# JoomClub > Independent English-language publication covering the Joomla CMS: security > advisories, releases, extensions, and practical guides for building and > running Joomla sites. Technical guidance targets Joomla 6. Content is free to read and quote with attribution and a link to the source article. Article pages are server-rendered: no JavaScript is required to read them, and the same HTML is served to every client. --- # Joomla 6.1.3 and 5.4.8 address core security issues Section: News URL: https://joomclub.net/news/joomla-6-1-3-and-5-4-8-address-core-security-issues Published: 2026-08-18 Joomla administrators should update to `6.1.3` or `5.4.8`, which address ten Core security issues alongside routine fixes and improvements across the two supported series. The security work covers several areas that affect site administration and extension-facing functionality. The listed issues include response header injection in download views, improper CORS origin validation, inconsistent or improper ACL checks in webservice and batch-copy operations, XSS through schema.org outputs, an MFA authentication bypass, schema.org contact-data injection, and unrestricted SHTML uploads. - All ten security entries are attributed to `Core` and are identified by the project as `20260801` through `20260810`. - The maintenance changes also cover menu editing, date and time validation, update-server error messages, nested components, global check-in, article options, division-by-zero errors, language handling, path traversal checks in `com_templates`, Smart Search, and site-offline behavior. Administrators can obtain installation and update packages from the [Joomla 6 downloads page](https://downloads.joomla.org/cms/joomla6/) and the [Joomla 5.4.8 downloads page](https://downloads.joomla.org/cms/joomla5/5-4-8). The project recommends testing upgrades on a copy of the production site first. Joomla `5.4.x` receives bugfix patches until 13 October 2026 and security patches until 12 October 2027. For developers planning the move from Joomla `5.4.x` to `6.x`, the project says this is an upgrade rather than a migration. Extension compatibility depends on removing deprecated code or using the Behaviour 6 - Backward Compatibility Plugin, so extensions should be checked before deployment. Published by the [Joomla Project](https://www.joomla.org/announcements/release-news/joomla-6-1-3-5-4-8-security-bugfix-release.html). --- # Akeeba releases Grafida desktop client for Joomla Section: News URL: https://joomclub.net/news/akeeba-releases-grafida-desktop-client-for-joomla Published: 2026-07-31 Akeeba has introduced Grafida, a desktop client for managing Joomla content outside the browser. The Windows, MacOS and Linux application supports an unlimited number of sites, but its stated incompatibility with Windows 11 Home may limit its reach among potential users. Grafida is designed to bring Joomla content work into a standalone desktop application. Its editor uses TinyMCE, including the familiar workflows for uploading images and other media. The application also declares support for working with AI. Content can be drafted while offline and synchronised with Joomla after the connection is restored. This allows work to continue without Wi-Fi, including while travelling or in other places without an internet connection. The application is available through GitHub. It was developed by Akeeba, a Greek Joomla development studio. The project is referenced in an announcement on Akeeba’s website, a blog post by Joomla co-founder Brian Teeman, and the application’s GitHub releases page. ## Windows 11 Home limitation At the time of the source post, the project documentation stated: `This software does not work on Windows 11 Home.` The post links this limitation to Windows 11’s stricter software publisher certificate checks, while noting that disabling those checks may allow the application to run. This is a practical concern for a desktop tool intended for general users, who may not be prepared to change operating-system security settings. The limitation also highlights the importance of continued maintenance for tools intended to become part of a Joomla publishing workflow. No version number or release date was provided in the source material. --- # Joomla 6.1.1 and 5.4.6 fix security issues across core Section: News URL: https://joomclub.net/news/joomla-6-1-1-5-4-6-security-bugfix-release Published: 2026-05-26 Joomla 6.1.1 and 5.4.6 are now available, bringing 20 security fixes alongside bug fixes and usability improvements for sites running the 6.x and 5.x series. Administrators should treat these as maintenance updates, particularly because the security work covers cross-site scripting, cross-site request forgery, SQL injection, local file inclusion, path traversal, authentication bypasses and privilege escalation. The fixes affect several areas of the core, including `com_associations`, `com_contenthistory`, `com_finder`, `com_tags`, `com_config`, `com_media`, `com_users`, `com_scheduler` and sample data plugins. The release also addresses access-control problems, cache-key construction, transport encryption downgrades and filtering issues in the Framework. Alongside the security changes, the update improves accessibility, administration and developer-facing behaviour. Changes include fixes for calendar filters, version previews, article publishing fields, fullscreen TinyMCE, API application errors, update-archive cleanup and several template and language issues. All `5.4` bug fixes are also up-merged into `6.1`. Joomla 5.4.x remains supported with bugfix patches until 13 October 2026 and security patches until 12 October 2027. Sites moving from Joomla 5.4.x to Joomla 6.1.1 should test on a copy first and check extension compatibility; the project says this is an upgrade rather than a migration, with the Behaviour 6 - Backward Compatibility Plugin available where needed. Published by the [Joomla Project](https://www.joomla.org/announcements/release-news/joomla-6-1-1-5-4-6-security-bugfix-release.html). --- # Joomla 6.1 and 5.4.5 released Section: News URL: https://joomclub.net/news/joomla-6-1-and-5-4-5-released Published: 2026-04-14 Joomla 6.1, codenamed Nyota, introduces new tools for spam protection, publication workflows, custom media fields and module history. Joomla 5.4.5 is also available with fixes for recursion, date and timezone handling, and field-display logic. The two releases address different needs within the Joomla ecosystem. Joomla 6.1 expands core functionality, while Joomla 5.4.5 provides a maintenance update for sites remaining on the 5.x series. ## What changes in Joomla 6.1 - **Proof-of-Work CAPTCHA:** Joomla now includes a spam-protection mechanism that does not require an API or an external service. - **Visual Workflow:** publication workflows can be represented through interactive diagrams. - **Media fields:** Custom Fields gain support for audio, video and document content. - **Module versioning:** module changes can now be tracked through a version history. These additions extend Joomla’s built-in administration and content-management capabilities without relying on separate services for the new CAPTCHA option. ## Fixes in Joomla 5.4.5 The 5.4.5 update resolves a recursion issue affecting `loadposition` and `loadmodule`. It also corrects date and timezone handling in the Media Manager and fixes the logic used to display fields with `ShowOn`. Joomla sites adopting the new functionality can move to 6.1, while installations staying on the 5.x branch can update to 5.4.5 for these maintenance fixes. The releases therefore provide both a feature-focused update and a stability update for existing deployments. --- # Joomla 6.1 adds workflows, media fields and spam protection Section: News URL: https://joomclub.net/news/joomla-6-1-adds-workflows-media-fields-and-spam-protection Published: 2026-04-14 Joomla 6.1, also known as Nyota, is now available with new tools for spam protection, content workflows, media fields and module management. The Joomla project has released `Joomla 6.1`, the latest minor version in the Joomla 6 series. The update includes more than 130 pull requests and brings several changes that will affect both site administrators and extension developers. - `Proof-of-Work CAPTCHA` returns as a privacy-friendly, invisible spam protection option. It requires neither an account nor an API and silently solves mathematical puzzles in the visitor’s browser. - The new `Visual Workflow Editor` provides an interactive diagram of the publication process, making content pipelines easier to inspect and manage. - `Media Custom Fields` now support audio, video and documents, rather than being limited to images. - Modules gain version history, while multilingual sites can associate module instances across languages in the same way they associate articles. Administrators running `Joomla 6.0.4` with automatic updates enabled will be updated automatically to `6.1.0`. Automatic updates support patch and minor updates from `5.4` and `6.0` onwards, but major-version changes still require a manual backend update or an external tool. Downloads are available as the full package and as an upgrade package. Developers can also review the feature-related pull requests in the Joomla 6.1 milestone before testing the release on a production site. Published by the [Joomla Project](https://www.joomla.org/announcements/release-news/joomla-6-1-is-here.html). --- # Joomla 6.1 adds workflow tools and broader media fields Section: News URL: https://joomclub.net/news/joomla-6-1-adds-workflow-tools-and-broader-media-fields Published: 2026-04-14 Joomla 6.1 [Nyota] is now available, bringing new tools for spam protection, content workflows, media fields and module management to sites running the Joomla 6 series. The latest minor release is aimed at both site administrators and extension-aware content teams. It includes more than 130 pull requests, with changes spanning everyday editorial and site-management tasks. - `Proof-of-Work CAPTCHA` returns as a privacy-friendly, invisible challenge that requires no account or API and works by solving background maths puzzles. - The new `Visual Workflow Editor` provides an interactive diagram of the publication process, making complex content pipelines easier to understand and manage. - `Media Custom Fields` now support audio, video and documents in addition to images, giving content creators more ways to attach media to content. - Version history is now available for modules, while multilingual sites can associate module instances across languages in the same way they associate articles. Administrators with automatic updates enabled on `6.0.4` will be updated automatically to `6.1.0`. Automatic updates support patch and minor updates from `5.4` and `6.0` onwards, but major-version changes still require a manual update in the backend or an external tool. The project provides both a full package and an upgrade package for the release. Published by the [Joomla Project](https://www.joomla.org/announcements/release-news/joomla-6-1-is-here.html). --- # Joomla 5.4.5 tidies media, forms and content plugins Section: News URL: https://joomclub.net/news/joomla-5-4-5-media-forms-content-plugin-fixes Published: 2026-04-14 Joomla 5.4.5 is a bugfix release for the 5.x series, addressing issues in content plugins, the Media Manager, custom fields, forms and editor styling. Site administrators can install Joomla 5.4.5 as an update package on existing Joomla 5 sites, while new installations can use the full packages. The release contains a focused set of fixes rather than new major features. - Recursion is prevented in the `loadposition/loadmodule` plugin, and `onContentPrepare` handling is fixed in `mod_articles`. - The `Media Manager` now avoids double timezone conversion in file dates, and its rotate-angle input no longer resets to zero. - Custom-field `ShowOnRule` regular-expression handling is corrected, while required modal category fields are highlighted properly after validation errors. - `TinyMCE` now loads non-minified custom CSS when a minified version is unavailable. - Additional changes address RTL/LTR corner-radius consistency, duplicate subform-field warnings, association template paths and documentation wording. Extension developers and site teams should review the changes and test affected editing, media and form workflows after updating. Joomla provides full and update packages through its [download page](https://downloads.joomla.org/cms/joomla5/5-4-5), while the complete change list is available on [GitHub](https://github.com/joomla/joomla-cms/milestone/160?closed=1). Published by the [Joomla Project](https://www.joomla.org/announcements/release-news/joomla-5-4-5-bugfix-release.html). --- # Joomla 5.4.5 fixes editor, media and form issues Section: News URL: https://joomclub.net/news/joomla-5-4-5-fixes-editor-media-and-form-issues Published: 2026-04-14 Joomla 5.4.5 is a bugfix release for the 5.x series, with corrections spanning media handling, editor styling, custom fields, module events and form validation. The Joomla project published `5.4.5` on 14 April 2026. Administrators running the 5.x series can choose a full package for a new installation or an update package for an existing site from the official download page. The changes include fixes for: - Recursion prevention in the `loadposition/loadmodule` plugin. - Double timezone conversion in `Media Manager` file dates and a reset issue affecting rotate-angle input. - RTL/LTR corner-radius handling in `Media Manager`. - `onContentPrepare` handling in `mod_articles`. - Regular-expression matching in `ShowOnRule` for custom fields. - Loading non-minified custom CSS in `TinyMCE` when no minified file exists. - Validation highlighting for required modal category fields. The release also adds a warning when duplicate subform fields are removed during saving and corrects documentation and template-path details. Developers and site owners can review the complete change list on GitHub before testing the update in their normal deployment process. Download options are available at the Joomla CMS downloads site. Published by the [Joomla Project](https://www.joomla.org/announcements/release-news/joomla-5-4-5-bugfix-release.html). --- # Joomla 6.1 RC3 puts the final package in testers’ hands Section: News URL: https://joomclub.net/news/joomla-6-1-rc3-final-package-testing Published: 2026-04-13 The Joomla project has published Joomla `6.1` Release Candidate 3, giving site builders and extension developers a final pre-release package to test before the planned stable release on or about 14 April 2026. Release Candidate 3 is intended for testing rather than production use. Administrators can use it to explore Joomla `6.1`, while developers should check their extensions and report problems before general availability. The project also points testers to nightly builds for the latest development packages and launch.joomla.org for a free test website. No further features are expected at this stage. The sole change listed for this candidate adds dispatcher support to the `jooa11y` plugin. Joomla `6.1` is also under a language freeze, meaning changes to language files will generally not be merged unless they are essential, such as fixes for critical bugs. The project is asking the community to focus on testing and bug reporting through issues.joomla.org. Extension developers are particularly encouraged to test compatibility and share their findings. Documentation contributions for Joomla `6.1` are also welcomed on manual.joomla.org. - Release Candidate 3: 13 April 2026 - Planned stable release: 14 April 2026 - Production use: not recommended for this candidate Known backward compatibility issues are documented on the Joomla documentation site, giving developers another reference point while reviewing their extensions. Published by the [Joomla Project](https://www.joomla.org/announcements/release-news/joomla-6-1-release-candidate-3-test-the-final-package.html). --- # Joomla 6.1 RC2 asks extension developers to test Section: News URL: https://joomclub.net/news/joomla-6-1-rc2-extension-developers-test Published: 2026-04-07 The Joomla project has published Release Candidate 2 for Joomla 6.1, giving site builders and extension developers a final opportunity to test compatibility before the planned stable release on 14 April 2026. Joomla 6.1 Release Candidate 2 is a test build rather than an update for production websites. The release candidate is intended to help developers validate their extensions and allow users to explore the changes already planned for Joomla 6.1. No new features are expected at this stage. The project has entered a language freeze, so changes to language files will generally be limited to critical fixes. Testing and bug reporting are now the main priorities. - Download the release candidate and test it in a non-production environment. - Check extensions and report problems through the Joomla issue tracker. - Review the documented backward compatibility issues for Joomla 6.1. - Help improve developer documentation on manual.joomla.org. Developers who want the latest build can use the nightly packages, while newcomers can create a free Joomla 6 test website through launch.joomla.org. The stable release is scheduled for 14 April 2026, although the project notes that timing can change. Published by the [Joomla Project](https://www.joomla.org/announcements/release-news/joomla-6-1-release-candidate-2-test-the-final-package.html). --- # Joomla 6.1 RC is ready for extension testing Section: News URL: https://joomclub.net/news/joomla-6-1-release-candidate-extension-testing Published: 2026-03-31 The Joomla project has published the `Joomla 6.1` Release Candidate, giving site builders and extension developers a final opportunity to test compatibility before the planned stable release. The Release Candidate is intended for testing rather than production use. Developers can use it to check extensions against the committed `Joomla 6.1` changes, while site owners can explore the update in a non-production environment. At this stage, the project says no new features will be added. The language freeze is also in effect, so changes to language files will only be merged when absolutely necessary, such as to address a critical bug. - Download the latest build through the Joomla release candidate package or use the nightly build packages, which are updated every night. - Launch a free Joomla 6 testing website at [launch.joomla.org](https://launch.joomla.org). - Report problems through [issues.joomla.org](https://issues.joomla.org). - Review and improve the `Joomla 6.1` documentation on [manual.joomla.org](https://manual.joomla.org). Extension developers are particularly encouraged to test their products, report defects and share their experience. The planned general-availability release is on or about 14th April 2026, although the schedule may change. Published by the [Joomla Project](https://www.joomla.org/announcements/release-news/joomla-6-1-release-candidate-test-the-final-package.html). --- # Joomla 6.0.4 and 5.4.4 address six security issues Section: News URL: https://joomclub.net/news/joomla-6-0-4-and-5-4-4-address-six-security-issues Published: 2026-03-31 Joomla 6.0.4 and 5.4.4 are now available with six security fixes, alongside bug fixes affecting administration, web services, media, workflows and scheduled tasks. The Joomla project released `6.0.4` for the Joomla 6.x series and `5.4.4` for Joomla 5.x. Site administrators should treat both as maintenance updates, particularly because the releases address access control, injection, cross-site scripting and file deletion issues. - ACL hardening in `com_ajax` - SQL injection in the `com_content` articles webservice endpoint - An XSS vector in the `com_associations` comparison view - XSS vectors in article title outputs - Arbitrary file deletion in `com_joomlaupdate` - An improper access check in webservice endpoints The maintenance work also resolves administrator sidebar icon flashing, PHP warnings in the Page Break modal, scheduled tasks stopping after a stuck task, media editing controls, workflow permission warnings and several calendar, editor, asset and article display problems. Developers should also note fixes to email validation and extension-related update handling. Joomla 5.4.x sites can move to Joomla 6.x through an upgrade rather than a migration, but the project advises testing on a copy of the production site first. Extension compatibility still needs checking; the Behaviour 6 - Backward Compatibility Plugin may be required for some extensions. Joomla 5.4.x receives bugfix patches until 13 October 2026 and security patches until 12 October 2027. Published by the [Joomla Project](https://www.joomla.org/announcements/release-news/joomla-6-0-4-5-4-4-security-bugfix-release.html). --- # Interim TinyMCE Firefox fix available for Joomla 5 and 6 Section: News URL: https://joomclub.net/news/interim-tinymce-firefox-fix-joomla-5-6 Published: 2026-02-27 An official interim patch is available for a TinyMCE blinking problem affecting content editing in Firefox on Joomla 5.4.3 and 6.0.3. The fix replaces two JavaScript files and is scheduled to become part of the next Joomla release. The issue appears while editing content with the TinyMCE editor in Firefox, where the editor interface may visibly flicker. The workaround is intended for sites running the affected Joomla versions and can be applied before the permanent change reaches a Joomla release. ## Files and installation path The patch is hosted in the [tinymce-firefoxfix GitHub repository](https://github.com/brianteeman/tinymce-firefoxfix). The download must match the Joomla version installed on the site. After extracting the archive, the following files should be uploaded: - `tinymce.js` - `tinymce.min.js` Both files replace the existing versions in: `/media/plg_editors_tinymce/js` The version requirement is important because the workaround is provided for the corresponding Joomla release. Using a fix intended for a different version may not be appropriate, so the downloaded files should be checked before replacement. The repository contains the official patch that is expected to be included in the next Joomla release. Until that release is available, replacing the TinyMCE files provides the interim correction for the Firefox blinking behaviour reported on Joomla 5.4.3 and 6.0.3. --- # Joomla 6.0.3 and 5.4.3 address bugs across the CMS Section: News URL: https://joomclub.net/news/joomla-6-0-3-and-5-4-3-address-bugs-across-the-cms Published: 2026-02-17 The Joomla project has released `Joomla 6.0.3` and `Joomla 5.4.3`, two bugfix updates for the `5.x` and `6.x` series. The releases improve reliability across administration, multilingual handling, installation and development dependencies. For administrators, the updates resolve several backend and content-management problems. Changes include a fix for an ignored language variable in `Multilingual`, improved language-cache error handling, a correction for a broken articles table, and a fix for incorrect URLs in the “Content: New Article Submitted” email template. The release also prevents errors when a `ListView` lacks a filter form. Developers will find updates affecting extension installation, forms and compatibility with newer PHP versions. The `Adapter` install routine now uses the current manifest, `Cassiopeia` font-size validation has been extended, and a PHP 8.5 null-access deprecation warning has been addressed. Updates to `NPM` and `Composer` development dependencies also resolve audit warnings and reported security vulnerabilities in the development toolchain. There is also a known issue involving Firefox version `148`, released on 24 February 2026, where the `TinyMCE` editor can flicker and load content indefinitely. The project provides an installable hotfix for affected users. Sites running `Joomla 5.4.x` do not need to upgrade immediately: bugfix support continues until 13 October 2026, with security patches scheduled until 12 October 2027. Those planning to move to `Joomla 6` should test on a copy of production first and verify extension compatibility. Published by the [Joomla Project](https://www.joomla.org/announcements/release-news/joomla-6-0-3-and-5-4-3-bugfix-release.html). --- # Joomla 6.0.2 and 5.4.2 address security bugs Section: News URL: https://joomclub.net/news/joomla-6-0-2-and-5-4-2-address-security-bugs