25. Internationale ILIAS-Konferenz

Download & Releases

9.21 (stable)

General Information

Release 9.21 has been published on July 7, 2026

  • Please read the ILIAS 9 feature page for information about new and abandoned features and changed behaviour of this version.
  • You find information about first time installation of ILIAS 9 and updating here.
  • Please also have a look at the Required Software for ILIAS 9 page.

ILIAS is free, open source software and published under the GNU General Public License (GPL), version 3.0  →  Licence

Download

ILIAS-9.21.zip
Download (github.com)
160 MB, 2026-07-07
md5: 6126db5be1f113cb950b9bce2ea79a8a

ILIAS-9.21.tar.gz
Download (github.com)
145 MB, 2026-07-07
md5: c38e5a299886c30fcada66ab95e390c4

Important Changes

  • System Styles: Custom system styles from 8 and earlier do no longer work
    • With ILIAS 9 the SCSS has been restructered according to the ITCSS structure suggested in the SASS guidelines. In addition, the depencency to less from Bootstrap has mostly been removed. However, the change from less to SCSS and the abandonment from Bootstrap means, that System Styles from 8 and lower are NOT compatible with ILIAS 9. They cannot be imported, be used, or compiled.
    • However, note, that most of the css should still work. Also less and scss are not that far appart. Best read through our SCSS Coding Guidelines to get started.
  • JavaScript Dependencies: Removal of 'node_modules' folder from Git repository
    • The 'npm' dependencies and thus the 'node_modules' folder in the ILIAS root directory were removed from the ILIAS codebase.
    • All 'npm' dependencies will still be automatically added to the release builds (linked on the official ILIAS release pages) on GitHub.
    • With this change 'npm' will become a requirement for ILIAS installations based on Git branches/tags. To install the 'npm' dependencies on such installations, you'll have to execute:

      npm clean-install --omit=dev --ignore-scripts
    • The --omit=dev flag can be ignored for development installations. 
  • Chat Server: Removal of 'node_modules' folder from Git repository
    • The 'npm' dependencies and thus the 'node_modules' folder of 'Modules/Chatroom/chat' were removed from the ILIAS codebase in Git with the integration of PR 5128.
    • All 'npm' dependencies will still be automatically added to the release builds (linked on the official ILIAS release pages) on GitHub.
    • With this change 'npm' will become a requirement for ILIAS installations based on Git branches/tags. To install the 'npm' dependencies on such installations, you'll have to execute:

      npm clean-install --omit=dev --ignore-scripts

      The --omit=dev flag can be ignored for development installations. 
  • Cron Jobs:
  • PDF Generation:
    • wkhtmltopdf has been removed from the code base. 
  • Authentication/SAML:
  • MathJax:
    • Please check if you configured a polyfill url at Administration » Third Party Software » MathJax. This is not needed by modern browsers and IE 11 is no longer supported by ILIAS at all. You should NOT use the polyfill.io library any longer, see https://sansec.io/research/polyfill-supply-chain-attack for details.

Known Issues

  • none

Changed Behaviour

Updated Languages

  • Update of Japanese language support, thanks to Shiro Tamoto from Nagaoka University of Technology

Security Fixes

The following security issues have been fixed. For more information about these vulnerabilities, see our 9.21 security blog post.

#47954: [Notes] Notes: Insufficient access checks
#46642: [Data Collection] Data Collection: Stored XSS with TinyMCE
#47952: [¥ Object] Object: Remove Information on Temp File Location from Error Message
#47887: [SOAP & Webservices] SOAP: Insecure Direct Object Reference (IDOR)
#47800: [Course Management] Stored XSS via HTML attribute injection (André Schweigert ( FAU | ILIAS ))
#47834: [Category and Repository] Add RBAC check for Repository Objects (Franziska Senze)