings. If your feed URL used to pass field mappings as parameters, set the same values on the card instead.

Why the change: before 3.6.2, any collection with a URL had a feed, and the feed URL could choose which fields it showed. That let the public read fields you may not have meant to publish. Drafts are now also kept out of every feed, always.

Mailer: Send History and a stack of fixes

A bulk email template now shows its Send History — how many were sent, failed, skipped or are still waiting — so you can see what a send actually did. Alongside it:

  • Proofing a send to your own address no longer blocks the real send afterwards.
  • A scheduled send goes out at the time you picked, in your site's timezone.
  • The hourly and daily send limits count the right hour.
  • The whitelist matches domains exactly and ignores capitalization.
  • Bulk sends now say how many objects were left out because they'd already received the email.

Sign-in is stricter about addresses

Signing in and password reset now match the email address exactly — [email protected] no longer resolves to [email protected]. A failed sign-in says "Invalid login credentials" without revealing whether the account exists. And if you'd rather not show "Keep me signed in", the login form can now hide it.

Also fixed

  • Sync no longer removes the receiving site's files or breaks images inside cards and decks when you push. Both sites need 3.6.2.
  • A file depot could be wiped by creating a folder with an empty name. It can't anymore.
  • Site Builder pages answer HEAD requests, so uptime monitors stop reporting working pages as down.
  • Form dividers, headers and fieldsets hide along with the fields inside them.
  • IndexNow submissions were being rejected with an HTTP 415 — they go through now.
  • Hidden collections that still had public read access from an old default (3.0.41–42) are cleaned up automatically, and password hashes are never sent to a browser or API client under any setting.
  • The new-object form keeps the cursor in the first field — in Safari too.

For the command line

tcms info now reports the site's real domain, edition and license (it used to show "unknown" and "trial" on every install), and lists every cache backend you have. And there's a new tcms check — the admin's Server Checker from the terminal, with an exit code you can use in deploy scripts.

Docs

The license page has been rewritten, the Mailer finally has full documentation, and there's a new guide on versioning your content in git safely.


Upgrading: update as usual from Admin → Updates or composer update. Afterwards, check the RSS Feed card on any collection whose feed you rely on, and if your site reads a collection anonymously through the API, confirm its public access is still what you expect.

The full changelog is on GitHub: https://github.com/totalcms/cms/releases/tag/3.6.2