Published: 2026-01-31 The Joomla project has released `6.0.2` and `5.4.2`, addressing two security issues, fixing bugs across the CMS and adding full support for `PHP 8.5`. Both releases contain fixes in `Joomla! Core` for inadequate content filtering affecting data URLs and an XSS vector in the `pagebreak plugin`. The announcement does not assign severity ratings or CVE identifiers to either issue, but site administrators should plan to install the update through the normal Joomla update process. The `6.0.2` update also improves several areas of the administrator and front-end experience. Changes include corrected menu toggle start-level handling, improved deep-submenu display, a fix for `tinyMCE` dark mode, better handling of broken language-file caches and fixes for email-to-Punycode conversion. Updates to `Cassiopeia Extended` address button hover colours and missing front-end translations. Dependency audit fixes are included as well. Joomla sites running `5.4.x` can move to the `6.x` series as an upgrade rather than a migration, provided extensions are compatible. The project recommends testing on a copy of the production site first and checking extension readiness. Support for the `5.4.x` branch continues with bugfix patches until 13 October 2026 and security patches until 12 October 2027. Published by the [Joomla Project](https://www.joomla.org/announcements/release-news/joomla-6-0-2-5-4-2-security-bugfix-release.html). --- # mySites.guru reports 19 Joomla extension vulnerabilities Section: Security URL: https://joomclub.net/security/mysites-guru-reports-joomla-extension-vulnerabilities Published: 2026-08-24 mySites.guru says it found 19 vulnerabilities in 17 Joomla extensions during June and July 2026, including five rated CVSS 10.0. The research identifies security problems in several widely used Joomla products. The named issues include an authentication bypass in `Gridbox`, customer invoice exposure and forged-order attacks in `EasyStore`, and multiple vulnerabilities in `SP Page Builder`, including pre-authentication SQL injection, an open mail relay and unauthenticated remote code execution. - `Phoca Cart`: front-end SQL injection - `JEM`: five reported issues, with no stable fix available when the article was published mySites.guru says it privately notified each vendor before disclosure. The article does not provide CVE identifiers or affected and fixed version numbers for the issues listed here, and it does not report whether the vulnerabilities are being actively exploited. Administrators should check the relevant vendors’ security notices, update affected extensions when fixes are available, and review exposure where no stable patch has been released. Originally reported by [mySites.guru](https://mysites.guru/blog/summer-2026-new-features/). --- # miniOrange OAuth Client flaw enables Joomla account takeover Section: Security URL: https://joomclub.net/security/miniorange-oauth-client-flaw-enables-joomla-account-takeover Published: 2026-08-24 A critical flaw in the miniOrange OAuth Client extension for Joomla allows unauthenticated account takeover, including access to administrator accounts. Research published by mySites.guru says the extension trusts a cookie value supplied by the visitor when identifying the logged-in account. Changing that value can therefore grant access to another user without credentials or prior access. The vulnerability is tracked as `CVE-2026-77995` and classified as CWE-287, improper authentication. The Joomla CNA rates it CVSS 10.0, Critical. The report does not identify active exploitation in the wild. - Affected: `miniOrange OAuth Client` versions `1.0.0` through `3.1.9` - Fixed: `3.2.0` and later - Vendor: miniOrange Administrators should update the extension on every affected Joomla site. If an immediate update is not possible, disable or remove it until a fixed release can be installed. Sites that previously ran a vulnerable version should also be checked for unfamiliar administrator or Super User accounts and suspicious activity in Joomla and server logs. Originally reported by [mySites.guru](https://mysites.guru/blog/miniorange-oauth-joomla-account-takeover/). --- # Fabrik 4.7.2 fixes 16 Joomla vulnerabilities Section: Security URL: https://joomclub.net/security/fabrik-4-7-2-fixes-16-joomla-vulnerabilities Published: 2026-08-22 Fabrikar has released Fabrik 4.7.2 for Joomla, addressing 16 CVE-listed vulnerabilities that include unauthenticated remote code execution, SQL injection and arbitrary file upload. Research published by mySites.guru says every Fabrik release below `4.7.2` should be treated as affected. The Joomla CNA published records for all 16 issues; 15 credit mySites.guru as the finder. Four carry the maximum CVSS score of 10.0, while seven are rated Critical overall. The disclosure does not report confirmed exploitation. The affected extension is `Fabrik` for Joomla, from Fabrikar. The issues include path traversal, directory listing, access-control failures, row and comment disclosure or manipulation, and a heredoc breakout. The CVEs are: - `CVE-2026-76571`, `CVE-2026-76596`, `CVE-2026-76597`, `CVE-2026-76598`, `CVE-2026-76600`, `CVE-2026-76601`, `CVE-2026-76602`, `CVE-2026-76603`, `CVE-2026-76604`, `CVE-2026-76605`, `CVE-2026-76606`, `CVE-2026-76607`, `CVE-2026-76608`, `CVE-2026-76609`, `CVE-2026-77027` and `CVE-2026-77992`. Administrators should download the newest `4.7.2` package directly from fabrikar.com and reinstall it even when the site already shows that version, because the release was reissued under the same version number. Joomla 3 sites cannot install Fabrik 4; there is no patched Fabrik 3 release. Check logs and files for signs of compromise after updating. Originally reported by [mySites.guru](https://mysites.guru/blog/fabrik-4-7-2-security-release/). --- # JEM Joomla extension flaws await stable fix Section: Security URL: https://joomclub.net/security/jem-joomla-extension-flaws-await-stable-fix Published: 2026-08-22 Multiple security issues in JEM, the Joomla Event Manager component, affect versions below 5.0.1, including stable 5.0.0. The most serious allows anonymous article overwrites and publication, while a stable fix is not yet available. Research published by mySites.guru identified five CVE-assigned issues in JEM (`com_jem`), maintained by the JEM Community. The flaws include improper authorization, reflected and stored cross-site scripting, insufficient access control for attendee data, and an authenticated file-write issue. The advisory also describes event and venue takeover by registered users. The highest-impact issue permits an unauthenticated visitor to overwrite and publish a Joomla article linked to an event. The source does not provide official CVSS scores; the CVE records were reserved but unpublished when the advisory appeared. It also says no working exploits were released. - Affected: every JEM version below `5.0.1`, including stable `5.0.0`. - Assigned identifiers: `CVE-2026-77034`, `CVE-2026-77035`, `CVE-2026-77989`, `CVE-2026-77990` and `CVE-2026-77991`. - Fixed version: `5.0.1`, currently available only as a release candidate. Administrators should restrict or disable front-end event and venue editing, limit attendee-list access to event managers, and avoid deploying the release candidate on production sites. Check installed versions and apply stable `5.0.1` as soon as it is released. Originally reported by [mySites.guru](https://mysites.guru/blog/jem-joomla-event-manager-disclosure/). --- # YOOtheme ZOO flaws fixed in version 4.1.64 Section: Security URL: https://joomclub.net/security/yootheme-zoo-flaws-fixed-version-4-1-64 Published: 2026-08-19 YOOtheme has fixed three unauthenticated vulnerabilities in its ZOO Joomla extension, including a critical file-upload flaw that can lead to remote code execution. The issues affect `com_zoo` versions 1.0.0 through 4.1.63. mySites.guru published the research and reported that the flaws were demonstrated on a live test installation, rather than inferred solely from code. - `CVE-2026-74803`: arbitrary file upload leading to remote code execution, CVSS 10.0, CWE-434. - `CVE-2026-74804`: unauthenticated SQL injection, CVSS 9.3, CWE-89. - `CVE-2026-75114`: unauthenticated open redirect, CVSS 5.1, CWE-601. YOOtheme released the fix in ZOO `4.1.64` on 19 August 2026. Administrators should update every installation to that version or later, including sites without a front-end submission form, because the SQL injection does not require one. Sites running the 3.x branch remain within the affected range, but no 3.x security release is available. Administrators should plan a move to 4.x or remove the extension. After updating, inspect `images/zoo/uploads/` and other image directories for unexpected PHP or other non-image files, and investigate any signs of compromise. Originally reported by [mySites.guru](https://mysites.guru/blog/zoo-unauthenticated-file-upload-rce/). --- # Critical SQL injection fixed in Joomla iCagenda module Section: Security URL: https://joomclub.net/security/critical-sql-injection-fixed-in-joomla-icagenda-module Published: 2026-08-17 A critical, unauthenticated SQL injection affects the iCagenda Calendar module for Joomla, with administrators urged to update to version 4.0.12. The Joomla project’s CVE Numbering Authority published `CVE-2026-67365` on 14 August 2026. The issue affects the Calendar module, `mod_icagenda_calendar`, shipped with the iCagenda events extension from vendor JoomliC (icagenda.com). mySites.guru reported that the flaw is a CWE-89 SQL injection reachable through Joomla’s `com_ajax` endpoint without an account, session or token. The official CVSS 4.0 score is 9.2, rated Critical. The advisory does not publish an exploit; it credits Joep van Antwerpen of Onvio as the finder. - Affected: iCagenda `4.0.0` through `4.0.11` - Fixed: `4.0.12` and later Administrators should update the iCagenda package and confirm that the Calendar module itself reports `4.0.12`. The module version may remain at `4.0.7` on packages up to `4.0.11`, so checking only the component version can be misleading. If an immediate update is impossible, unpublish or uninstall the Calendar module as a temporary measure. Originally reported by [mySites.guru](https://mysites.guru/blog/icagenda-calendar-module-sql-injection/). --- # Sourcerer 14.0.0 fixes critical Joomla code execution flaw Section: Security URL: https://joomclub.net/security/sourcerer-14-0-0-fixes-critical-joomla-code-execution-flaw Published: 2026-08-17 Regular Labs has released Sourcerer 14.0.0 to address a critical Joomla vulnerability that could execute PHP from unverified or reflected content. The affected extension is `Sourcerer`, available in Free and Pro editions from Regular Labs. CVE-2026-74253 affects versions `1.0.0` through `13.1.1` and is fixed in `14.0.0`, released on 17 August 2026. The issue is classified as improper control of code generation (`CWE-94`), with code injection also identified under CAPEC-242. The Joomla CNA rates it CVSS 4.0 at **10.0 Critical**, describing unauthenticated remote code execution. mySites.guru published the research and does not report exploitation in the wild; it also says it will not publish a working payload. Administrators should update to `14.0.0` and test the deliberate breaking change, since previously accepted code from unverified page locations may stop running. If an immediate update is impossible, disabling the Sourcerer system plugin removes the exposure but also disables the extension. The separate earlier issue, `CVE-2026-64796`, affected versions through `12.2.8` and was fixed in `13.0.0`. Originally reported by [mySites.guru](https://mysites.guru/blog/sourcerer-14-unverified-content-php-execution/). --- # Outdated PHP patches leave supported branches exposed Section: Security URL: https://joomclub.net/security/outdated-php-patches-leave-supported-branches-exposed Published: 2026-08-16 mySites.guru says PHP 8.5.7 is behind on security patches even though it is newer than fully patched PHP 8.4.24. The report concerns the PHP project and security fixes released across supported branches. It identifies three vulnerabilities in PHP components: an out-of-bounds write in `BCMath`, SQL injection in the `PostgreSQL` extension, and a crash in `Phar`. - `CVE-2026-17544`: out-of-bounds write in `BCMath` - `CVE-2026-17543`: SQL injection in the `PostgreSQL` extension - `CVE-2026-7260`: crash in `Phar` According to mySites.guru, the fixes are included in `8.2.33`, `8.3.33`, `8.4.24` and `8.5.9`. Versions below the corresponding fixed release are affected. The write-up does not provide CVSS ratings or report active exploitation of these specific issues. Administrators should update to the newest patch available for their PHP branch, with priority given to supported branches. PHP 8.2 and 8.3 receive security fixes only, while PHP versions below 8.2 are outside the supported lifecycle and should be migrated. Originally reported by [mySites.guru](https://mysites.guru/blog/php-supported-versions-amber-green/). --- # Phoca Cart patches critical unauthenticated SQL injection Section: Security URL: https://joomclub.net/security/phoca-cart-patches-critical-unauthenticated-sql-injection Published: 2026-08-16 Phoca Cart users should review their installed version after a published analysis identified a critical SQL injection in the Joomla extension’s public product filter. mySites.guru published research into the flaw, which affects the front-end product filter and can be reached without authentication. The vulnerable code accepts product attribute and specification parameters and places them into SQL queries without adequate escaping. The issue is classified as CWE-89 and tracked as `CVE-2026-74251`, with a CVSS 4.0 score of 9.3 (Critical). - `Phoca Cart 5.x` is fixed in `5.2.4`; earlier releases are affected. - `Phoca Cart 6.x` is fixed in `6.1.7`; earlier releases are affected. - The available `3.x` and `4.x` branches remain unpatched. The research was based on code and release analysis, not a live attack, and does not report confirmed exploitation. Administrators should update to the appropriate fixed release immediately. Joomla 5 sites running Phoca Cart 6.x may need to install `6.1.7` manually because the extension updater may not offer it. Sites on Joomla 3 or 4 should migrate to a supported, fixed branch or remove the extension. Originally reported by [mySites.guru](https://mysites.guru/blog/phoca-cart-sql-injection-product-filter/). --- # JoomShaper fixes critical SP Page Builder flaw Section: Security URL: https://joomclub.net/security/joomshaper-fixes-critical-sp-page-builder-flaw Published: 2026-08-12 JoomShaper has fixed two unauthenticated vulnerabilities in SP Page Builder for Joomla, including a critical flaw that could enable remote code execution. Version 6.8.0 contains the fixes. The issues affect `SP Page Builder` releases from `5.5.0` through `6.7.1`. The extension's vendor, JoomShaper, was privately notified by mySites.guru on 27 July 2026 and released the fix on 12 August. - Unauthenticated PHP file inclusion leading to pre-authentication remote code execution: CVSS 4.0 9.3, Critical, tracked as `CVE-2026-67285`. - Unauthenticated arbitrary file write: CVSS 4.0 Medium, tracked as `CVE-2026-67286`. mySites.guru said both flaws involve the Dynamic Content “load more” endpoint. The research was disclosed before publication, while exact requests and proof-of-concept details are being withheld. The advisory reports no public exploitation details. Administrators should update to `SP Page Builder 6.8.0` immediately. Sites that previously ran an affected release, including `6.7.1`, should also be checked for signs of compromise. Originally reported by [mySites.guru](https://mysites.guru/blog/sp-page-builder-pre-auth-rce-file-inclusion-disclosure/). --- # Cotton Cloud fixes two Joomla access control flaws Section: Security URL: https://joomclub.net/security/cotton-cloud-fixes-two-joomla-access-control-flaws Published: 2026-08-12 Two medium-severity access control vulnerabilities in the Cotton Cloud file-storage extension for Joomla have been fixed in version `2.0.3`, according to mySites.guru. The affected release was `2.0.1`. `CVE-2026-67283` covered missing authentication, allowing unauthenticated visitors to reach front-end tasks when only a CSRF token was checked. It carried a CVSS 4.0 score of 6.9 and was fixed in `2.0.2`. `CVE-2026-67284` involved broken authorisation and insecure direct object references (IDOR) in database access by numeric file and folder IDs. A logged-in user could access or alter another user’s data. It was rated medium severity with a CVSS 4.0 score of 5.3. mySites.guru said it reproduced the remaining issue in `2.0.2`, where an ownership check had been added to a method that the package did not call. The developer corrected the authorisation path in `2.0.3`, including checks around the model, terminal and MCP interfaces. Administrators should update Cotton Cloud to `2.0.3`. The advisory says to treat `2.0.2` and earlier releases as vulnerable. Originally reported by [mySites.guru](https://mysites.guru/blog/cotton-cloud-incomplete-security-fix/). --- # Fabrik fixes critical unauthenticated RCE Section: Security URL: https://joomclub.net/security/fabrik-fixes-critical-unauthenticated-rce Published: 2026-08-10 Fabrik for Joomla up to version 4.6.6 contains an unauthenticated remote code execution flaw in its calc element. Tracked as `CVE-2026-66915`, the issue has a CVSS 4.0 score of 10.0 Critical and is fixed in version 4.6.7. mySites.guru published research describing the vulnerability as code injection (CWE-94) through Fabrik’s front-end AJAX calculation endpoint. An anonymous visitor could reach the endpoint without authentication or user interaction and cause PHP code to run on the server when the relevant calc element was configured for AJAX recalculation. The advisory said there was no known exploitation in the wild when it was published, and the issue was not listed in CISA’s Known Exploited Vulnerabilities catalog. - Update every Fabrik installation below `4.6.7` as soon as possible. - The fixed release supports Joomla 4.2 and later, and Joomla 5.1 through the Joomla 5 series. - Fabrik 4.x does not install on Joomla 6, while no patched release was identified for the Fabrik 3.x line used by Joomla 3 sites. - Where an update is not immediately possible, unpublish public Fabrik forms and lists as a temporary exposure reduction, then investigate the site for signs of compromise. Administrators need a valid Fabrik subscription to obtain or install the update through Joomla’s updater or the vendor’s download channel. Originally reported by [mySites.guru](https://mysites.guru/blog/fabrik-unauthenticated-rce-calc-element/). --- # Critical Gridbox flaws fixed in Joomla extension update Section: Security URL: https://joomclub.net/security/critical-gridbox-flaws-fixed-joomla-extension-update Published: 2026-07-29 Balbooa’s Joomla page builder Gridbox contains 23 critical vulnerabilities, including pre-authentication remote code execution. mySites.guru says some flaws are being exploited and urges an immediate update to 2.20.2. mySites.guru disclosed the findings after Balbooa commissioned a full security review of `com_gridbox`. The issues affect Gridbox `2.20.1` and earlier; Balbooa released `2.20.2` on 29 July 2026 as the complete fix. - Unauthenticated remote code execution through a single request - Privilege escalation and routes to administrator access without a password - Unauthenticated SQL injection, including a path that exposes user password hashes - Unauthenticated file reading and deletion flaws The advisory names `CVE-2026-65884` and `CVE-2026-65885`, rated Critical at 10.0 and 9.4 respectively. Both records have the “Attacked” exploit-maturity designation. The earlier Gridbox authentication bypass, `CVE-2026-61425`, was fixed in `2.20.1`. The Joomla Security Strike Team has confirmed active exploitation of several issues. Administrators should install `2.20.2` immediately and check their sites, logs and user accounts for signs of compromise, including unexpected administrator accounts. Originally reported by [mySites.guru](https://mysites.guru/blog/gridbox-23-critical-vulnerabilities/). --- # JCE 2.9.99.10 fixes privileged file rename flaw Section: Security URL: https://joomclub.net/security/jce-2-9-99-10-fixes-privileged-file-rename-flaw Published: 2026-07-29 JCE 2.9.99.10 fixes a file-handling vulnerability that could let a privileged, authenticated user hide a file in the directory they were viewing. The JCE developer released `2.9.99.10` on 29 July 2026. According to research published by mySites.guru, the affected versions are `2.9.99.6` through `2.9.99.9`. The issue requires a valid login, a JCE profile with file-browser access, and the Rename permission. This is an authenticated privilege-related file handling flaw. It could turn a filename into a hidden file, but does not provide code execution. The report does not identify active exploitation of this issue, and no CVE had been assigned as of the release date. The update also prevents renaming from silently replacing an existing file. Administrators should update JCE to `2.9.99.10` through the Joomla administrator interface. Until that is possible, the developer advises disabling Rename in file-related plugins for profiles assigned to untrusted or lower-trust users. This workaround addresses only the rename issue. - Sites below `2.9.99.6` should be treated as needing urgent attention for the separate unauthenticated upload flaw fixed in `2.9.99.5`, identified as `CVE-2026-48907`. - The release also includes additional file-validation and upload-hardening changes not fully detailed in the changelog. Originally reported by [mySites.guru](https://mysites.guru/blog/jce-2-9-99-10-security-update/). --- # SP Page Builder 6.7.1 fixes four Joomla vulnerabilities Section: Security URL: https://joomclub.net/security/sp-page-builder-671-fixes-four-joomla-vulnerabilities Published: 2026-07-27 JoomShaper has released SP Page Builder 6.7.1 to fix four vulnerabilities affecting version 6.7.0 and earlier, including a pre-authentication SQL injection and an unauthenticated mail relay. mySites.guru reported the issues after auditing SP Page Builder, JoomShaper’s Joomla page-builder extension. The most serious flaw is a high-severity pre-authentication SQL injection rated CVSS 8.7, which could allow anonymous attackers to read database contents. A second issue is an unauthenticated mail relay rated medium severity at CVSS 6.9. The remaining flaws require a low-privilege Joomla account: a high-severity SQL injection in the media manager (CVSS 7.1) and arbitrary file deletion (CVSS 7.2). The latter could allow an author-level user to remove files such as `configuration.php` or `.htaccess`. The Joomla CNA assigned `CVE-2026-65766`, `CVE-2026-65877`, `CVE-2026-65878` and `CVE-2026-65879`. mySites.guru says the issues were privately reported and does not report exploitation of these flaws in the wild. Administrators should back up their sites and update SP Page Builder to `6.7.1` or later through Joomla’s extension update tools. Sites previously running an affected version should also review credentials and stored secrets because the SQL injection could expose database data. Originally reported by [mySites.guru](https://mysites.guru/blog/sp-page-builder-sql-injection-mail-relay-disclosure/). --- # Joomla AJAX handlers remain an overlooked security risk Section: Security URL: https://joomclub.net/security/joomla-ajax-handlers-overlooked-security-risk Published: 2026-07-25 Joomla sites are facing continued automated scanning in 2026 for AJAX handlers that verify neither authentication nor permissions, leaving extensions and template frameworks exposed to unauthorized actions. The issue centers on `com_ajax`, Joomla’s lightweight router for letting plugins and modules process AJAX requests without creating separate routes. The router does not perform authorization on behalf of the extension, so each handler must enforce its own access rules. ## Three checks with different purposes - `Session::checkToken()` validates the CSRF token and helps establish that a request originated from the site. It does not identify the sender or confirm permission. - `$user->guest` indicates whether the request comes from a logged-in user. - `authorise()` and Joomla ACL rules determine whether that user may perform the requested action. The source post cites missing authorization checks in AJAX handlers for Astroid Framework and Novarian Framework. It also links a wave of Joomla site defacements involving an unauthenticated AJAX endpoint in JoomShaper Helix3, referred to as the “AntonKill” wave. AcyMailing is cited for privilege escalation caused by missing permission checks in its internal router; the listed affected range is Joomla 9.11.0–10.8.1. A handler that checks only a token can still expose destructive operations: ``` Session::checkToken() or die('Invalid Token'); $input = Factory::getApplication()->getInput(); $this->deleteItem($input->getInt('id')); ``` The recommended pattern adds an explicit ACL check before the operation: ``` Session::checkToken() or die('Invalid Token'); $app = Factory::getApplication(); $user = $app->getIdentity(); if (!