Blog · publishing since 2008
From the source.
Release announcements, version previews, security advisories, and the occasional detour — written by the team building Blesta.
New for Developers in 3.1
Blesta 3.1 for developers: a non-interactive CLI installer, config.json for plugins, modules, and gateways, nearly a dozen new events, and an updated API.
Security Advisory - Cross-site scripting vulnerabilities
Cross-site scripting advisory for Blesta 3.0.0 through 3.0.6: client, admin, and Support plugin interfaces render content unsanitized. Fixed in 3.0.7.
Blesta 3.1: Beta Released
Blesta 3.1 beta 1 is now available to license holders in the client area, with a 30-day free trial for new installs. Try it and share feedback on the forums.
Security Advisory - Plugin vulnerabilities
Plugin XSS advisory: the System Overview and Feed Reader plugins in Blesta 3.0.0 through 3.0.4 render content unsanitized. Fixed in the 3.0.5 patch.
30-day free trial · No credit card · Your server
Read enough. Run it.
Everything on this blog ships in the box. Full product, free for 30 days, on your own server.