Skip to main content.

Interchange News

  • Remote code execution vulnerability patched

    Posted on August 8, 2026

    A critical remote code execution (RCE) vulnerability was found in the “quick question” admin feature. In default installations arbitrary Perl code can be injected and executed server-side by unauthenticated users. The Perl code normally runs within a Safe container which limits the scope of what it ... [more]

  • Interchange Redis Sessions

    Posted on June 16, 2026

    Interchange now supports storing user sessions in Redis, a popular in-memory data store, as a core feature. Sessions are where Interchange keeps client state that makes a catalog operate as a continuous experience—the shopping cart, form values, login status, and other data that persist from one req... [more]

See earlier news about Interchange.

Recent Commits

    See more at the Interchange GitHub project.

    Site Areas

    What Interchange users are saying:

    First and foremost, a web application platform really must be a platform — it must play nicely with all the other things that your marketing and logistics and operations and vendor management groups want to bolt onto it. As such, the platform must be flexible, open, pliable, and also somewhat standardized.

    Moreover, it needs to perform under screaming loads, as well as hold stable under the day-in-​day-out slog of data that come with running a fair-sized web-centric business. Interchange meets all of these requirements.

    We built a $100M+ company using Interchange both as a customer-​facing web application suite as well as the the back-office web-based logistics platform for our buyers, marketers, and warehouse operations.

    The Open Source outlook of Interchange, along with its Perl architecture, brings the needed flexibility and continuity throughout the app. A competent and experienced developer can take Interchange and make it sing.

    Dave Jenkins, CTO at Backcountry.com

    See other endorsements of Interchange.