$user->authorise('core.manage', 'com_yourcomponent')) { throw new Exception('Access Denied', 403); } $this->deleteItem($app-> getInput()->getInt('id')); ``` Developers should review every `com_ajax` action for an explicit authorization decision rather than treating token validation as sufficient. Site administrators should keep Astroid, Novarian, Helix and other third-party extensions updated, and audit older handlers where `checkToken()` is present without an ACL check. --- # Joomla extension filter highlights third-party components Section: Security URL: https://joomclub.net/security/joomla-extension-filter-highlights-third-party-components Published: 2026-07-24 Joomla administrators can use a core-versus-third-party filter in the full extension list to identify non-core extensions installed on a site, an inventory view that is particularly useful amid more frequent checks of Joomla websites. The filter is available in the administrator area under **System → Extensions → Manage**. It separates extensions listed as part of Joomla’s core from those supplied by external developers, allowing the extension inventory to be narrowed to third-party components. ## Why the inventory matters Third-party extensions are an important part of many Joomla installations, but they also make a site’s software inventory harder to review manually. A focused list gives administrators a practical starting point for checking which external components are present before carrying out broader maintenance or security work. The view can also help distinguish the software that belongs to Joomla itself from additional packages that may require separate attention. This is relevant as checks of Joomla sites have reportedly become more frequent. The filter does not replace updates or a broader review, but it reduces the effort needed to establish which extensions are installed outside the core set. For site audits, the relevant path is therefore the complete extension list rather than a separate security screen: open **System → Extensions → Manage**, then use the filter labelled for core and third-party extensions. Selecting the third-party option provides a quick overview of the externally supplied extensions recorded by Joomla. --- # EasyStore 2.0.2 fixes three Joomla security flaws Section: Security URL: https://joomclub.net/security/easystore-202-security-flaws Published: 2026-07-23 JoomShaper’s EasyStore ecommerce extension for Joomla contained three serious vulnerabilities before version `2.0.2`, including flaws that could expose customer records or alter orders without authentication. mySites.guru published the research after privately reporting the issues to JoomShaper. The affected releases are `2.0.1` and all earlier versions; administrators should update to `2.0.2` immediately. - `CVE-2026-65759`: unauthenticated order forgery and field manipulation, rated High with a CVSS 4.0 score of 8.7. - `CVE-2026-65760`: broken access control allowing logged-in customers to view other customers’ orders and invoices, rated Critical at 9.2. - `CVE-2026-65761`: unauthenticated SQL injection through product sorting, rated Critical at 9.3. The SQL injection could expose Joomla accounts, password hashes, site secrets and customer data, while the order flaw could mark purchases as paid. The report documents testing on a research installation and does not report exploitation in the wild. After upgrading, administrators whose sites ran a vulnerable release should assess potential data exposure and consider rotating the Joomla secret, API keys and other sensitive credentials. The update closes all three issues. Originally reported by [mySites.guru](https://mysites.guru/blog/easystore-security-disclosure/). --- # Regular Labs patches Joomla extensions across its catalogue Section: Security URL: https://joomclub.net/security/regular-labs-patches-joomla-extensions-across-catalogue Published: 2026-07-22 Regular Labs has released security fixes across roughly 30 Joomla extensions, addressing issues including SSRF, command injection and stored XSS. Administrators should update now. Research published by mySites.guru says the 22 July 2026 release also hardens the shared Regular Labs Library, including privileged AJAX checks and an HTTP request-handling fix. The issues affect Regular Labs extensions rather than Joomla core. No CVE identifiers were assigned to the fixes, and the write-up does not identify active exploitation. The reported problems include unauthenticated and low-privilege issues, as well as administrator-side weaknesses. - `Cache Cleaner` 10.0.0 fixes SSRF, SiteGround command injection, path traversal and credential exposure. - `GeoIP` 7.0.0 addresses spoofed client-IP headers, SSRF, credential exposure and unsafe archive extraction. - `Articles Anywhere` 19.0.0, `Modules Anywhere` 9.0.0 and `Users Anywhere` 2.0.0 fix SSRF, stored XSS and unauthorised data exposure. - `Modals` 16.0.0, `Tooltips` 10.0.0 and `Keyboard Shortcuts` 4.0.0 address stored XSS, path traversal or arbitrary JavaScript execution. - `Sourcerer` 13.0.0 restricts PHP in articles to Super Users. Administrators should update every installed Regular Labs extension to its latest release, prioritising the extensions above, and test any affected functionality after updating. Originally reported by [mySites.guru](https://mysites.guru/blog/regular-labs-joomla-extension-security-release/). --- # Regular Labs fixes security issues across Joomla extensions Section: Security URL: https://joomclub.net/security/regular-labs-fixes-security-issues-across-joomla-extensions Published: 2026-07-22 Regular Labs has released security updates for roughly 30 Joomla extensions, addressing issues including SSRF, stored XSS and command injection. No CVEs were assigned. mySites.guru published research on the coordinated 22 July 2026 release, which affects Regular Labs extensions rather than Joomla core. The report does not indicate active exploitation and no formal severity rating was given, but it identifies serious issues reachable in some cases by unauthenticated or low-privilege users. Priority fixes include: - `Cache Cleaner 10.0.0`, addressing SSRF, OS command injection on SiteGround hosts, path traversal and credential exposure. - `GeoIP 7.0.0`, fixing spoofable client-IP headers and additional SSRF and archive-handling problems. - `Articles Anywhere 19.0.0`, `Modules Anywhere 9.0.0` and `Users Anywhere 2.0.0`, fixing SSRF, stored XSS and unauthorised data exposure. - `Modals 16.0.0`, `Tooltips 10.0.0`, `Keyboard Shortcuts 4.0.0` and `Sourcerer 13.0.0`, with fixes for stored XSS, arbitrary JavaScript or overly broad code permissions. Shared Regular Labs Library changes also strengthen AJAX token and permission checks and update an HTTP-message component. Administrators should update every installed Regular Labs extension to its available fixed release and test configuration changes. No CVE identifiers have been assigned to this release. Originally reported by [mySites.guru](https://mysites.guru/blog/regular-labs-joomla-extension-security-release/). --- # PageBuilder CK fix left Joomla RCE open to Editors Section: Security URL: https://joomclub.net/security/pagebuilder-ck-fix-left-joomla-rce-open-to-editors Published: 2026-07-21 Joomlack has released PageBuilder CK 3.6.3 after researchers found that versions 3.6.0 through 3.6.2 only partially fixed a critical file-upload vulnerability, leaving Joomla Editor accounts able to execute code. mySites.guru published the research on the incomplete remediation of `CVE-2026-56290`, a critical remote code execution flaw originally rated CVSS 10.0. The first fix blocked unauthenticated requests, but did not restore the upload handler’s file-type restriction. As a result, an account with Joomla’s `core.edit` permission could still upload and run a PHP file through PageBuilder CK. The issue was confirmed on a clean test installation using a harmless marker file. mySites.guru said it is not publishing a working exploit, and reported no involvement of customer or third-party sites. Joomlack’s 3.6.3 release restores the media-file allow-list and rejects the same upload. - Update every PageBuilder CK installation from `3.6.0`, `3.6.1` or `3.6.2` to `3.6.3`. - Block PHP execution in writable directories such as `/images`, `/media`, `/templates` and `/tmp`. - Review Editor accounts and investigate possible compromise where untrusted accounts had access. Originally reported by [mySites.guru](https://mysites.guru/blog/pagebuilderck-file-upload-rce-incomplete-fix/). --- # Events Booking flaw exposed registrants’ invoices Section: Security URL: https://joomclub.net/security/events-booking-flaw-exposed-registrants-invoices Published: 2026-07-21 A security flaw in the Joomla Events Booking extension allowed unauthenticated visitors to download other registrants’ invoices, exposing personal and payment information. Research published by mySites.guru identifies the issue as an insecure direct object reference and authorization failure. The vulnerable release tested was `5.8.1`; the vendor, JoomDonation, fixed the issue in `5.8.2`. The disclosure is tracked as `CVE-2026-63047`. Invoices could include a registrant’s name, organisation, postal address, email address and payment amount. The advisory says the download endpoint relied on a registration ID supplied in the request and did not properly confirm that the requester was entitled to access the document. No formal severity rating is given. mySites.guru demonstrated the problem on a clean test installation, says it did not access live sites, and released no proof of concept. It reports no known in-the-wild exploitation. - Update Events Booking to `5.8.2` on every site, including installations previously updated to `5.8.1`. - If an immediate update is not possible, disable the extension’s invoicing feature temporarily. - Because invoices may contain personal data, administrators should assess whether the exposure requires further privacy or breach-response action. Originally reported by [mySites.guru](https://mysites.guru/blog/events-booking-invoice-idor/). --- # mySites.guru says Joomla .htaccess hardening has limits Section: Security URL: https://joomclub.net/security/mysitesguru-says-joomla-htaccess-hardening-has-limits Published: 2026-07-21 mySites.guru has warned that Joomla administrators may overestimate the protection provided by hardened `.htaccess` files, since many extension vulnerabilities are reached through the normal `index.php` entry point. The research, published by mySites.guru, discusses recent third-party extension attacks and cites two vulnerabilities in products from JoomShaper: an unauthenticated file write in `Helix3` and an unauthenticated menu write that could lead to stored cross-site scripting in `Helix Ultimate`. The article does not provide affected or fixed version numbers, CVE identifiers, a formal severity rating, or a statement confirming active exploitation for either issue. It also does not present a new Joomla core vulnerability. Instead, it explains why request-level rules cannot determine whether code reached through the front controller will safely process a request. Administrators should not treat `.htaccess` hardening as a replacement for keeping Joomla extensions updated. Site owners using the cited JoomShaper products should check the vendor’s current release information and apply available security updates, while also recognising that server rules may affect legitimate callbacks and recovery tools. Originally reported by [mySites.guru](https://mysites.guru/blog/your-htaccess-wont-stop-a-joomla-hack/). --- # Membership Pro 4.6.2 fixes critical anonymous upload flaw Section: Security URL: https://joomclub.net/security/membership-pro-462-fixes-critical-anonymous-upload-flaw Published: 2026-07-21 JoomDonation has released Membership Pro 4.6.2 to address a critical unauthenticated file upload vulnerability affecting versions through 4.6.1. Security researchers at mySites.guru say the flaw allowed anonymous visitors to upload files to Joomla sites running Membership Pro, including installations that did not use File custom fields. The issue is tracked as `CVE-2026-62415` and has a critical 9.1 rating. JoomDonation’s release describes the change as improved file-upload handling. In `4.6.2`, the upload endpoint is disabled when no File custom fields are configured, while sites that use the feature receive additional checks. The release also includes a cleanup tool for unauthenticated upload files left behind before the update. mySites.guru reports no confirmed exploitation of Membership Pro in its write-up. The research links the issue to a similar flaw previously reported in another JoomDonation extension, Events Booking, while noting that Membership Pro was not audited line by line. - Versions `4.6.1` and earlier are affected. - Update to `4.6.2` immediately. - Run the included cleanup tool after updating; a scheduled-task version is also available. Originally reported by [mySites.guru](https://mysites.guru/blog/membership-pro-unauthenticated-file-upload/). --- # Events Booking flaws allowed uploads and user-data exposure Section: Security URL: https://joomclub.net/security/events-booking-flaws-allowed-uploads-and-user-data-exposure Published: 2026-07-20 Two unauthenticated vulnerabilities in JoomDonation’s `Events Booking` Joomla extension allowed anonymous file uploads and exposed users’ names and email addresses. mySites.guru published the research after privately reporting the issues to JoomDonation, with the Joomla Security Strike Team copied on the disclosure. The upload flaw affected `Events Booking` `5.7.1` and earlier, while a separate access-control problem allowed user details to be retrieved by ID. The issues received three CVE identifiers: `CVE-2026-58149`, `CVE-2026-60024` and `CVE-2026-60025`. The default upload configuration accepted files without authentication or a CSRF token. On affected sites, uploaded image files could also be served through a public endpoint. The default file allow-list limited the immediate risk, but the report said the flaw could enable remote code execution if administrators allowed executable file types. JoomDonation shipped fixes in `5.8.0` and `5.8.1`. Administrators should update to `5.8.1`, which adds further upload protections. Joomla 3 sites should install `4.9.5`; that release is unavailable in the public downloads area, so the updater or vendor support may be required. No proof-of-concept or exact attack requests have been published. Originally reported by [mySites.guru](https://mysites.guru/blog/events-booking-unauthenticated-upload-user-enumeration/). --- # DJ-Classifieds flaw allowed unauthenticated file uploads Section: Security URL: https://joomclub.net/security/dj-classifieds-flaw-allowed-unauthenticated-file-uploads Published: 2026-07-20 mySites.guru has reported a high-severity file-upload vulnerability in the Joomla extension DJ-Classifieds, which was being probed in the wild before the vendor released a fix. The issue affects DJ-Classifieds from versions up to and including `3.11.1`. It allows unauthenticated visitors to submit files through the extension’s front-end image-upload endpoint without logging in or supplying a CSRF token. The vulnerability is tracked as `CVE-2026-61424` and has been rated High. Research published by mySites.guru says the upload restriction could be bypassed by disguising executable content inside a valid image file. While this does not automatically result in code execution on a standard server, the stored file could become dangerous on systems with permissive PHP handling or another local file-inclusion flaw. The researchers also observed anonymous requests targeting the endpoint in server logs, indicating exploitation or automated probing in the wild. - Update DJ-Classifieds to `3.11.2`, released by DJ-Extensions on 20 July 2026. - If immediate updating is impossible, block requests to the image-upload task at the firewall. - Review affected sites and logs for unexpected uploaded files or other signs of compromise. Originally reported by [mySites.guru](https://mysites.guru/blog/dj-classifieds-unauthenticated-file-upload/). --- # jDownloads fixes unauthenticated upload flaw in 4.1.6 Section: Security URL: https://joomclub.net/security/jdownloads-fixes-unauthenticated-upload-flaw-4-1-6 Published: 2026-07-17 jDownloads has fixed a high-severity unauthenticated file-upload vulnerability affecting versions 4.1.0 through 4.1.5. Administrators should update to 4.1.6. Research published by mySites.guru found that the affected Joomla extension included a standalone test upload script outside Joomla’s normal authentication and permission checks. An unauthenticated visitor could use it to place certain files on a site. The issue is tracked as `CVE-2026-61900` and classified as CWE-434, unrestricted upload of file with dangerous type. mySites.guru reproduced the issue but did not report evidence of active exploitation. The script rejected direct PHP uploads, although the advisory says its permitted file types included archives, documents, images and executables. The research rates the vulnerability High because the endpoint was publicly reachable and could be more serious on incorrectly configured servers. - Affected: `jDownloads` 4.1.0 through 4.1.5 - Fixed: `jDownloads` 4.1.6 - Action: update every affected installation to `4.1.6`. If an immediate update is not possible, remove `administrator/components/com_jdownloads/assets/upload/upload-handler.php` as a temporary measure and review the related `test_uploads` directory for unexpected files. Originally reported by [mySites.guru](https://mysites.guru/blog/jdownloads-4-1-unauthenticated-upload-flaw/). --- # Joomla extensions hit by SQL injection and stored XSS flaws Section: Security URL: https://joomclub.net/security/joomla-extensions-hit-by-sql-injection-and-stored-xss-flaws Published: 2026-07-17 Two Joomla extensions have received security fixes for high-severity, unauthenticated vulnerabilities: SQL injection in JoomCCK and stored cross-site scripting in ChronoForms. The Joomla CNA published the disclosures, which were covered by mySites.guru. Neither issue is reported as being actively exploited. - `CVE-2026-49048` affects JoomCCK from JoomCoder through version `6.4.0`. The unauthenticated SQL injection can be reached without logging in and may allow database reads. It is fixed in `6.4.1`. The CNA assigned a CVSS 4.0 score of 8.7 (High); the CVSS 3.1 score is 9.8 (Critical). The issue was reported by Kamil Soltanov. - `CVE-2026-58148` affects ChronoForms from ChronoEngine through version `8.0.52`. The unauthenticated stored XSS allows injected markup to execute in another user’s browser. It is fixed in `8.0.53` and has a CVSS 4.0 score of 8.7 (High). It was reported by Italo Almeida. Joomla administrators should check whether either extension is installed and update to the fixed version immediately. These are third-party extension flaws, not Joomla core vulnerabilities. Originally reported by [mySites.guru](https://mysites.guru/blog/we-are-not-the-only-ones-auditing-joomla-extensions/). --- # Quix Page Builder SQL injection fixed in version 6.2.2 Section: Security URL: https://joomclub.net/security/quix-page-builder-sql-injection-fixed Published: 2026-07-15 mySites.guru has disclosed an unauthenticated, error-based SQL injection in ThemeXpert’s Quix Page Builder for Joomla, tracked as `CVE-2026-58078` and rated High at CVSS 8.7. The vulnerability affected `Quix Page Builder` `6.2.0` and all earlier releases. An anonymous request to a front-end element endpoint could supply a manipulated article ID, allowing database contents to be returned through an error response. According to mySites.guru, the issue could expose data held in Joomla’s database, including user accounts, password hashes, configuration secrets and site content. The research was reproduced on test installations. The advisory does not report confirmed exploitation of third-party sites, although it found vulnerable versions deployed in the wild. ThemeXpert addressed the injection in `6.2.1`. The vendor subsequently released `6.2.2` with a fix for another reported issue and additional hardening, making it the recommended version for administrators. Administrators running Quix should update to `6.2.2` immediately and review systems that previously used an affected release. Because the flaw could expose database-held credentials and secrets, site owners should also assess whether those values need to be rotated. Originally reported by [mySites.guru](https://mysites.guru/blog/quix-sql-injection-disclosure/). --- # JoomShaper releases security patches for Joomla 3 extensions Section: Security URL: https://joomclub.net/security/joomshaper-releases-security-patches-for-joomla-3-extensions Published: 2026-07-15 JoomShaper has released Joomla 3 security updates for Helix Ultimate, Helix3 and SP Page Builder, reversing its recent decision to stop providing patches for the end-of-life platform. The fixes address multiple security issues, including unauthenticated actions, upload flaws, traversal, open redirects and stored cross-site scripting. mySites.guru, which published the research, identifies `CVE-2026-49049` in Helix3 and `CVE-2026-48908` in SP Page Builder. The latter is rated CVSS 10.0. - Helix Ultimate: the Joomla 3 patch uses the `2.1.4-j3sec` baseline and supports versions from `2.1.0` through that release. - Helix3: security patch `v1.0.0` updates the extension and template to `3.1.2`. - SP Page Builder: an existing manual security fix is now installable through Joomla’s extension installer; the source does not specify a fixed version. The report says the vulnerabilities were exploited in the wild, including defacements and the creation of hidden Super Administrators. Administrators should apply the vendor patches, check sites for compromise, and note that Helix Ultimate versions below `2.1.0` cannot use its patch. Joomla 3 itself remains unsupported, so migration to a supported Joomla release should continue. Originally reported by [mySites.guru](https://mysites.guru/blog/joomshaper-reverses-joomla-3-decision/). --- # DPCalendar reports serious read-only database access flaw Section: Security URL: https://joomclub.net/security/dpcalendar-reports-serious-read-only-database-access-flaw Published: 2026-07-14 Digital Peak has reported a serious vulnerability in its DPCalendar event-calendar component that can enable unauthorised access to data stored in a Joomla database. The issue is limited to reading data and does not allow attackers to modify or update it, but administrators are urged to update DPCalendar immediately. The vulnerability was reported to the Digital Peak team on 12 July 2026. The available information classifies the issue as serious and indicates that exploitation can expose database contents through DPCalendar. Digital Peak says the weakness is read-only: an attacker cannot use it to alter or update data. That limitation does not remove the need for prompt remediation, since database access can still expose information held by a Joomla site. ## Update paths Updates can be applied through Joomla’s update manager or by downloading the relevant package manually from Digital Peak. The referenced download for the current release is DPCalendar `10.11.2`. A separate package, DPCalendar `8.19.4`, is provided for sites running Joomla 3.x. - DPCalendar 10.11.2: `https://joomla.digital-peak.com/download/dpcalendar/dpcalendar-10.11.2` - DPCalendar 8.19.4 for Joomla 3.x: `https://joomla.digital-peak.com/download/dpcalendar/dpcalendar-8.19.4` The source notice does not provide a CVE identifier or technical details about the vulnerable code. Site operators should check the installed DPCalendar version and apply the appropriate update without delay. --- # EDocman SQL injection fixed in version 3.9.0 Section: Security URL: https://joomclub.net/security/edocman-sql-injection-fixed-version-390 Published: 2026-07-14 mySites.guru has disclosed an unauthenticated SQL injection in the Joomla extension `EDocman`, allowing database contents to be read remotely. JoomDonation fixed the issue in `3.9.0`. The vulnerability affects `EDocman` `3.8` and earlier releases, with the vulnerable feature reportedly present in the extension for a long time. It is tracked as `CVE-2026-57832`. mySites.guru confirmed the flaw on a test installation using an anonymous request. The research showed that attackers could retrieve Joomla user records, password hashes, configuration data and other database contents. Where the site's database account has broad privileges, the potential exposure may extend beyond the Joomla site's own tables. The report describes the issue as a critical-impact, unauthenticated SQL injection. It documents successful testing but does not report exploitation in the wild. The researchers are withholding the endpoint and proof of concept while administrators apply the fix. - Update every affected installation to `EDocman 3.9.0`. - If an immediate update is impossible, use a SQL-injection-filtering web application firewall as a temporary mitigation. - Review logs and investigate possible exposure, particularly on sites using highly privileged database accounts. Originally reported by [mySites.guru](https://mysites.guru/blog/edocman-sql-injection-disclosure/). --- # DPCalendar SQL injection fixed in Joomla security update Section: Security URL: https://joomclub.net/security/dpcalendar-sql-injection-fixed-joomla-security-update Published: 2026-07-13 Digital Peak has fixed a high-severity, unauthenticated SQL injection in its DPCalendar extension for Joomla, which could expose the site database to anonymous visitors. mySites.guru published the research and reported the issue to Digital Peak before public disclosure. The vulnerability affects DPCalendar from `8.18.0` onward, across the Free, Pro and Business editions. It is tracked as `CVE-2026-57831` and rated High, with a CVSS 4.0 score of 8.7. The flaw was in the public events feed. An attacker could submit an untrusted author-filter value and use SQL injection to infer data from database tables without logging in. Potentially exposed information includes Joomla accounts and password hashes, configuration secrets and other stored site data. No exploitation in the wild is reported in the write-up, and mySites.guru did not publish a working proof of concept. - Joomla 4.4.4 through 6.x: update to DPCalendar `10.11.2`. - Joomla 3: update to `8.19.4`. Administrators should update immediately. A web application firewall may reduce exposure but is not a substitute for installing the vendor’s fix. Originally reported by [mySites.guru](https://mysites.guru/blog/dpcalendar-sql-injection-disclosure/). --- # Phoca Download fixes authenticated upload RCE Section: Security URL: https://joomclub.net/security/phoca-download-fixes-authenticated-upload-rce Published: 2026-07-10 Phoca Download for Joomla contained an authenticated remote code execution flaw in versions up to 6.1.2, allowing eligible members to upload and run PHP files. Version 6.1.3 fixes the issue. mySites.guru published the research, which was reported to Phoca and fixed in the component’s 6.1.3 release. The vulnerability affects `com_phocadownload` when its frontend member-upload feature is enabled and a category permits registered users to upload files. The upload path failed to apply the configured file-type allow-list. As a result, a logged-in member could upload an executable file, such as a PHP script, to the public user-upload directory. The issue is tracked as `CVE-2026-57828` and classified as CWE-434 unrestricted upload of file with dangerous type. - Severity: Critical, CVSS 4.0 score 9.0, according to the Joomla CNA. - Access requires a registered account and the non-default upload feature to be enabled. - No proof of concept has been made public. Administrators should update every installation of `Phoca Download` from version 6.1.2 or earlier to `6.1.3` or later. Sites that had member uploads enabled should also review the user-upload directory and administrator accounts for signs of tampering. Originally reported by [mySites.guru](https://mysites.guru/blog/phoca-download-authenticated-file-upload-rce/). --- # RSFiles! fixes critical unauthenticated upload flaw Section: Security URL: https://joomclub.net/security/rsfiles-fixes-critical-unauthenticated-upload-flaw Published: 2026-07-10 RSJoomla has fixed a critical security flaw in `RSFiles!` for Joomla that could let unauthenticated visitors upload and execute PHP code on affected websites. Research published by mySites.guru identifies the vulnerability as an unauthenticated file upload issue, classified as CWE-434 and tracked as `CVE-2026-57827`. The affected component is `com_rsfiles`, with versions through `1.17.11` vulnerable. RSJoomla addressed the issue in `1.17.12`. The flaw is rated critical because an attacker did not need an account to upload a PHP file to the component’s downloads directory and execute it. The advisory says no proof of concept has been made public. It does not report confirmed exploitation. - Update every `RSFiles!` installation to `1.17.12` or later immediately. - After updating, inspect affected sites for unexpected files and administrator accounts. - Treat installations running `1.17.11` or earlier as potentially exposed until checked. Administrators should prioritise the update rather than wait for a routine maintenance window. Originally reported by [mySites.guru](https://mysites.guru/blog/rsfiles-unauthenticated-file-upload-rce/). --- # AcyMailing SQL injection fixed in version 10.11.1 Section: Security URL: https://joomclub.net/security/acymailing-sql-injection-fixed-in-version-10-11-1 Published: 2026-07-09 AcyMailing versions 6.0.0 through 10.11.0 contain an unauthenticated SQL injection affecting Joomla and WordPress installations. Administrators should update to version 10.11.1. mySites.guru published research into the issue, which is tracked as `CVE-2026-56292` and was assigned by the Joomla CNA. The advisory rates it CVSS 4.0 8.7 (High). It says the flaw was reported privately to the AcyMailing team before public disclosure. The vulnerable code was in a public-facing endpoint that accepted unsanitised input in a database query. An attacker without an account could potentially retrieve information from Joomla or WordPress database tables, including user records, password hashes, content and extension configuration data. - Affected: `AcyMailing` 6.0.0 through 10.11.0 - Fixed: `AcyMailing` 10.11.1, released 9 July 2026 - Class: unauthenticated SQL injection - Exploitation: the advisory does not report confirmed exploitation Administrators should back up affected sites and update `AcyMailing` to `10.11.1` or later through the Joomla Extensions manager or WordPress plugin updater. A web application firewall may reduce exposure, but does not replace patching. Originally reported by [mySites.guru](https://mysites.guru/blog/acymailing-sql-injection-disclosure/). --- # Balbooa Forms fixes two unauthenticated RCE flaws Section: Security URL: https://joomclub.net/security/balbooa-forms-fixes-two-unauthenticated-rce-flaws Published: 2026-07-08 Joomla administrators using `com_baforms` should update to version `2.4.3` or later after two unauthenticated remote code execution flaws were disclosed in Balbooa Forms. mySites.guru reported that Balbooa Forms versions through `2.4.0` allowed anonymous visitors to upload executable files through a frontend attachment handler. The file-upload issue, classified as CWE-434 and tracked as `CVE-2026-56291`, could lead to unauthenticated remote code execution and was being exploited in the wild before the vendor issued a fix in `2.4.1`. A separate vulnerability was later identified in the Signature field. `CVE-2026-65880` is another unauthenticated RCE and carries a CVSS score of 10.0. It affects versions through `2.4.2.1`, meaning that installations updated only to `2.4.1` or `2.4.2` remain exposed. Balbooa fixed this issue in `2.4.3`. - Update every Balbooa Forms installation to `2.4.3` or later immediately. - Review affected sites for unexpected PHP files and administrator accounts. - No public proof of concept has been released, but the first flaw is under active exploitation. Administrators should treat the update as urgent, particularly where the component was reachable from public forms. Originally reported by [mySites.guru](https://mysites.guru/blog/balbooa-forms-unauthenticated-file-upload-flaw/). --- # Joomla 6.1.2 and 5.4.7 address core security flaws Section: Security URL: https://joomclub.net/security/joomla-6-1-2-and-5-4-7-address-core-security-flaws Published: 2026-07-07 Joomla has released versions 6.1.2 and 5.4.7 with security fixes for the core and web services, alongside more than 35 bug fixes and stability improvements. Sites running Joomla 5.x or 6.x should be updated. ## Security fixes The releases address cross-site scripting (XSS) vulnerabilities affecting several administrative and frontend areas, including multifactor authentication (MFA) method management, `com_templates`, `com_installer`, language overrides, and image and modal output layouts. They also correct access-control problems in web-service endpoints for `com_media`, `com_privacy`, and `com_fields`. Related permission issues were fixed in the contacts component, `com_contact`, as well as modules and workflow processes involving `com_modules` and `com_workflow`. ## Other changes More than 35 additional corrections are included in the two releases. Notable changes include: - Extensions can now be updated directly from the command line through the CLI. - A bug that duplicated the CodeMirror editor has been fixed. - Pagination in modal windows has been corrected. - Successful Joomla alert messages now receive the intended styling. - A critical regression introduced by earlier security updates in Joomla 5.4.6 and 6.1.1 has been resolved. - The installer no longer fails when moving to the database step if a password contains leading or trailing spaces. All fixes from the 5.4 branch have also been carried into 6.1. Administrators maintaining sites on either supported branch should apply the relevant release. --- # Joomla com_fields access flaw affects 4.x and 6.x Section: Security URL: https://joomclub.net/security/joomla-com-fields-access-flaw-affects-4x-and-6x Published: 2026-07-07 Joomla sites running `4.0.0-5.4.6` or `6.0.0-6.1.1` are affected by an Incorrect Access Control issue in `com_fields`; administrators should upgrade to `5.4.7` or `6.1.2`. The Joomla project has disclosed an improper access check affecting webservices endpoints in the `com_fields` component. The flaw could allow unauthorized users to create custom fields. The advisory assigns the issue a Severity of Moderate and a Probability of Low. Its exploit type is Incorrect Access Control, and it is tracked as `CVE-2026-48958`. - Affected Joomla CMS versions: `4.0.0-5.4.6` - Affected Joomla CMS versions: `6.0.0-6.1.1` - Fixed versions: `5.4.7` and `6.1.2` Administrators should review their installations and upgrade to the applicable fixed version. The issue was reported by Federico Brasili on 2026-05-05, and the Joomla project published the fix on 2026-07-07. The advisory identifies the affected area as webservices endpoints and directs questions to the JSST at the Joomla! Security Centre. Published by the [Joomla Security Centre](https://developer.joomla.org/security-centre/1066-20260712-core-incorrect-access-control-in-com-fields-webservice-endpoints.html). --- # Joomla fixes access control flaw in com_privacy endpoints Section: Security URL: https://joomclub.net/security/joomla-fixes-access-control-flaw-in-com-privacy-endpoints Published: 2026-07-07 Joomla administrators running `4.0.0-5.4.6` or `6.0.0-6.1.1` should upgrade to `5.4.7` or `6.1.2`, respectively, to fix CVE-2026-48957 in `com_privacy` webservice endpoints. The Joomla project classifies this issue as an Incorrect Access Control vulnerability with Moderate severity and Low probability. It affects Joomla! CMS installations using the listed version ranges. The flaw involves an improper access check that can let unauthorized users access datasets exposed through `com_privacy`. Site administrators should apply the appropriate update rather than relying on endpoint restrictions or user permissions as a workaround. - **Exploit type:** Incorrect Access Control - **Impact:** Low - **CVE:** `CVE-2026-48957` - **Fixed versions:** `5.4.7` and `6.1.2` The Joomla Security Strike Team received the report from Himanshu Anand on 2026-06-12. The project marked the issue fixed on 2026-07-07. Published by the [Joomla Security Centre](https://developer.joomla.org/security-centre/1065-20260711-core-incorrect-access-control-in-com-privacy-webservice-endpoints.html). --- # Joomla fixes module access-control flaw Section: Security URL: https://joomclub.net/security/joomla-fixes-module-access-control-flaw Published: 2026-07-07 Joomla CMS sites running `4.0.0-5.4.6` or `6.0.0-6.1.1` should be upgraded to `5.4.7` or `6.1.2` to address a Moderate-severity access-control issue. The Joomla project has assigned `CVE-2026-48956` to an issue in the `com_modules` component. Its exploit type is Incorrect Access Control, with a Moderate impact, Moderate severity and Low probability. The affected Joomla CMS releases are: - `4.0.0-5.4.6` - `6.0.0-6.1.1` According to the advisory, an improper access check can allow users to display a list of modules in the frontend. The behaviour concerns visibility of the module listing; the announcement does not describe a route to modify module content or configuration. Administrators should update installations in the affected ranges to `5.4.7` for the 4.x and 5.x line, or `6.1.2` for the 6.x line. The project credits Warisjeet Singh (sin99xx) with reporting the issue. Sites that cannot update immediately should review frontend access and module-management permissions, although the advisory does not specify a workaround. Published by the [Joomla Security Centre](https://developer.joomla.org/security-centre/1064-20260710-core-incorrect-access-control-in-com-modules.html). --- # Joomla workflow access flaw fixed in version 6.1.2 Section: Security URL: https://joomclub.net/security/joomla-workflow-access-flaw-fixed-in-version-612 Published: 2026-07-07 Administrators running Joomla! CMS `6.0.0-6.1.1` should upgrade to `6.1.2` to address a Moderate Incorrect Access Control vulnerability in `com_workflow`, tracked as `CVE-2026-48955`. The Joomla project’s advisory describes an authorization failure in `com_workflow`, the component responsible for workflow features. Under certain conditions, an unauthorized user could obtain information about workflow stages and transitions. The issue is classified as follows: - Exploit type: Incorrect Access Control - Severity: Moderate - Probability: Low - Impact: Moderate - CVE: `CVE-2026-48955` The affected release range is Joomla! CMS `6.0.0-6.1.1`. The project lists `6.1.2` as the solution, so site owners should review their installed version and apply the update through their normal Joomla maintenance process. Developers and administrators who manage workflow-based sites should also check whether access to stage or transition information may have been exposed before the update was applied. The vulnerability was reported on 2026-04-22 by 廖双. The Joomla Security Centre lists 2026-07-07 as the fixed date and directs further enquiries to the JSST. Published by the [Joomla Security Centre](https://developer.joomla.org/security-centre/1063-20260709-core-incorrect-access-control-in-com-workflow.html). --- # Joomla language overrides expose sites to moderate XSS Section: Security URL: https://joomclub.net/security/joomla-language-overrides-expose-sites-to-moderate-xss Published: 2026-07-07 Joomla! CMS sites running versions `3.0.0-5.4.5` or `6.0.0-6.1.1` are affected by a Moderate XSS vulnerability in language overrides; administrators should upgrade to `5.4.7` or `6.1.2`. The Joomla project has disclosed a cross-site scripting issue caused by improper validation in the `language override` feature. The flaw can provide a generic XSS vector, making validation of override-related input the central security concern. The advisory assigns the issue a severity of Moderate and a probability of Low. It identifies the exploit type as XSS and tracks the vulnerability as `CVE-2026-48954`. - Affected installs: Joomla! CMS `3.0.0-5.4.5` and `6.0.0-6.1.1` - Fixed versions: Joomla! CMS `5.4.7` and `6.1.2` - Reported date: 2026-05-15 - Fixed date: 2026-07-07 Administrators should apply the appropriate update for their Joomla! CMS branch rather than relying on configuration changes as a workaround. The issue was reported by Morris Baumgarten-Egemole. The Joomla! Security Centre lists the Joomla! Security Strike Team as the contact for this advisory. Published by the [Joomla Security Centre](https://developer.joomla.org/security-centre/1062-20260708-core-xss-through-language-overrides.html). --- # Joomla generic image layout exposed to XSS Section: Security URL: https://joomclub.net/security/joomla-generic-image-layout-exposed-to-xss Published: 2026-07-07 Administrators running Joomla! CMS 4.0.0-5.4.5 or 6.0.0-6.1.1 should upgrade to 5.4.7 or 6.1.2 to address a Moderate-severity XSS vulnerability in the generic image output layout, tracked as `CVE-2026-48953`. The Joomla project published the advisory on 2026-07-07, identifying insufficient escaping in the `generic image output layout` as the source of the issue. The exploit type is XSS, with the project rating its severity as Moderate and its probability as Low. The advisory's Versions field lists `4.0.0-5.4.6` and `6.0.0-6.1.1`. Its Affected Installs field specifies Joomla! CMS versions `4.0.0-5.4.5` and `6.0.0-6.1.1`. Administrators should apply the release corresponding to their major version: - Joomla! CMS 4 users: upgrade to `5.4.7`. - Joomla! CMS 6 users: upgrade to `6.1.2`. Pavel Kohout of Aisle Research reported the vulnerability on 2026-05-15. The Joomla! Security Strike Team lists the fixed date as 2026-07-07 and directs questions to the Joomla! Security Centre. Published by the [Joomla Security Centre](https://developer.joomla.org/security-centre/1061-20260707-core-xss-in-the-generic-image-output-layout.html). --- # Joomla com_installer XSS fixed in 5.4.7 and 6.1.2 Section: Security URL: https://joomclub.net/security/joomla-com-installer-xss-fixed-in-547-and-612 Published: 2026-07-07 Joomla administrators running affected CMS releases should upgrade to `5.4.7` or `6.1.2`, which fix a Moderate XSS vulnerability in `com_installer`. The Joomla project says a lack of escaping exposes the update list view of `com_installer` to cross-site scripting. The advisory identifies the exploit type as XSS and assigns it Moderate severity, with Low probability and Moderate impact. Its general version field lists `4.0.0-5.4.6` and `6.0.0-6.1.1`. The affected-installs section specifies `4.0.0-5.4.5` and `6.0.0-6.1.1`; administrators should follow the stated upgrade path rather than rely on the earlier branch endpoint. - CVE: `CVE-2026-48952` - Fixed versions: `5.4.7` and `6.1.2` - Reported date: 2026-05-21 - Fixed date: 2026-07-07 The issue was reported by 廖双. Site owners should update promptly, particularly where administrators use the installer’s update list view. Published by the [Joomla Security Centre](https://developer.joomla.org/security-centre/1060-20260706-core-xss-in-com-installer.html). --- # Joomla fixes XSS in modalreturn layouts Section: Security URL: https://joomclub.net/security/joomla-fixes-xss-in-modalreturn-layouts Published: 2026-07-07 Joomla administrators should upgrade to version `5.4.7` or `6.1.2` to address a Moderate XSS vulnerability in `modalreturn` layouts, tracked as `CVE-2026-48951`. The Joomla project says a lack of escaping creates cross-site scripting vulnerabilities in `modalreturn` layouts used by various components. The exploit type is XSS, and the assigned Severity is Moderate, with a Low probability. The advisory’s Versions field lists `4.0.0-5.4.6` and `6.0.0-6.1.1`. Its Affected Installs entry specifies Joomla! CMS versions `4.0.0-5.4.5` and `6.0.0-6.1.1`. Administrators should check their installed release against both entries and apply the appropriate update: `5.4.7` for the 5.x series or `6.1.2` for the 6.x series. The issue is identified as `CVE-2026-48951`. Jorian Woltjer reported it on 2026-05-07, and the Joomla project recorded the fix date as 2026-07-07. The advisory concerns the Joomla! CMS and directs users with questions to the JSST at the Joomla! Security Centre. Published by the [Joomla Security Centre](https://developer.joomla.org/security-centre/1059-20260705-core-xss-in-various-modalreturn-layouts.html). --- # Joomla fixes XSS in com_templates file management view Section: Security URL: https://joomclub.net/security/joomla-fixes-xss-in-com-templates-file-management-view Published: 2026-07-07 Joomla installations in the affected 4.x, 5.x and 6.x ranges should be upgraded to `5.4.7` or `6.1.2` to address a Moderate XSS vulnerability in `com_templates`, identified as `CVE-2026-48950`. The Joomla project describes the issue as a lack of escaping in the file management view of `com_templates`. An attacker could use this flaw to inject script content into the affected interface, making it an XSS exploit type. The project rates both the impact and severity as Moderate, with Low probability. The advisory presents two version ranges relevant to administrators: - The listed Versions range is `4.0.0-5.4.6,6.0.0-6.1.1`. - The Affected Installs range is `4.0.0-5.4.5,6.0.0-6.1.1`. Joomla users should move to the applicable fixed release: `5.4.7` for the 5.x line or `6.1.2` for the 6.x line. Administrators should also review their update procedures and prioritise sites exposing template management to untrusted or lower-privileged users. The vulnerability was reported on 2026-05-07 and fixed on 2026-07-07. The Joomla Security Strike Team credits Jorian Woltjer for reporting it. Published by the [Joomla Security Centre](https://developer.joomla.org/security-centre/1058-20260704-core-xss-in-com-templates.html). --- # Joomla MFA XSS fixed in 5.4.7 and 6.1.2 Section: Security URL: https://joomclub.net/security/joomla-mfa-xss-fixed-in-547-and-612 Published: 2026-07-07 Joomla! CMS versions `4.2.0-5.4.5` and `6.0.0-6.1.1` are affected by an XSS vulnerability in the `MFA management views`. The Joomla project rates it Moderate severity with Low probability and identifies it as `CVE-2026-48949`. Upgrade to `5.4.7` or `6.1.2`, as appropriate. The advisory attributes the problem to a lack of validation in the `MFA management views`. Insufficient checking of data handled by these views creates the conditions for cross-site scripting. The project lists the exploit type as XSS and does not describe a separate mitigation, making the upgrade the stated remedy. Administrators should identify sites running an affected release and plan the update using their normal backup and testing procedures. After updating, confirm that MFA administration continues to work as expected and review any locally maintained integrations that interact with this area. - Installations in the `4.2.0-5.4.5` range should move to `5.4.7`. - Installations in the `6.0.0-6.1.1` range should move to `6.1.2`. The issue was reported by Jorian Woltjer. Site owners should apply the relevant correction rather than leave vulnerable installations exposed. Published by the [Joomla Security Centre](https://developer.joomla.org/security-centre/1057-20260703-core-xss-in-mfa-method-management.html). --- # Joomla fixes access control flaw in contact vCard downloads Section: Security URL: https://joomclub.net/security/joomla-fixes-access-control-flaw-contact-vcard-downloads Published: 2026-07-07 Administrators running Joomla! CMS versions `3.0.0-5.4.5` or `6.0.0-6.1.1` should upgrade to `5.4.7` or `6.1.2` to address a Low-severity `Incorrect Access Control` issue in `com_contact`. The Joomla project says the flaw could allow a user to download vCard exports for contacts that should be inaccessible to them. The issue is tracked as `CVE-2026-48948`. The advisory rates both the impact and probability as Low. It concerns Joomla!'s contact component and specifically affects the vCard download functionality, where an improper access check could expose contact data through an export request. - **Exploit type:** `Incorrect Access Control` - **Fixed versions:** `5.4.7` and `6.1.2` - **Affected Installs:** `3.0.0-5.4.5` and `6.0.0-6.1.1` The source's Versions field lists `3.0.0-5.4.6` and `6.0.0-6.1.1`, while its Affected Installs field lists the first range through `5.4.5`. Administrators should follow the stated upgrade guidance and move to the fixed release for their branch. Published by the [Joomla Security Centre](https://developer.joomla.org/security-centre/1056-20260702-core-incorrect-access-control-in-com-contact-vcf-download.html). --- # Joomla com_media access flaw fixed in 5.4.7 and 6.1.2 Section: Security URL: https://joomclub.net/security/joomla-com-media-access-flaw-fixed-in-547-and-612 Published: 2026-07-07 Joomla! CMS installations running `4.1.0-5.4.6` or `6.0.0-6.1.1` are affected by incorrect access control in `com_media` webservice endpoints; administrators should upgrade to `5.4.7` or `6.1.2`, as appropriate. The Joomla project has addressed a permission-checking weakness that could let privileged users overwrite media files even when they do not have editing permissions. The issue is tracked as `CVE-2026-48947` and affects the Joomla! CMS. The vulnerable version ranges are `4.1.0-5.4.6` and `6.0.0-6.1.1`. The corrected releases are `5.4.7` and `6.1.2`, respectively. Administrators should identify which supported branch their site uses and apply the matching update. The advisory classifies the exploit type as `Incorrect Access Control`. Its assigned impact is `Moderate`, while the severity is `Low` and the probability is `Low`. The affected area is the `com_media` webservice endpoints, so sites that allow privileged backend access should prioritise checking their installed version. The issue was reported by Federico Brasili. The Joomla project lists the reported date as 2026-05-05 and the fixed date as 2026-07-07. Published by the [Joomla Security Centre](https://developer.joomla.org/security-centre/1055-20260701-core-incorrect-access-control-in-com-media-webservice-endpoints.html). --- # JoomShaper patches serious Helix Ultimate security flaws Section: Security URL: https://joomclub.net/security/joomshaper-patches-helix-ultimate-security-flaws Published: 2026-07-07 JoomShaper has released `Helix Ultimate` 2.2.7 to fix multiple Joomla security issues, including an unauthenticated menu write that could lead to stored XSS. mySites.guru reported that all `Helix Ultimate` versions below `2.2.7` are affected. The previous public release was `2.2.4`. The vendor's security release addresses missing CSRF and authorisation checks in the framework's `com_ajax` handler, including menu and mega-menu operations. The most serious issue described is an anonymous ability to write attacker-controlled menu data, combined with unescaped output. This creates a stored cross-site scripting risk, classified as `CWE-79`. The missing-authorisation issues are classified as `CWE-862`. Other fixes cover an in-folder arbitrary file deletion, an open redirect, an unprotected template settings export, and weak media-upload validation. No CVE has been assigned, and the report says there is no evidence of exploitation in the wild. It is not considered a zero-day, although the public patch may help attackers develop exploits. Administrators should update every affected installation to `2.2.7` without delay. Originally reported by [mySites.guru](https://mysites.guru/blog/helix-ultimate-security-update/). --- # Helix3 3.1.1 fixes critical Joomla security flaws Section: Security URL: https://joomclub.net/security/helix3-311-fixes-critical-joomla-security-flaws Published: 2026-06-29 JoomShaper has released `Helix3` 3.1.1 to address critical security vulnerabilities that could let unauthenticated attackers write and delete files on Joomla servers. The affected component is the `plg_ajax_helix3` plugin in Helix3, with versions before `3.1.1` affected. mySites.guru published the research after finding the issues while investigating a hacked customer site and reported them to JoomShaper through responsible disclosure. The flaws include unauthenticated file writing, arbitrary file deletion and template-parameter overwriting. The release also hardens image uploads, path handling and output escaping, addressing additional code-execution, cross-site scripting and abuse risks. The vulnerable handler was reachable through Joomla’s `com_ajax` dispatcher without requiring a login. mySites.guru rates the update as critical. Its analysis says the issue affects current Joomla 4, 5 and 6 installations using Helix3. The write-up does not identify a CVE, and reports that the compromise investigation provided evidence of real-world impact. Administrators should update every site using Helix3 to `3.1.1` immediately. Helix Ultimate is a separate product and is not affected by this issue. Originally reported by [mySites.guru](https://mysites.guru/blog/helix3-security-update-changelog-failure/). --- # Hidden cron jobs can restore malware after Joomla cleanup Section: Security URL: https://joomclub.net/security/hidden-cron-jobs-can-restore-malware-after-joomla-cleanup Published: 2026-06-27 A mySites.guru investigation warns that Joomla sites can be reinfected by malicious cron jobs hidden outside the account-level schedules visible in hosting panels. The published research describes cron-based persistence that can restore webshells after files and databases have been cleaned. Administrators should check their own account crontab, but a clean cPanel or Plesk schedule does not rule out jobs in system locations or another account’s spool. The article also discusses `CVE-2026-54420`, described as a symlink-handling flaw in the LiteSpeed cPanel plugin. mySites.guru says the issue was added to CISA’s Known Exploited Vulnerabilities catalog for active exploitation. The write-up does not provide affected or fixed version numbers, a formal severity rating, or a named Joomla extension; it is not an extension-specific advisory. - Review account-level cron jobs for unfamiliar commands, downloads or frequent file-copy operations. - Ask the hosting provider or a system administrator to inspect system crontabs and cron directories when reinfection continues. - Do not treat file cleanup alone as a complete remediation if server-level persistence may be present. Originally reported by [mySites.guru](https://mysites.guru/blog/reinfected-check-every-crontab-not-just-yours/). --- # OVH falsely flags Joomla backup connector as malware Section: Security URL: https://joomclub.net/security/ovh-falsely-flags-joomla-backup-connector-as-malware Published: 2026-06-22 mySites.guru says OVH mistakenly identified the legitimate Joomla `bfnetwork` connector file `bfRestore.php` as malware. In a June 22 write-up, mySites.guru said the flagged file is part of its connector extension for audits, backups, updates and restores. The vendor says `bfRestore.php` is password-gated and passes restore requests to Joomla’s core `com_joomlaupdate` extraction code. The incident is described as a false-positive malware detection rather than a vulnerability in the extension. The report says OVH’s response disabled website access, PHP email and outbound connections across affected hosting plans. It reports no compromise or exploitation. No affected or fixed extension versions, CVE identifiers or formal severity rating are provided. Administrators who received an OVH alert naming `bfnetwork/bfRestore.php` should not delete the file. Instead, they should use the OVH control panel to lift the security measures, then test forms, password resets and Joomla update checks. If the block returns, mySites.guru recommends opening an OVH support ticket and requesting that the specific file be whitelisted. Originally reported by [mySites.guru](https://mysites.guru/blog/ovh-flagged-our-plugin-as-malware/). --- # SP Page Builder flaw exploited to create Joomla admins Section: Security URL: https://joomclub.net/security/sp-page-builder-flaw-exploited-to-create-joomla-admins Published: 2026-06-15 A critical SP Page Builder vulnerability is being exploited against Joomla sites, allowing unauthenticated attackers to upload PHP files and create hidden Super Administrator accounts. Research published by mySites.guru identifies the affected extension as `SP Page Builder`, developed by JoomShaper. All versions through and including `6.6.1` are affected; version `6.6.2` contains the fix. Tracked as `CVE-2026-48908`, the issue is an improper access control flaw (CWE-284) involving unauthenticated file upload and remote code execution. It carries a CVSS score of 10.0 and is rated Critical. The vulnerable `asset.uploadCustomIcon` task can be reached without logging in. mySites.guru says the vulnerability is already being exploited in the wild. Attackers have used it to plant hidden Super Administrator accounts, commonly with email addresses ending in `@secure.local`, and may leave additional PHP backdoors for persistence. Administrators should update every affected Joomla site to `6.6.2` or later immediately. Updating only blocks further exploitation, so review Super Administrator accounts, investigate unfamiliar users and inspect compromised sites for malicious files. Unpublishing the extension is not a sufficient mitigation. Originally reported by [mySites.guru](https://mysites.guru/blog/sp-page-builder-zero-day-uploadcustomicon-rce/). --- # iCagenda flaw enabled unauthenticated RCE on Joomla 6 Section: Security URL: https://joomclub.net/security/icagenda-flaw-enabled-unauthenticated-rce-on-joomla-6 Published: 2026-06-15 mySites.guru has reported a critical iCagenda vulnerability that allowed unauthenticated attackers to upload executable files and achieve remote code execution on Joomla 6 sites. The issue was being exploited before JoomliC released a fix. The affected extension is `iCagenda`, developed by JoomliC. The primary issue is an improper access-control flaw (CWE-284) in the frontend event submission process. It is tracked as `CVE-2026-48939` and carries a CVSS 4.0 score of 10.0 (Critical). According to research published by mySites.guru, the upload-to-code-execution chain required no login and worked on Joomla 6, where core upload protections did not block the dangerous file. Earlier Joomla versions were still affected by an access-control bypass that could allow anonymous users to submit unapproved events. - 4.x releases through `4.0.7`: update to `4.0.8`, released 15 June 2026. - 3.2.1 through `3.9.14`: update to `3.9.15`, released 16 June 2026. Administrators should update immediately and inspect the iCagenda attachment directory for unexpected files, particularly on Joomla 6. Treat suspicious files as evidence of compromise and investigate the wider site. Unpublishing the component does not provide protection. Automated attacks were reported in the wild from 15 June 2026. Originally reported by [mySites.guru](https://mysites.guru/blog/icagenda-zero-day-file-upload-rce/). --- # Joomla Framework XSS fixed in cleanAttributes filtering Section: Security URL: https://joomclub.net/security/joomla-framework-xss-fixed-cleanattributes-filtering Published: 2026-05-26 Joomla! CMS installations running `3.0.0-5.4.5` or `6.0.0-6.1.0` are affected by a Moderate XSS issue in the Framework; upgrade to `5.4.6` or `6.1.1`. The Joomla project says the vulnerability affects the Framework's `cleanAttributes` filter code, which processes HTML attributes. Insufficient input filtering can allow an XSS vector through this code path. Site administrators should apply the appropriate update, particularly where untrusted or user-supplied HTML is handled. - **Exploit type:** XSS - **Severity:** Moderate - **Impact:** Moderate - **Probability:** Moderate - **CVE:** `CVE-2026-48905` The affected Joomla! CMS ranges are `3.0.0-5.4.5` and `6.0.0-6.1.0`. The corresponding fixed versions are `5.4.6` and `6.1.1`. The issue was reported on 2026-05-04 and fixed on 2026-05-26. Jesper den Boer reported the vulnerability. Administrators should check which supported branch their sites use and upgrade to the matching fixed version. The Joomla! Security Centre lists the JSST as the contact point for this advisory. Published by the [Joomla Security Centre](https://developer.joomla.org/security-centre/1052-20260520-framework-inadequate-content-filtering-within-the-cleanattributes-filter-code.html). --- # Joomla fixes XSS in checkAttribute filtering Section: Security URL: https://joomclub.net/security/joomla-fixes-xss-in-checkattribute-filtering Published: 2026-05-26 Joomla CMS sites running `3.0.0-5.4.5` or `6.0.0-6.1.0` should be upgraded to `5.4.6` or `6.1.1` to address a Moderate-severity XSS vulnerability in the `Framewok` subproject. The Joomla project says inadequate filtering in the `checkAttribute` methods can allow cross-site scripting in various components. The advisory identifies the exploit type as XSS and assigns the issue Moderate impact, Moderate severity and Moderate probability. The affected Joomla! CMS installations are: - `3.0.0-5.4.5` - `6.0.0-6.1.0` Administrators should select the corresponding maintenance release: `5.4.6` for the first affected branch, or `6.1.1` for the second. These are the fixed versions listed by the project for the issue. The vulnerability was reported on 2026-04-21 and fixed on 2026-05-26. It is tracked as `CVE-2026-48903`. The advisory is attributed to the JSST, with the Joomla! Security Centre listed as the contact point for security-related enquiries. Published by the [Joomla Security Centre](https://developer.joomla.org/security-centre/1051-20260519-framework-inadequate-content-filtering-within-the-checkattribute-filter-code.html). --- # Joomla fixes reset-link encryption downgrade Section: Security URL: https://joomclub.net/security/joomla-fixes-reset-link-encryption-downgrade Published: 2026-05-26 Administrators running Joomla! CMS `3.9.0-5.4.5` or `6.0.0-6.1.0` should upgrade to `5.4.6,6.1.1` to fix a Low-severity transport encryption downgrade affecting password and username reset links, tracked as `CVE-2026-48902`. The issue affected the password and username reset features when a site used an HTTPS connection but the `Force SSL` flag had not been explicitly enabled. In that configuration, Joomla could generate reset links using plain HTTP rather than HTTPS. The Joomla project classifies the exploit type as **Mixed Content**. It assigns the issue an impact of **Low**, severity of **Low** and probability of **Low**. Although the advisory does not describe active exploitation, administrators should apply the available maintenance release rather than rely on configuration changes alone. - Affected releases: `3.9.0-5.4.5,6.0.0-6.1.0` - Upgrade target: `5.4.6,6.1.1` - CVE: `CVE-2026-48902` - Reported date: 2026-04-20 - Fixed date: 2026-05-26 The issue was reported by ZeroXJacks via Github. Site teams should test the upgrade in their normal deployment process and confirm that reset messages now contain appropriately protected links. Published by the [Joomla Security Centre](https://developer.joomla.org/security-centre/1050-20260518-core-transport-encryption-downgrade-for-password-and-username-reset-links.html). --- # Joomla InputFilter cache flaw fixed in 5.4.6 and 6.1.1 Section: Security URL: https://joomclub.net/security/joomla-inputfilter-cache-flaw-fixed Published: 2026-05-26 Joomla installations running `4.0.0-5.4.5` or `6.0.0-6.1.0` are affected by a cache-key issue in `InputFilter`; administrators should upgrade to `5.4.6` or `6.1.1`, as appropriate. The Joomla project has corrected how `InputFilter::getInstance()` identifies cached instances. A security-sensitive parameter was not included in the cache key, creating the possibility that an instance could be retrieved under conditions different from those used when it was created. The advisory assigns the issue CVE-2026-48901. Its exploit type is Incorrect Cache Key Construction, with Impact: Low, Severity: Low and Probability: Low. - Affected: Joomla CMS `4.0.0-5.4.5` and `6.0.0-6.1.0` - Fixed: Joomla CMS `5.4.6` and `6.1.1` - Reported: `2025-11-14` - Fixed: `2026-05-26` The report was submitted by ZeroXJacks via Github. Site owners should check their installed CMS branch and apply the corresponding maintenance release through their usual Joomla update process. Developers maintaining extensions that interact with the input-filtering API should also review their compatibility with the corrected behaviour. Published by the [Joomla Security Centre](https://developer.joomla.org/security-centre/1049-20260517-core-incorrect-cache-key-construction-for-inputfilter-objects.html). --- # Joomla fixes scheduler access control flaw Section: Security URL: https://joomclub.net/security/joomla-fixes-scheduler-access-control-flaw Published: 2026-05-26 Administrators running affected Joomla versions should upgrade to `5.4.6` or `6.1.1` to address an incorrect access control issue in `com_scheduler`. The Joomla project has published a security advisory for an improper access check in the CMS scheduler component. The issue could allow low privileged users to edit the task types belonging to existing scheduler tasks. The advisory identifies the issue as `CVE-2026-48900`. It classifies the impact as Moderate, the severity as Low, and the probability as Low. The exploit type is Incorrect Access Control. - Affected versions: `4.1.0-5.4.5` and `6.0.0-6.1.0` - Fixed versions: `5.4.6` and `6.1.1` - Component: `com_scheduler` The issue was reported on 2026-04-29, and the Joomla project published the fix on 2026-05-26. Site administrators should review their installed CMS branch and apply the corresponding update. The advisory credits Federico Brasili with reporting the vulnerability. Published by the [Joomla Security Centre](https://developer.joomla.org/security-centre/1048-20260516-core-incorrect-access-control-in-com-scheduler.html). --- # Joomla sample data plugins expose access-control flaw Section: Security URL: https://joomclub.net/security/joomla-sample-data-plugins-access-control-flaw Published: 2026-05-26 The Joomla project says `Joomla! CMS` installations running `4.0.0-5.4.5` or `6.0.0-6.1.0` are affected by an access-control flaw in sample data plugins. Administrators should upgrade to `5.4.6` or `6.1.1`, as appropriate. The vulnerability allows unauthorized users to carry out actions associated with installing `sampledata`. It affects the `Joomla! CMS` and is classified by the project as an `Incorrect Access Control` issue. The advisory assigns the issue an Impact of **High**, a Severity of **Moderate** and a Probability of **Moderate**. Its CVE identifier is `CVE-2026-48899`. Site administrators should treat the upgrade as the appropriate remediation for installations using the affected releases. - Reported date: 2026-04-23 - Fixed date: 2026-05-26 - Reported by: 廖双, JSST The Joomla Security Strike Team published the notice on 2026-05-26. It identifies the affected functionality as sample data plugins and directs users to the fixed releases listed in the advisory. The project’s contact point for questions is the JSST at the Joomla! Security Centre. Published by the [Joomla Security Centre](https://developer.joomla.org/security-centre/1047-20260515-core-incorrect-access-control-in-sample-data-plugins.html). --- # Joomla fixes privilege escalation in com_users webservices Section: Security URL: https://joomclub.net/security/joomla-fixes-privilege-escalation-in-com-users-webservices Published: 2026-05-26 Joomla! CMS installations running `4.0.0-5.4.5` or `6.0.0-6.1.0` are affected by a privilege escalation flaw in `com_users` webservice endpoints. Administrators should upgrade to `5.4.6` or `6.1.1`. The Joomla project has disclosed a security issue involving the group-editing webservice endpoint in `com_users`. An inadequate access-control check could allow a user to carry out actions beyond their intended permissions, making this a Privilege Escalation vulnerability. The advisory identifies the issue as `CVE-2026-48904`. Joomla classifies its impact as High, its Severity as Moderate and the Probability as Low. The affected releases are: - Joomla! CMS `4.0.0-5.4.5` - Joomla! CMS `6.0.0-6.1.0` The project released fixes in Joomla! CMS `5.4.6` and `6.1.1`. Site administrators should apply the version appropriate to their current release branch and ensure that the update completes successfully. The issue was reported by Christos Papakonstantinou of Cantina. The advisory records 2026-04-15 as the reported date and 2026-05-26 as the fixed date. Joomla administrators who need additional information can contact the Joomla! Security Strike Team through the project’s Security Centre. Published by the [Joomla Security Centre](https://developer.joomla.org/security-centre/1046-20260514-core-privilege-escalation-through-com-users-webservice-endpoints.html). --- # Joomla fixes high-severity com_users privilege escalation Section: Security URL: https://joomclub.net/security/joomla-fixes-high-severity-com-users-privilege-escalation Published: 2026-05-26 Joomla installations running `4.0.0-5.4.5` or `6.0.0-6.1.0` are affected by a High-severity privilege escalation issue in `com_users`; administrators should upgrade to `5.4.6` or `6.1.1`. The Joomla project has disclosed CVE-2026-48898, which concerns an access-control failure in the batch task provided by `com_users`. Under the advisory's classification, the exploit type is Privilege Escalation. The listed impact is High, while the probability is Low. Administrators should check their installations against the affected release lines and apply the corresponding maintenance release: - `4.0.0-5.4.5` is affected and should be updated to `5.4.6`. - `6.0.0-6.1.0` is affected and should be updated to `6.1.1`. The issue was reported on 2026-04-15 and fixed on 2026-05-26. The Joomla Security Strike Team credits Adrian Junge aka vulno, Christos Papakonstantinou and Cantina with reporting it. Sites that cannot be updated immediately should review access to administrative functionality involving user-management batch operations and prioritise the upgrade as soon as possible. Published by the [Joomla Security Centre](https://developer.joomla.org/security-centre/1045-20260513-core-privilege-escalation-through-com-users-batch-task.html). --- # Joomla MFA bypass fixed in security updates Section: Security URL: https://joomclub.net/security/joomla-mfa-bypass-fixed-in-security-updates Published: 2026-05-26 Administrators running `Joomla! CMS` `4.0.0-5.4.5` or `6.0.0-6.1.0` should upgrade to `5.4.6` or `6.1.1`, respectively, to fix an MFA authentication bypass. The Joomla project has published details of a security issue in the CMS authentication flow. Tracked as `CVE-2026-48897`, the vulnerability involves session states being reset incorrectly. Under the affected conditions, that state could allow an attacker to get past two-factor authentication checks. The project classifies the exploit type as **Authentication Bypass**. Its assigned impact is **High**, while both the severity and probability ratings are **Moderate**. The issue concerns the core `Joomla! CMS`, rather than an independently installed extension. Joomla administrators should review their deployed branches and apply the corresponding maintenance release. Sites that cannot be updated immediately should treat the advisory as a priority because multi-factor authentication may not provide its intended protection when the vulnerable session handling is triggered. The issue was reported by Morris Baumgarten-Egemole. The Joomla Security Centre lists 2026-04-01 as the reported date and 2026-05-26 as the fixed date. Published by the [Joomla Security Centre](https://developer.joomla.org/security-centre/1044-20260512-core-mfa-authentication-bypass.html). --- # Joomla MFA bypass affects 4.x and 6.x releases Section: Security URL: https://joomclub.net/security/joomla-mfa-bypass-affects-4x-and-6x-releases Published: 2026-05-26 Administrators running Joomla! CMS `4.0.0-5.4.5` or `6.0.0-6.1.0` should upgrade to `5.4.6` or `6.1.1` to address a Moderate-severity MFA authentication bypass. The Joomla project has disclosed a security issue in the `Core` component. The vulnerability is identified as `CVE-2026-48896` and is classified as an `Authentication Bypass`. A flaw in the handling of authentication state can allow an attacker to get past two-factor authentication checks. The advisory assigns the issue a High impact and Moderate probability, while its overall severity rating is Moderate. - Affected versions: Joomla! CMS `4.0.0-5.4.5` and `6.0.0-6.1.0` - Fixed versions: `5.4.6` and `6.1.1` - Reported: 2026-04-01 - Fixed: 2026-05-26 The issue was reported by Doyensec in collaboration with Claude and Anthropic Research, Christos Papakonstantinou, and Cantina. Site owners should apply the matching update promptly, particularly where multi-factor authentication protects administrator accounts. Published by the [Joomla Security Centre](https://developer.joomla.org/security-centre/1043-20260511-core-mfa-authentication-bypass.html). --- # Joomla com_media path traversal requires an update Section: Security URL: https://joomclub.net/security/joomla-com-media-path-traversal-update Published: 2026-05-26 Joomla! CMS installations running `4.0.0-5.4.5` or `6.0.0-6.1.0` should be upgraded to `5.4.6` or `6.1.1` to address a Moderate path traversal vulnerability. The Joomla project’s advisory covers an issue in the search parameter handled by the `com_media` files API webservice endpoint. Improper validation of that parameter can allow path traversal, making this a relevant update for administrators using affected Joomla! CMS installations. The published details are: - Affected versions: `4.0.0-5.4.5,6.0.0-6.1.0` - Fixed versions: `5.4.6,6.1.1` - CVE: `CVE-2026-40384` - Exploit type: Path traversal - Severity: Moderate - Impact: Moderate - Probability: Low The issue was reported on 2026-04-15 and fixed on 2026-05-26. Doyensec reported it in collaboration with Claude and Anthropic Research. Administrators should plan the applicable Joomla! CMS upgrade and verify that their deployment is running one of the fixed versions. The Joomla Security Centre lists the JSST as the contact for further information. Published by the [Joomla Security Centre](https://developer.joomla.org/security-centre/1042-20260510-core-path-traversal-in-com-media-webservice-endpoint.html). --- # Joomla fixes high-severity LFI in HTMLView layout parameter Section: Security URL: https://joomclub.net/security/joomla-fixes-high-severity-lfi-in-htmlview-layout-parameter Published: 2026-05-26 Administrators running `Joomla! CMS` versions `3.2.1-5.4.5,6.0.0-6.1.0` should upgrade to `5.4.6,6.1.1` to address a High-severity Local File Inclusion vulnerability tracked as `CVE-2026-40383`. The Joomla project’s advisory covers an input-validation flaw in the HTMLView layout parameter. Under certain conditions, improperly handled user-supplied input can cause the application to include a local file. The project classifies the impact as **High** and the probability as **Low**. The affected releases are listed as `3.2.1-5.4.5,6.0.0-6.1.0`. Site administrators should apply the release corresponding to their supported branch: - Upgrade the 5.x series to `5.4.6`. - Upgrade the 6.x series to `6.1.1`. The issue was reported on 2026-04-15 and fixed on 2026-05-26. Doyensec reported the vulnerability in collaboration with Claude and Anthropic Research. Administrators should review their installed version and schedule the appropriate update promptly, particularly where the affected layout parameter is exposed to untrusted input. Published by the [Joomla Security Centre](https://developer.joomla.org/security-centre/1041-20260509-core-lfi-in-htmlview-layout-parameter.html). --- # Joomla com_config webservice access flaw fixed Section: Security URL: https://joomclub.net/security/joomla-com-config-webservice-access-flaw-fixed Published: 2026-05-26 Joomla CMS administrators running affected 4.x or 6.x versions should upgrade to the corresponding fixed release for an improper access check in `com_config` webservice endpoints. The Joomla project has fixed an issue that could allow unauthorized access to `com_config` webservice endpoints. The vulnerability affects Joomla! CMS versions `4.0.0-5.4.5` and `6.0.0-6.1.0`. The advisory identifies the exploit type as `Incorrect Access Control` and assigns it a severity of Moderate. Its listed impact is High, while the probability is Low. The issue is tracked as `CVE-2026-35223`. - Installations on the 4.x range should upgrade to `5.4.6`. - Installations on the 6.x range should upgrade to `6.1.1`. Joomla records the issue as reported on 2026-04-15 and fixed on 2026-05-26. The report was credited to Rishi Shakya and Qi Deng. Administrators should check their deployed version and apply the appropriate update, particularly where webservice access is enabled. Published by the [Joomla Security Centre](https://developer.joomla.org/security-centre/1040-20260508-core-improper-access-check-in-com-config-webservice-endpoints.html). --- # Joomla com_tags affected by authenticated blind SQLi Section: Security URL: https://joomclub.net/security/joomla-com-tags-authenticated-blind-sqli Published: 2026-05-26 Joomla administrators using versions `4.0.0-5.4.5` or `6.0.0-6.1.0` should upgrade to `5.4.6` or `6.1.1` to address an authenticated blind SQLi in `com_tags`, tracked as `CVE-2026-352212`. The Joomla project says the vulnerability stems from improperly validated order clauses in `com_tags`. An authenticated attacker could use crafted input to influence database queries through the component, making this relevant to sites where untrusted users can access the affected functionality. The advisory classifies the exploit type as SQLi and assigns a Severity of Moderate. Its stated Impact is High, while the Probability is Low. Administrators should treat the upgrade as the appropriate remediation rather than relying on access restrictions alone. - Install the applicable fixed release: `5.4.6` for the 5.x branch or `6.1.1` for the 6.x branch. - Review update procedures and confirm that production sites are running one of these versions after deployment. The issue was reported on 2026-03-31 and fixed on 2026-05-26. The Joomla project credits Adrian Junge, also known as vurlo, and Federico Brasili for reporting it. Published by the [Joomla Security Centre](https://developer.joomla.org/security-centre/1039-20260507-core-authenticated-blind-sqli-in-com-tags.html). --- # Joomla 6.0.0-6.1.0 affected by CSRF activation flaw Section: Security URL: https://joomclub.net/security/joomla-6-0-0-6-1-0-csrf-activation-flaw Published: 2026-05-26 Administrators running Joomla! CMS `6.0.0-6.1.0` should upgrade to `6.1.1` to address a Moderate CSRF vulnerability in the user activation endpoint. The Joomla project says the issue affects the administrative activation endpoint in `com_users`. The endpoint did not validate a CSRF token, creating a cross-site request forgery attack vector that could allow an unwanted activation request to be submitted by a victim's browser. The advisory classifies the exploit type as CSRF. Its impact, severity and probability ratings are each Moderate. The vulnerability is tracked as `CVE-2026-35220`. Sun HuangnSec reported the issue on 2026-03-28. The Joomla project published the fix on 2026-05-26, with `6.1.1` identified as the solution. Site owners should review their installed CMS version and plan the update promptly, particularly where administrator accounts and user-management functions are exposed to untrusted browsing sessions. Published by the [Joomla Security Centre](https://developer.joomla.org/security-centre/1037-20260505-core-csrf-in-user-activation-endpoint.html). --- # Joomla XSS flaw affects 4.x and 6.x installations Section: Security URL: https://joomclub.net/security/joomla-xss-flaw-affects-4x-and-6x-installations Published: 2026-05-26 Joomla CMS installations running `4.0.0-5.4.5` or `6.0.0-6.1.0` are affected by a Moderate XSS issue in the `content history component`; administrators should upgrade to `5.4.6` or `6.1.1`. The Joomla project’s advisory describes an output-escaping failure that creates a cross-site scripting vector. The issue is tracked as `CVE-2026-30895`, with XSS listed as the exploit type. The project rates the impact as Moderate and the severity as Moderate, while assessing the probability as Low. Although exploitation may require suitable conditions in an affected installation, site owners should treat the update as a routine security maintenance task. - Reported date: 2026-04-14 - Fixed date: 2026-05-26 - Reported by: peterhulst The advisory identifies the affected functionality as the `content history component`. Administrators should confirm which Joomla branch their sites use, apply the corresponding fixed release, and test any extensions or customisations that interact with content history after updating. The Joomla Security Strike Team can be contacted through the Joomla Security Centre for further information. Published by the [Joomla Security Centre](https://developer.joomla.org/security-centre/1036-20260504-core-xss-in-readmore-links.html). --- # Joomla fixes moderate XSS in com_associations Section: Security URL: https://joomclub.net/security/joomla-fixes-moderate-xss-in-com-associations Published: 2026-05-26 Administrators running affected Joomla! CMS releases should upgrade to a fixed version to address a cross-site scripting issue in the multilingual associations component. The Joomla project has disclosed an output-escaping flaw in `com_associations`, the multilingual associations component. The issue creates an XSS vector that could allow injected content to be rendered in an affected installation. The advisory classifies the impact as Moderate, the severity as Moderate and the probability as Low. It identifies the exploit type as XSS and assigns the issue `CVE-2026-25901`. Affected Joomla! CMS installations are those running: - `4.0.0-5.4.5` - `6.0.0-6.1.0` The Joomla project advises upgrading to `5.4.6` or `6.1.1`, matching the installation's major version. Administrators should schedule the update promptly and verify that extensions or custom changes involving multilingual associations continue to work afterwards. The vulnerability was reported by vnth4nhnt from CyStack and Pavel Kohout from Aisle Research. Administrators seeking further information or assistance can contact the JSST through the Joomla Security Centre. Published by the [Joomla Security Centre](https://developer.joomla.org/security-centre/1034-20260502-core-xss-in-com-associations.html). --- # Joomla feed modules affected by moderate XSS flaw Section: Security URL: https://joomclub.net/security/joomla-feed-modules-affected-by-moderate-xss-flaw Published: 2026-05-26 Joomla administrators running affected CMS releases should upgrade to `5.4.6` or `6.1.1` to address a moderate XSS vulnerability in feed modules. The Joomla project says the vulnerability results from a lack of output escaping in the `feed modules` component. The flaw could provide a cross-site scripting vector, making it relevant to administrators and developers who deploy or maintain affected Joomla! CMS installations. The advisory rates the issue as Moderate severity, with a Low probability of exploitation. It is tracked as `CVE-2026-25900` and is classified as XSS. - Affected `Joomla! CMS` versions: `3.0.0-5.4.5` and `6.0.0-6.1.0` - Fixed releases: `5.4.6` and `6.1.1` - Reported date: 2026-03-28 - Fixed date: 2026-05-26 Mohamed Elabbas and Sun Huang reported the issue. Administrators should apply the appropriate upgrade rather than relying on the vulnerability's Low probability rating, particularly where feed modules are exposed to untrusted or user-controlled content. Published by the [Joomla Security Centre](https://developer.joomla.org/security-centre/1033-20260501-core-xss-in-feed-modules.html). --- # Sorry ransomware exploits critical cPanel authentication flaw Section: Security URL: https://joomclub.net/security/sorry-ransomware-exploits-critical-cpanel-authentication-flaw Published: 2026-05-11 Sorry ransomware is targeting cPanel-hosted sites through a critical authentication bypass in cPanel and WHM, encrypting files and adding the `.sorry` extension. Research published by mySites.guru says the malware is a host-level threat that can affect Joomla, WordPress, Drupal and static sites. It encrypts accessible files and appends `.sorry` to their names. The entry point is `CVE-2026-41940`, a pre-authentication authentication-bypass flaw caused by CRLF injection in cPanel and WHM’s login and session handling. WebPros rated it CVSS 9.8. The affected surface includes cPanel and WHM releases after `v11.40`, while WP Squared versions through `136.1.6` are also affected. Exploitation was reportedly observed from 23 February 2026, before disclosure on 28 April. Administrators should upgrade to a fixed release: `11.110.0.97`, `11.118.0.63`, `11.126.0.54`, `11.132.0.29`, `11.134.0.20`, `11.136.0.5` or WP Squared `136.1.7`. If compromise is suspected, do not reuse the host: rebuild on a patched system, restore a known-good backup and rotate every credential stored or used there. Originally reported by [mySites.guru](https://mysites.guru/blog/sorry-ransomware-cpanel-detection/). --- # AcyMailing privilege escalation also affects Joomla sites Section: Security URL: https://joomclub.net/security/acymailing-privilege-escalation-also-affects-joomla-sites Published: 2026-04-16 A privilege-escalation vulnerability identified as `CVE-2026-3614` also affects Joomla installations of AcyMailing, despite public advisories describing the issue as WordPress-only. Research published by mySites.guru says the vulnerable code is shared between AcyMailing’s Joomla component and WordPress plugin. The affected range is `9.11.0` through `10.8.1`; the vendor fixed the issue in `10.8.2`, released on 13 March 2026. AcyMailing’s changelog marks the security fix for both platforms. The flaw is a high-severity privilege escalation with a CVSS score of 8.8. An authenticated, low-privilege user can reach controller functions without the required authorization and potentially authenticate as another CMS user, including an administrator. The advisory does not report active exploitation. - Check every Joomla site running `AcyMailing`. - Upgrade affected installations from `9.11.0` through `10.8.1` to `10.8.2`. - After updating, review accounts and site files if an affected installation may already have been accessed. mySites.guru notes that Joomla’s public vulnerability listings did not include this CVE, which may leave administrators unaware that their sites require action. Originally reported by [mySites.guru](https://mysites.guru/blog/acymailing-cve-2026-3614-joomla/). --- # Malicious Smart Slider 3 Pro release affected Joomla sites Section: Security URL: https://joomclub.net/security/malicious-smart-slider-3-pro-release-affected-joomla-sites Published: 2026-04-08 Nextend’s Smart Slider 3 Pro `3.5.1.35` was a malicious release distributed through the official update channel, giving affected Joomla sites a remote code-execution backdoor. mySites.guru published research describing the incident as a supply-chain compromise of Nextend’s update infrastructure, rather than a conventional extension vulnerability. The affected release could execute shell commands or PHP code and was also associated with hidden administrator accounts and persistence files. The incident affects the Joomla and WordPress editions of `Smart Slider 3 Pro`. The reported version status is: - `3.5.1.35`: malicious and compromised - `3.5.1.34` and earlier: not affected by this incident - `3.5.1.36`: clean replacement The supplied report gives no formal severity rating or separate CVE for the supply-chain compromise. It references `CVE-2026-3098` as an earlier arbitrary file-read issue in Smart Slider 3, not as the identifier for this malicious release. Administrators who installed `3.5.1.35` should update to `3.5.1.36`, then treat the site as potentially compromised. Check for unauthorized users, suspicious `cf_check.php` files and known backdoor strings, and use Nextend’s official cleanup script. Updating alone does not remove changes made before the upgrade. Originally reported by [mySites.guru](https://mysites.guru/blog/smart-slider-3-pro-supply-chain-compromise/). --- # Joomla ACL issue affects com_ajax access checks Section: Security URL: https://joomclub.net/security/joomla-acl-issue-affects-com-ajax-access-checks Published: 2026-03-31 Joomla! CMS installations running `3.0.0-5.4.3` or `6.0.0-6.0.3` are affected by an access-control issue in `com_ajax`. Administrators should upgrade to `5.4.4` or `6.0.4`. The Joomla project describes the problem as an incorrect access-control configuration in the administrative area. The ajax component was not covered by the standard check for logged-in users, a behavior that could be unexpected for third-party developers integrating with the component. The advisory identifies the issue as `CVE-2026-21629`. Its exploit type is **Incorrect Access Control**, with the project assigning a severity of **Low** and a probability of **Moderate**. - Affected versions: `3.0.0-5.4.3` and `6.0.0-6.0.3` - Fixed versions: `5.4.4` and `6.0.4` - Reported date: 2026-03-11 - Fixed date: 2026-03-31 Site owners should apply the update that corresponds to their Joomla branch and review any third-party administrative integrations that rely on `com_ajax`. Developers should also account for the corrected access-check behavior when testing extensions and custom integrations. Published by the [Joomla Security Centre](https://developer.joomla.org/security-centre/1027-20260301-core-acl-hardening-in-com-ajax.html). --- # Joomla fixes SQL injection in com_content webservice endpoint Section: Security URL: https://joomclub.net/security/joomla-fixes-sql-injection-com-content-webservice-endpoint Published: 2026-03-31 Joomla administrators running `4.0.0-5.4.3` or `6.0.0-6.0.3` should upgrade to `5.4.4` or `6.0.4` to fix a Moderate SQLi vulnerability in the articles webservice endpoint. The Joomla project has disclosed a vulnerability involving improperly constructed order clauses in the `com_content` articles webservice endpoint. Under the project’s classification, the impact is High, the severity is Moderate, and the exploit type is SQLi. The issue is tracked as `CVE-2026-21630`. The affected Joomla! CMS releases are: - `4.0.0-5.4.3` - `6.0.0-6.0.3` Administrators should update according to their major release branch. The project lists `5.4.4` as the fix for the 5.x series and `6.0.4` for the 6.x series. Sites that expose the relevant webservice functionality should treat the update as a maintenance priority, while checking application logs and access controls as part of their normal incident-review process. The vulnerability was reported on 2026-03-05 and fixed on 2026-03-31. The Joomla Security Strike Team credits Antonio Morales from GitHub Security Lab Taskflow Agent and vnth4nhnt from CyStack with reporting the issue. Published by the [Joomla Security Centre](https://developer.joomla.org/security-centre/1028-20260302-core-sql-injection-in-com-content-articles-webservice-endpoint.html). --- # Joomla article title XSS fixed in 5.4.4 and 6.0.4 Section: Security URL: https://joomclub.net/security/joomla-article-title-xss-fixed-in-544-and-604 Published: 2026-03-31 Administrators running Joomla! CMS `4.0.0-5.4.3` or `6.0.0-6.0.3` should upgrade to `5.4.4` or `6.0.4` to address a Moderate-severity XSS issue. The Joomla project’s advisory concerns insufficient protection around article title data when it is rendered in several parts of the CMS. An attacker may be able to place script content in a title and have it interpreted in affected output contexts, creating cross-site scripting vectors. The issue affects Joomla! CMS releases `4.0.0-5.4.3` and `6.0.0-6.0.3`. The project identifies the exploit type as XSS, with Impact rated Moderate, Severity rated Moderate and Probability rated Low. The vulnerability is tracked as `CVE-2026-21632`. Sites should be updated to Joomla! CMS `5.4.4` or `6.0.4`, depending on the installed major version. Administrators may also wish to review article titles and publishing workflows while planning the update, particularly on sites where untrusted users can create or edit content. The issue was reported on 2026-03-10, and the Joomla project published the fixes on 2026-03-31. The advisory credits peter vanderhulst with reporting the vulnerability. Published by the [Joomla Security Centre](https://developer.joomla.org/security-centre/1030-20260304-core-xss-vectors-in-various-article-title-outputs.html). --- # Joomla fixes high-severity file deletion flaw in com_joomlaupdate Section: Security URL: https://joomclub.net/security/joomla-fixes-high-severity-file-deletion-flaw-in-com-joomlaupdate Published: 2026-03-31 Joomla administrators running versions `4.0.0-5.4.3` or `6.0.0-6.0.3` should upgrade to `5.4.4` or `6.0.4` to fix a high-severity vulnerability in `com_joomlaupdate`. The Joomla project has addressed an arbitrary file deletion vulnerability affecting the CMS autoupdate server mechanism. The flaw is caused by inadequate validation of input handled during the update process and could allow files to be removed from a Joomla installation. The project rates the issue as **High** severity, with a **Low** probability of exploitation. It is tracked as `CVE-2026-23898`. - Affected: Joomla! CMS `4.0.0-5.4.3` - Affected: Joomla! CMS `6.0.0-6.0.3` - Fixed: Joomla! CMS `5.4.4` or `6.0.4` - Exploit type: **Arbitrary File Deletion** Site owners should check which major Joomla branch their installation uses and apply the corresponding fixed release. Updating also ensures that the vulnerable update functionality is replaced, rather than relying on configuration changes or workarounds. Administrators should use the normal Joomla update process and review their files and access logs if they suspect unexpected deletion activity. The vulnerability was reported by Phil Taylor. The Joomla Security Centre directs security-related enquiries to the JSST. Published by the [Joomla Security Centre](https://developer.joomla.org/security-centre/1031-20260305-core-arbitrary-file-deletion-in-com-joomlaupdate.html). --- # Joomla webservice access flaw fixed in 5.4.4 and 6.0.4 Section: Security URL: https://joomclub.net/security/joomla-webservice-access-flaw-fixed-in-544-and-604 Published: 2026-03-31 Joomla! CMS versions `4.0.0-5.4.3` and `6.0.0-6.0.3` are affected by an `Incorrect Access Control` flaw in webservice endpoints. The Joomla project rates its severity as `High` and probability as `Low`; administrators should upgrade to `5.4.4` or `6.0.4`. The issue is tracked as `CVE-2026-23899`. The vulnerability is caused by an improper access check in the core `webservice endpoints`. According to the Joomla project, the flaw can allow unauthorized access to those endpoints. This makes the issue relevant to administrators whose installations fall within either affected version range, even though the advisory assigns a low probability to exploitation. The Joomla Security Strike Team recorded the report on `2026-03-09`, with the fix released on `2026-03-31`. The report was submitted by vnth4nhnt from CyStack. The advisory identifies the affected product as `Joomla! CMS` and classifies the exploit type as `Incorrect Access Control`. Administrators should update through the normal Joomla upgrade process and verify that the installation reaches one of the fixed releases. The advisory does not list a separate workaround, so keeping the CMS on a supported fixed version is the stated remediation. Published by the [Joomla Security Centre](https://developer.joomla.org/security-centre/1032-20260306-core-improper-access-check-in-webservice-endpoints.html). --- # Critical Novarain Framework flaw puts Joomla sites at risk Section: Security URL: https://joomclub.net/security/critical-novarain-framework-flaw-puts-joomla-sites-at-risk Published: 2026-03-30 A critical vulnerability in the Tassos/Novarain Framework for Joomla allows unauthenticated attackers to include, read and delete files and carry out SQL injection. Research published by mySites.guru identifies the issue as `CVE-2026-21627`, with a CVSS score of 9.5. It affects the `plg_system_nrframework` plugin in versions `4.10.14` through `6.0.37`. Tassos.gr fixed the issue in version `6.0.38` and later releases. The framework is commonly installed as a dependency of Tassos extensions, including: - `Convert Forms` - `EngageBox` - `Google Structured Data` - `Advanced Custom Fields` - `Smile Pack` The vulnerability is reachable without authentication through Joomla’s AJAX endpoint. A public exploit tool with multiple attack modes is available on GitHub. Tassos.gr said in its 18 February advisory that it had no evidence of exploitation in the wild at that time. Administrators should check whether `plg_system_nrframework` is installed, update it to `6.0.38` or newer through Tassos.gr, and review affected sites for signs of compromise if they were running a vulnerable release. Originally reported by [mySites.guru](https://mysites.guru/blog/novarain-framework-joomla-vulnerability/). --- # Critical Astroid Framework flaw is under active exploitation Section: Security URL: https://joomclub.net/security/critical-astroid-framework-flaw-under-active-exploitation Published: 2026-03-05 JoomDev's Astroid Framework for Joomla is affected by a critical authentication bypass that attackers are actively using to upload backdoors and inject SEO spam. Research published by mySites.guru identifies the issue as `CVE-2026-21628`, rated CVSS 10.0 Critical and classified as CWE-434, unrestricted upload of a file with a dangerous type. The flaw affects every `Astroid Framework` version before `3.3.11`, including installations on Joomla 5 and Joomla 6. The vulnerable administrative AJAX handling accepted a CSRF token without confirming that the requester was an authenticated administrator. As a result, attackers could send requests without logging in and upload files or install extensions. Observed attacks have installed malicious BLPayload system plugins and hidden SEO links. Administrators should update to `Astroid Framework 3.3.13`. Version `3.3.11` introduced the security fix, while `3.3.12` addressed regressions; `3.3.13` is the recommended release. On potentially compromised sites, updating alone is not sufficient. - Search the Joomla plugin manager for `BLPayload` or `BL Payload`. - Remove suspicious `plg_jcp_*.html` files from `/administrator/cache/` and investigate other backdoors. - Run a full audit and change Joomla, database, FTP and hosting credentials. Originally reported by [mySites.guru](https://mysites.guru/blog/astroid-framework-security-vulnerability/). --- # Tassos Framework security patch fixes Joomla AJAX flaw Section: Security URL: https://joomclub.net/security/tassos-framework-security-patch-joomla-ajax-flaw Published: 2026-02-25 Tassos has released security updates for six Joomla extensions after a vulnerability in its Tassos Framework system plugin could, under certain conditions, expose server files, remove files, or access Joomla database data through AJAX requests. The vulnerability was reported to Greek developer Tassos Marinos on 7 January 2026. It concerns the way the framework handled certain requests through Joomla’s `com_ajax` entry point, where internal framework functionality could be called without adequate restrictions. Depending on the conditions, an unauthenticated attacker could read files available to the web server and potentially delete files. Database requests could also be altered in some circumstances to retrieve data from a Joomla database. The combined capabilities could potentially support privilege escalation and unauthorised code execution. Tassos says there is currently no evidence that the vulnerability has been exploited in real-world conditions. The company conducted an internal code review, added further validation and security measures, and issued corrected versions of the affected extensions. ## Fixed extension versions The following versions contain the security release of the Tassos Framework System Plugin, version `6.0.62`: - Convert Forms: `5.1.1` for Joomla 4/5/6, `4.1.1` for Joomla 3 - EngageBox: `7.1.1` for Joomla 4/5/6, `6.3.9` for Joomla 3 - Google Structured Data: `6.1.1` for Joomla 4/5/6, `5.6.9` for Joomla 3 - Advanced Custom Fields: `3.1.1` for Joomla 4/5/6, `2.8.10` for Joomla 3 - Smile Pack: `2.1.1` for Joomla 4/5/6, `1.2.4` for Joomla 3 - MailChimp Auto-Subscribe: `5.1.1+` for Joomla 4/5/6, `5.0.4` for Joomla 3 Sites with several Tassos extensions need to update only one of them to apply the framework patch, although Tassos recommends updating every installed extension. The company published the security notice on its blog. --- # Joomla 3 security plugin reaches version 1.0.9 Section: Security URL: https://joomclub.net/security/joomla-3-security-plugin-version-1-0-9 Published: 2026-01-16 A security plugin for sites still running the unsupported Joomla 3 series has reached version 1.0.9, addressing five reported vulnerabilities including cross-site scripting, SQL injection and malicious file uploads. Joomla 3 is no longer officially supported, but many websites continue to use the series. The project behind `Joomla-3-EOL-Security-Fixes` says its latest update is intended to provide ongoing security maintenance for those installations. Version 1.0.9 addresses the following issues: - `CVE-2025-63083`: an XSS vector in the Pagebreak plugin. - `CVE-2025-63082`: inadequate content filtering for data URLs. - `CVE-2025-25226`: SQL injection in the Database package. - `CVE-2025-22213`: malicious file uploads through Media Manager. - `CVE-2024-40747`: missing escaping in module chrome attributes. The update therefore covers vulnerabilities in several Joomla components, from content rendering and URL filtering to database handling and media uploads. The post describes all five issues as critical and recommends that Joomla 3 administrators install and regularly update the security plugin while their sites remain on the unsupported branch. The project is available on GitHub under the name `TLWebdesign/Joomla-3-EOL-Security-Fixes`. The repository is hosted at [github.com/TLWebdesign/Joomla-3-EOL-Security-Fixes](https://github.com/TLWebdesign/Joomla-3-EOL-Security-Fixes). --- # JL Content Fields Filter 4.0.0 adds Joomla 6 support Section: Security URL: https://joomclub.net/security/jl-content-fields-filter-4-0-0-adds-joomla-6-support Published: 2026-01-05 JL Content Fields Filter 4.0.0 is a major release of the free Joomla extension, adding full Joomla 6 compatibility while addressing five SQL injection issues and other security weaknesses. The update also replaces the administrator interface and refactors the extension for PHP 8.2 and later. The release migrates the codebase to PSR-4, removes deprecated methods, and updates database interactions for current Joomla development practices. Compatibility fixes target PHP 8.2+ in addition to Joomla 6. ## Security and administration changes According to the release information, five SQL injections were fixed across multiple files. The update also adds XSS protection and improves CSRF token handling and permission checks. The component’s administrator interface has been rebuilt around a modern JavaScript stack using Native Fetch and ES6+. Bootstrap 5 modal windows are also included. A new `FilterfieldsField` field provides real-time filter previews, while the interface adds full CRUD functionality, improved SEO features, and usability changes. ## Module and plugin updates The release improves slider behaviour and form resets, adds dynamic context detection for plugins, and optimises the filtering logic. JL Content Fields Filter filters Joomla category articles according to configured custom fields. JL Content Fields Filter 4.0.0 is available from the extension’s project page. --- # Joomla passkey flaw enables user enumeration Section: Security URL: https://joomclub.net/security/joomla-passkey-flaw-enables-user-enumeration Published: 2025-09-30 Administrators running `Joomla! CMS` 4.0.0-4.4.13 or 5.0.0-5.3.3 should upgrade to 4.4.14 or 5.3.4 to address a User Enumeration issue in the `passkey authentication method`, tracked as `CVE-2025-54477`. The Joomla project classifies this as Severity: Low, with Impact: Moderate and Probability: Low. The exploit type is User Enumeration. The weakness can allow an attacker to distinguish valid users by observing how the passkey authentication flow handles authentication requests. This concerns the core `passkey authentication method`, rather than an extension-specific feature. Site operators should apply the appropriate update for their current Joomla branch and ensure that routine update and access-control procedures cover passkey-enabled accounts. - 4.x installations should move to `4.4.14`. - 5.x installations should move to `5.3.4`. Marco Schubert reported the issue on 2025-09-04. The Joomla project marked it fixed on 2025-09-30. Administrators who cannot update immediately should review passkey usage and monitor authentication activity, while treating the upgrade as the definitive remediation. Published by the [Joomla Security Centre](https://developer.joomla.org/security-centre/1011-20250902-core-user-enumeration-in-passkey-authentication-method.html). --- # Restaurant table reservations without an external booking service Section: Extensions URL: https://joomclub.net/extensions/smart-table-booking-restaurant-reservations Published: 2026-08-26 Smart Table Booking lets a restaurant accept and manage table reservations from its Joomla website. Restaurants need this because Joomla does not have a native system for matching a booking to table capacity, opening hours, service days and overlapping reservations. Core can handle a simple contact or custom form, but staff would still need to check availability and assign tables manually. A template override can change the appearance of a form; it cannot add reservation logic. Sites usually use an external booking service, build a custom component, or install an extension such as this one. According to the listing, Smart Table Booking goes beyond Joomla's form capabilities with table and capacity records, time-slot and service-day limits, automatic table assignment, after-midnight handling and administrator-side reservation editing. This is aimed at restaurants, cafés, hotels and other hospitality businesses that want bookings held in Joomla rather than managed through a separate service. It may also suit a Joomla team prepared to configure opening hours, table capacities and notification emails. A site that only needs a contact form, has no table inventory, or already uses a booking platform has little reason to add it. Smart Table Booking is a paid download, licensed under GPLv2 or later, and the listing says it is compatible with Joomla 5 and Joomla 6. Stephan Römer is shown as the developer, with 21 other extensions in the directory, but this listing has no reviews. Support is marked as unavailable. Before buying, check the unanswered details: whether deposits, cancellations, calendar synchronisation, spam protection and privacy compliance are covered, and what documentation and support are available. The listing also does not explain pricing, update terms or the meaning of its “Includes” entry. Listed on the [Joomla Extensions Directory](https://extensions.joomla.org/extension/vertical-markets/booking-a-reservations/smart-table-booking/). --- # Store Locator Pro adds radius searches to Joomla maps Section: Extensions URL: https://joomclub.net/extensions/store-locator-pro-radius-searches Published: 2026-08-26 Store Locator Pro is a paid Joomla component for publishing a searchable Google Maps directory of shops, dealers, offices or other locations. Location directories come up when a site needs more than a contact page: visitors may need to find the nearest branch, filter dealers by type, or get directions from a map. Joomla core can organise location information with articles, categories, custom fields and menu items, but it does not provide a native Google Maps directory with radius searching, marker management, geocoding or CSV-based location maintenance. A template override can change the presentation of a custom solution, but it cannot supply that missing data model and search process on its own. According to the listing, Store Locator Pro goes beyond core with a `com_storelocator` component, Google Maps search by address, city or ZIP code, categories and tags, marker clustering, CSV import/export, batch geocoding and a search log. It is aimed at retail chains, dealerships, franchises and organisations with multiple service offices, particularly teams migrating a Sysgen Store Locator installation from Joomla 3. A small site with one address, or a site that only needs a static map embed, has little reason to add it. Developers building a bespoke directory may also prefer their own data and mapping stack. The listing marks it as a paid download, but gives no price. It identifies Infyways Solutions as the developer, while describing the software as a JoomlaX-maintained fork of Sysgen Store Locator; the page shows 99 other extensions. Before purchase, check Google Maps API billing and usage requirements, migration details from Sysgen, import limitations, support and update terms, and whether the stated Joomla 4.4+, 5, 6 and PHP 8.1+ requirements match the target server. The listing does not explain those points or report any reviews. Listed on the [Joomla Extensions Directory](https://extensions.joomla.org/extension/maps-a-weather/maps-a-locations/store-locator-pro/). --- # MapLab Pro builds searchable location directories and maps Section: Extensions URL: https://joomclub.net/extensions/maplab-pro-searchable-location-directories-maps Published: 2026-08-26 MapLab Pro is a paid Joomla extension for publishing searchable maps and directories of branches, dealers, venues, service centres or other locations. This problem exists because Joomla core can store structured content with categories, custom fields and menu items, and can publish lists through components and modules, but it does not provide a native interactive map directory with geocoding, clustered markers, region filters or CSV-based location management. A developer could build a directory around core articles or custom fields and use a template override to change its presentation, but the map, search and administration work would still need custom code. According to the listing, MapLab Pro goes beyond that by combining map datasets, location fields, multiple markers, imports, card grids, filtering and individual location pages in one extension. It is aimed at organisations managing substantial location data: a dealer or stockist network, a business with branches, a service company covering territories, or an agency building venue and event directories for clients. A small Joomla site with one address, a contact page or a handful of manually maintained locations has little reason to install it; core content and a simple embedded map may be enough. The listing identifies MapLab Pro as a paid download from Extensions by The Design Company and says it supports Joomla 5 and 6. The developer has 10 other extensions in the directory, while MapLab Pro has no reviews there. The listing does not state the price, map provider or API requirements, usage limits, support terms, migration path, or how much configuration is needed for structured-data pages. Those points, plus a trial or demo, should be checked before purchase. Listed on the [Joomla Extensions Directory](https://extensions.joomla.org/extension/maps-a-weather/maps-a-locations/maplab-pro/). --- # Hikari Flipbook turns Joomla PDFs into page-turning books Section: Extensions URL: https://joomclub.net/extensions/hikari-flipbook-page-turning-pdf-books Published: 2026-08-26 Hikari Flipbook presents PDFs and image collections as browser-based page-turning books inside Joomla pages, modules or selected content fields. This job arises when a site needs to publish a brochure, catalogue, magazine or manual in a more book-like format than a download link or an ordinary embedded PDF. Joomla core can store media, link to a PDF from an article, and place article or custom HTML content in modules. It does not provide a native page-turning viewer, document search and thumbnails, direct links to individual PDF pages, or a ready-made PDF.js-based book interface. A template override could alter surrounding markup or styling, but creating the viewer would still require JavaScript and PDF rendering work. The usual alternative is a dedicated flipbook extension or an external document service. According to the listing, Hikari Flipbook goes beyond core by accepting PDFs, image folders or both, with responsive page layouts, zoom, lightbox and fullscreen display, configurable controls, and insertion through modules, an article shortcode or custom fields. It is aimed at publishers, organisations, shops and other sites that want visitors to browse long-form documents on the site rather than simply download them. A site that only links to occasional PDFs, or that already uses a third-party document viewer, has little reason to add it. - The directory labels it a free download, with unlimited usage, but its licence information is inconsistent: the description says GPL v3 while the listing metadata says GPLv2 or later. - The developer is Hikari Software Team. The directory shows 73 other extensions from the developer and no reviews for this listing; that is a record of directory entries, not evidence of performance. - Before installing, check the stated Joomla 4, 5 and 6 and PHP 8.1 requirements, plus support arrangements, update history, PDF size and browser limitations, image-folder setup, shortcode syntax and whether accessibility claims meet your needs. We have not tested the software. Listed on the [Joomla Extensions Directory](https://extensions.joomla.org/extension/style-a-design/print-a-pdf/hikari-flipbook/). --- # VirtueMart licensing and download limits for paid files Section: Extensions URL: https://joomclub.net/extensions/virtuemart-licensing-and-download-limits-for-paid-files Published: 2026-08-26 VM Update Key Manager links VirtueMart purchases to protected downloads, licence keys and time-limited access to Joomla extension updates. The job is to turn a VirtueMart order for a digital product into controlled file delivery and, where applicable, a licence that authorises updates. This need arises because Joomla's core update system can read update manifests and install extension updates, but it is not a shop, licence server or download- entitlement system. VirtueMart can handle the commerce side, while a template override is generally not the right tool for securing files or tracking entitlements. Sites usually add custom code or an extension when they need download limits, expiring access, update keys and renewal workflows in one process. According to the listing, this extension goes beyond Joomla core by generating keys, serving files from VirtueMart's Safe Path, recording downloads, producing update XML and checksums, and sending expiry reminders with coupons. It is aimed at a developer or small software business selling Joomla extensions, templates or other downloadable files through VirtueMart. A site selling physical goods, publishing ordinary content, or using another ecommerce platform has no obvious use for it. It also requires VirtueMart, so it is not a general Joomla licensing layer. The listing identifies the extension as a paid download from ToPowerYou.com in the VirtueMart extensions section. The directory shows two other extensions from the developer and no reviews for this listing. Before buying, check the price, support terms, documentation, payment-status setup, update-server details, email and coupon requirements, and how existing products or licences are migrated. The listing states Joomla 5 and 6 compatibility, but does not explain those integration details. Listed on the [Joomla Extensions Directory](https://extensions.joomla.org/extension/extension-specific/virtuemart-extensions/vm-update-key-manager/). --- # Per-user session limits and timed access for Joomla Section: Extensions URL: https://joomclub.net/extensions/per-user-session-limits-and-timed-access-for-joomla Published: 2026-08-26 Session Length adds per-user or per-group controls for session duration, login frequency and time-limited frontend access. The underlying problem is common on membership sites, courses and private portals: access may need to end after a subscription period, while a shared or temporary account may also need limits on how often it can log in. Joomla core already provides a global session lifetime in Global Configuration, user groups and access levels for deciding who can see content, and login-attempt controls intended to slow repeated failed logins. Those settings do not normally create subscription start and expiry dates, enforce a quota such as three successful logins per day, or apply different session periods to individual users and groups. Sites usually handle the simpler cases with core configuration and access levels. A template override is not a meaningful solution here because the requirement concerns authentication and access enforcement rather than markup. More specific membership rules generally lead to an extension. According to its listing, Session Length goes beyond core by combining timed access, login-frequency limits and session settings, with automatic expiry. Its likely audience is a membership or paid-content site, online course, temporary customer portal, kiosk, exam system or controlled demo that needs deadlines or account-use limits. A conventional brochure site, blog or site whose users only need fixed group-based permissions has little reason to install it. Session Length is a paid download from ToPowerYou.com, listed in the user management section and released under GPLv2 or later. The directory shows two other extensions from the developer and no reviews for this listing. Before buying, check the documentation and demo for the exact Joomla 6 support stated by the listing, backend versus frontend scope, timezone and renewal behaviour, notifications, administrator overrides, integrations and how quotas reset. The listing does not answer those points. Listed on the [Joomla Extensions Directory](https://extensions.joomla.org/extension/clients-a-communities/user-management/session-length/). --- # Transport Accounting splits route VAT for XML invoices Section: Extensions URL: https://joomclub.net/extensions/transport-accounting-route-vat-xml-invoices Published: 2026-08-26 For transport operators, Transport Accounting puts route-based tax and invoice preparation inside Joomla. Its job is to calculate transport routes, divide kilometres between domestic and foreign journeys, apply VAT rules, and prepare invoice data for PDF or XML export. This need exists because a transport invoice can depend on pickup points, stops, return trips, borders, taxes and extra costs such as tolls or parking. Joomla core does not calculate routes, maintain transport-specific VAT logic, or generate accounting imports. Core can handle ordinary content, users and site configuration, but this is not a template-override problem: an override can change how existing output looks, not produce the underlying accounting calculations. Operators commonly manage the work manually in spreadsheets, their accounting package, or a custom integration, and reach for an extension when they want the workflow tied to Joomla. According to the listing, Transport Accounting goes beyond core by calculating routes through Google Maps, storing invoice history and customer details, and producing XML for compatible accounting software. The likely audience is a taxi company, passenger-transfer business or transport operator that already uses Joomla and wants route-based invoices prepared alongside its existing accounts system. A brochure site, ordinary online shop, or business whose accounting software has no XML import would have little reason to install it. Transport Accounting is a paid download from ToPowerYou.com in the directory's transport accounting area. The listing shows no reviews, so it provides little evidence of the developer's directory track record. Before buying, check the licence and price, the exact XML format accepted by your accounting package, Google Maps requirements and costs, VAT rules for your countries, PDF customisation, data protection, backups, support terms, and the Joomla 6 compatibility stated in the listing. It also does not explain which accounting systems are supported, how updates are handled, or whether tax rules receive ongoing maintenance. Listed on the [Joomla Extensions Directory](https://extensions.joomla.org/extension/financial/transport-accounting/). --- # SEF Extended adds canonical rules and a custom 404 route Section: Extensions URL: https://joomclub.net/extensions/sef-extended-canonical-rules-custom-404 Published: 2026-08-25 SEF Extended adds controls for canonical URLs, URL normalization and the way Joomla serves missing pages. URL cleanup becomes an issue when a site has query parameters, multiple URL spellings, multilingual menu structures or old links that need redirecting. Joomla core already provides the `System - SEF` plugin for generating search-friendly URLs and configuring options such as URL rewriting and suffixes. It also includes the Redirect component for managing redirects, while a template can provide a custom error page. Site owners commonly combine those tools with template overrides or a dedicated SEO and redirect extension. According to the listing, SEF Extended goes further by allowing canonical URL adjustments, GET-parameter handling and exclusions for selected components or page types. It also claims to normalize www choices, remove an unwanted `.html` suffix and correct repeated slashes. Its 404 feature displays a chosen menu item while retaining the requested address and an HTTP 404 status, with language-association handling for multilingual sites. The standard SEF plugin must remain enabled. This is aimed at administrators of established, multilingual or SEO-sensitive sites that need consistent URL rules and a more controlled missing-page response. A small site using Joomla’s default routing, a simple template error page and occasional manual redirects is unlikely to need it. The directory lists SEF Extended as a free download under SEF, from `joomla.center`, with GPLv2 or later licensing and compatibility marked for Joomla 5 and 6. The developer has one other extension listed, and this extension has no reviews. Before installing, check the documentation and support arrangements, test interactions with the core Redirect component and other SEO tools, and confirm how its canonical and 404 settings affect existing URLs. The listing does not provide test results, performance information or details of that other extension. Listed on the [Joomla Extensions Directory](https://extensions.joomla.org/extension/site-management/sef/sef-extended/). --- # Content Amplifier turns Joomla articles into social campaigns Section: Extensions URL: https://joomclub.net/extensions/content-amplifier-social-campaigns Published: 2026-08-25 Content Amplifier drafts and schedules social posts from Joomla articles across six networks, using the site's own AI and social credentials. Content Amplifier takes a Joomla article and creates, edits and schedules related social posts for LinkedIn, Facebook, Instagram, Threads, Bluesky and Mastodon. This is a job Joomla sites encounter because publishing an article and promoting it are separate tasks. Core Joomla handles article creation, categories, tags, publishing dates and, depending on the site's setup, editorial workflow; it does not natively turn an article into posts for social networks or manage a cross-network promotion calendar. A template override changes how an article is displayed on the site, not how it is sent elsewhere. Teams usually copy text manually, use each network's tools, or install an extension that connects to social APIs. According to the listing, Content Amplifier goes beyond those core publishing tools by generating network-specific drafts, campaign beats, scheduled posts and recurring promotion inside the administrator. It is aimed at publishers, organisations and marketing teams that regularly promote Joomla content and want that work kept in the site's administration area. A brochure site that publishes rarely, or a team already committed to a separate social scheduling service, may have little reason to add it. The directory lists it as a free download, although per-channel custom AI prompts are marked as paid. The listing shows Multizone Limited has six other extensions and no reviews for this extension. Before installing, check which AI providers and social app permissions are supported, how credentials and article data are handled, what the paid feature costs, whether network API changes affect publishing, and what support covers. Joomla 4, 5 and 6 compatibility is stated, but usage limits and a detailed privacy policy are not. Listed on the [Joomla Extensions Directory](https://extensions.joomla.org/extension/social-web/social-media/content-amplifier/). --- # Moves HikaShop downloads off the Joomla server Section: Extensions URL: https://joomclub.net/extensions/amazon-s3-for-hikashop Published: 2026-08-24 Amazon S3 for HikaShop stores HikaShop product downloads on Amazon S3 or compatible storage instead of the Joomla server. This job comes up when a shop sells large downloadable files and its hosting has limited disk space, bandwidth, or upload capacity. Joomla core provides local media and file handling, but it is not an ecommerce download-delivery system and does not natively connect HikaShop products to Amazon S3. A template override can change markup or download-related presentation, but it cannot replace the storage and transfer layer. HikaShop itself handles product, order, and download permissions; according to the listing, this paid plugin adds remote storage, temporary private links, multipart uploads, and migration of existing files. The developer says the plugin keeps HikaShop's checks before issuing a link, supports S3-compatible services including Backblaze B2, Wasabi, DigitalOcean Spaces, Scaleway, OVH, and MinIO, and can also store files uploaded through HikaShop's `AJAX file` custom field. Those are claims from the listing, not results from our testing. It is aimed at HikaShop shops selling sizeable downloads, particularly teams that want to keep their web server as a control layer while using object storage for delivery. A small site selling a few modest files, or a Joomla site without HikaShop, has little reason to install it. The listing marks it as a paid download, but gives no price. Hikari Software Team has 72 other extensions shown in the directory; this listing has no reviews. Check the purchase terms, support arrangements, documentation, storage-service costs, and the required configuration permissions. The listing says HikaShop 6.5.2 or later is needed for sending uploads, PHP 7.4 is the minimum, and all Joomla versions are supported, but it does not explain the exact Joomla compatibility matrix or security setup for storage credentials. Listed on the [Joomla Extensions Directory](https://extensions.joomla.org/extension/directory-a-documentation/cloud-storage/amazon-s3-for-hikashop/). --- # Easy Glossary automates in-article term definitions Section: Extensions URL: https://joomclub.net/extensions/easy-glossary-automates-in-article-term-definitions Published: 2026-08-24 Easy Glossary adds glossary management and automatic in-article term highlighting, with tooltips, links and browsable term pages. This job arises when a site uses specialist language that readers may not know, such as medical, legal, product or technical terminology. Joomla core can store supporting information in articles, categories and custom fields, and Smart Search can index content, but it does not provide a built-in glossary manager that finds terms in article text and displays definitions on hover or keyboard focus. A template override can change the presentation of existing content, while manual links and custom JavaScript can provide individual tooltips. Those approaches do not, by themselves, maintain multiple dictionaries or apply terms across articles. According to the listing, Easy Glossary goes beyond those core and template options with automatic highlighting, configurable skipping of headings, links and code, A-Z directory pages, term pages, related terms, usage reporting and DefinedTerm JSON-LD. It also claims support for frontend term suggestions, CSV import and export, and an editor button for inserting individual terms when automatic highlighting is disabled. It is aimed at sites with a substantial vocabulary and a team maintaining one or more public dictionaries. A documentation portal, catalogue, medical information site or multilingual product knowledge base might have a reason to evaluate it. A small brochure site, blog with ordinary language, or site that only needs occasional manual links probably has no use for a dedicated glossary component. The listing identifies this as a paid download from Infyways Solutions and says it targets Joomla 4, 5 and 6 with PHP 8.1 or later. The directory shows 98 other extensions from the developer, but this listing has no reviews. Before buying, check the price, licence and support terms, migration and override guidance, and how the claimed search, structured data and accessibility behaviour are tested in your template. The listing does not explain those details or provide independent test results. Listed on the [Joomla Extensions Directory](https://extensions.joomla.org/extension/directory-a-documentation/glossary/easy-glossary/). --- # Easy Events Calendar adds recurring event views to Joomla Section: Extensions URL: https://joomclub.net/extensions/easy-events-calendar-recurring-event-views Published: 2026-08-24 Easy Events Calendar is a paid Joomla extension for publishing events with calendar views, recurrence, sharing and homepage display modules. Event publishing comes up when a site needs more than a date in an article: venues, start and end times, recurring dates, maps, images and an archive that visitors can browse. Joomla core supplies articles, categories, tags, custom fields, menu layouts, modules and Smart Search, but it does not provide a dedicated event record or calendar interface. A site can model events with articles and a template override, or use an extension. According to the listing, Easy Events Calendar goes beyond that core approach with month, week, agenda, cards and timeline views; recurring events; CSV import and export; Google, Outlook and Apple/ICS subscription options; an Add to calendar action; and Event JSON-LD. It also supplies component views, modules and a Smart Search plugin. The likely audience is a news or tourism site with a “what’s on” section, or a school, church, club, council or local organisation that needs event listings on a landing page and in a sidebar. An agency managing several such sites may value the reusable menu and module layouts. It is not aimed at a site that only publishes occasional dates, nor does it replace a booking or ticketing system—the listing explicitly says there is no ticketing. Before installing, note that this is a paid download, licensed GPLv2 or later. Infyways Solutions is shown with 98 other directory extensions, but this listing has no reviews. The listing states Joomla 4.4+, 5 and 6 and PHP 8.1+, but pricing, update and support terms, migration options, accessibility details, and the precise limits of calendar-feed integration are not explained. The directory places it in Calendars & Events. Listed on the [Joomla Extensions Directory](https://extensions.joomla.org/extension/calendars-a-events/easy-events-calendar/). --- # Server-side YouTube channel feeds arrive as a Joomla module Section: Extensions URL: https://joomclub.net/extensions/server-side-youtube-channel-feeds-joomla-module Published: 2026-08-24 Easy Youtube Feed turns a YouTube channel or playlist into a configurable Joomla module rather than a collection of manually embedded videos. This problem exists because Joomla core can place a video embed or other fixed HTML on a page, but it does not natively query the YouTube Data API and keep a channel or playlist current. A template override can change the markup and styling of data already available; it cannot, by itself, retrieve YouTube videos, search them, or manage API responses. The developer says this module goes beyond those options by fetching channel or playlist data in PHP and presenting it through grid, list, slider, featured, or Shorts layouts, with search, sorting, tabs and several pagination modes. That makes it relevant to a site whose homepage, campaign page, or media section needs to follow an active YouTube source. It is less relevant to a site with a handful of fixed videos, where Joomla's editor or a custom module can handle embeds without an API key. Teams should also note that this is a site module identified as `mod_easyyoutubefeed`, rather than a replacement for Joomla's media management. According to the listing, Easy Youtube Feed is a paid download from Infyways Solutions, supports Joomla 4, 5 and 6, and requires PHP 8.1 or later. The directory shows 98 other extensions from the developer, while this listing has no reviews. It does not state the price, licensing or support terms, YouTube quota usage, cache controls in practical detail, privacy implications, accessibility coverage, or upgrade policy. Those points are worth confirming before committing an API key and production content to it. Listed on the [Joomla Extensions Directory](https://extensions.joomla.org/extension/social-web/easy-youtube-feed/). --- # System - Image Optimizer converts Joomla images to WebP and AVIF Section: Extensions URL: https://joomclub.net/extensions/system-image-optimizer-webp-avif Published: 2026-08-24 System - Image Optimizer is a paid Joomla plugin that converts images in the media library into WebP and AVIF formats. Image conversion comes up because large, widely supported formats such as JPEG and PNG can make pages heavier than necessary. WebP and AVIF can reduce the bytes sent to visitors, but a site still needs suitable fallback handling and a workflow for processing existing files. Joomla core provides the Media Manager for uploading and organising images, and template code can be overridden when a site needs different image markup or responsive-image behaviour. Those tools do not, by themselves, provide the workflow described here: according to the listing, this plugin can convert existing media-library images with one click and lets administrators adjust quality and compression. That is the gap it is intended to fill, rather than a replacement for Joomla's media management or a template override. It is aimed at site owners, agencies and editorial teams with an established image library and a deliberate performance budget, especially where manually converting files would be tedious. A small site with few images, a team already handling conversion in its build or image pipeline, or a site that must retain only original formats has little reason to install it. Before installing, note that the listing marks it as a paid download and states compatibility with Joomla 5 and 6. It identifies `mixwebtemplates` as the developer; the directory lists 56 other extensions from that developer, while this listing has no reviews. The page provides no support documentation, and leaves unanswered how conversion handles originals, filenames, references, fallbacks, storage, server requirements and rollback. Those details matter before processing a live media library. Listed on the [Joomla Extensions Directory](https://extensions.joomla.org/extension/core-enhancements/performance/system-image-optimizer/). --- # CodeMirror Extended adds editor shortcuts and code navigation Section: Extensions URL: https://joomclub.net/extensions/codemirror-extended-editor-shortcuts-code-navigation Published: 2026-08-24 CodeMirror Extended is a free Joomla system plugin that adds tabs, change tracking, keyboard saving and line navigation to the CodeMirror editor. The job here is to add editing controls to Joomla’s CodeMirror-based code fields that are not part of the editor’s basic Joomla integration. This situation comes up when administrators edit templates, CSS, JavaScript or other code through Joomla’s back end. Joomla core already provides the CodeMirror editor option for code editing, along with the normal form submission and saving process. A template override is usually relevant to the site’s output, not to changing the editor’s own interface, so it is not the usual answer. Teams generally either accept the core editor, modify the administrator interface with custom code, or install an extension. According to its listing, CodeMirror Extended goes beyond core by adding tabs, line wrapping, `Ctrl+S` saving, change tracking, direct navigation to a code line and an Ajax-saving adapter. It is aimed at site owners, administrators and developers who regularly edit source files in Joomla and want more editor-oriented controls. A site that keeps code in a local development workflow, does not expose code editing to administrators, or is happy with Joomla’s existing CodeMirror setup has little reason to install it. The extension is listed as a free download under Editors, supplied by joomla.center, and marked compatible with Joomla 5 and 6. The directory shows no reviews, so there is little public user feedback there. Before installing, check what the Ajax adapter saves, which Joomla editing screens it affects, how change tracking behaves after switching fields or closing a form, and whether it conflicts with administrator customisations or other editor plugins. The listing does not explain those details, browser requirements, permissions, or a rollback path. Listed on the [Joomla Extensions Directory](https://extensions.joomla.org/extension/edition/editors/codemirror-extended/). --- # Joomla plugin injects ClickPatrol’s click-fraud script Section: Extensions URL: https://joomclub.net/extensions/system-clickpatrol-click-fraud-script Published: 2026-08-23 System - ClickPatrol Click Fraud Protection adds ClickPatrol’s measurement script to public Joomla pages so visits can be classified in the ClickPatrol service. This job comes up on sites buying traffic through Google Ads, affiliate programmes, or other advertising networks, where invalid or suspicious visits can affect reporting and spend. Joomla core does not identify fraudulent ad clicks, send those classifications to advertising networks, or provide a ClickPatrol integration. Administrators can add third-party scripts manually in a template, through a custom HTML or code-injection facility, or via Google Tag Manager. This extension goes beyond core by putting the ClickPatrol script behind a system plugin and a saved UID, without editing the template. According to the listing, it does not replace a GTM container and does not itself define how each network applies protection. The likely audience is a Joomla site team already using ClickPatrol for paid or affiliate traffic and wanting a site-level installation path. It may also suit teams that do not want to maintain a template change for the tracking code. A site with no advertising traffic, no ClickPatrol account, or an existing carefully managed tag deployment has little apparent reason to install it. The extension is a free download from `clickpatrol` in the Directory’s Analytics section, and the listing says it is GPLv2 or later. The directory entry shows zero reviews, so it offers little public evidence of the developer’s track record there. Before installation, check what data the remote host receives, how consent requirements are handled, whether caching, content-security policies, logged-in users, and excluded pages are supported, and what the `?source=f` test actually changes. The listing names Joomla 4, 5, and 6 compatibility, but leaves those operational details to ClickPatrol’s documentation and account. Listed on the [Joomla Extensions Directory](https://extensions.joomla.org/extension/site-management/analytics/system-clickpatrol-click-fraud-protection/). --- # Embedding legal streaming availability in Joomla articles Section: Extensions URL: https://joomclub.net/extensions/embedding-legal-streaming-availability-in-joomla-articles Published: 2026-08-23 Suchen.tv Streaming Widget lets German-language publishers place streaming-availability searches and curated title lists inside Joomla articles. The job is to show readers where a film or programme can legally be streamed, without the publisher maintaining that catalogue. Joomla already provides the article editor, custom HTML and, where appropriate, custom fields for storing and presenting editorial information. A team could also build a presentation layer with a template override, but that would not supply a streaming-availability database. This extension goes beyond those core tools by placing the external suchen.tv service in articles through tokens such as `{suchentvhub}`, `{suchentvlist}` and `{suchentv}`. According to the listing, the output is delivered in sandboxed iframes from `https://suchen.tv`, with searches, category lists, editorial picks and individual titles available. It is aimed at German-language publishers, entertainment sites and editorial teams that regularly answer streaming-discovery questions and want repeatable article embeds rather than a home-built catalogue. A general business site, a publisher covering a different market, or a site that does not publish film and television recommendations has little reason to install it. - The directory lists it as a free download under the GPLv2 or later licence, from developer **suchentv**, in the multimedia display section. - The listing shows Joomla 4 and 5 compatibility, but it does not explain the service’s coverage, update process, availability guarantees or any limits attached to partner IDs. - Check what data the iframe service receives, how its consent option works, and whether its privacy-policy wording meets the site’s obligations. The directory shows no reviews, and provides no broader developer track-record information. Listed on the [Joomla Extensions Directory](https://extensions.joomla.org/extension/multimedia/multimedia-display/suchen-tv-streaming-widget/). --- # QC Dynamic Replacer edits Joomla output with rules and tokens Section: Extensions URL: https://joomclub.net/extensions/qc-dynamic-replacer-edits-joomla-output Published: 2026-08-23 QC Dynamic Replacer changes matching Joomla frontend output through configurable rules and reusable tokens instead of edits to source files. The job is to alter, remove, add to, or wrap text and markup after Joomla has rendered it, with the result controlled by conditions such as the page, menu item, audience, schedule, or module context. This need appears when a site has to make broad or conditional presentation changes without modifying an extension's files. Joomla core already handles authored content, Custom HTML modules, menu and module assignment, access permissions, and ordinary publishing controls. A template override is the usual route when the required change belongs to a known component or module layout. Developers may instead use a content plugin or another extension to intervene during rendering. According to the listing, QC Dynamic Replacer goes beyond those targeted tools by applying rules to rendered frontend output generally, with reusable tokens and, in higher tiers, diagnostics, discovery tools, dynamic data, scheduling, and PHP tokens. It is aimed at administrators and development teams managing sites with repeated or conditional frontend changes: for example, different notices for user groups, scheduled substitutions, or output that is difficult to reach through a template override. A small brochure site with stable content, or a site whose changes can be made in articles, modules, or an override, has little reason to add it. Basic is free for one production domain; Pro and Max are paid tiers, with a three-day Max Preview for eligible users. The listing identifies QuantaCade as the developer, shows nine other extensions, and reports no reviews for this listing. It does not state Joomla or PHP version support, pricing, support terms, performance limits, or the exact matching and licensing details. Those points, plus the security implications of Max PHP Tokens, deserve checking before installation. We have not tested it. Listed on the [Joomla Extensions Directory](https://extensions.joomla.org/extension/edition/replace/qc-dynamic-replacer/). --- # Postrider separates Joomla mailing lists from mass mail Section: Extensions URL: https://joomclub.net/extensions/postrider-separates-joomla-mailing-lists Published: 2026-08-23 Postrider is a free Joomla component for managing separate subscriber lists, newsletters and discussion-style email lists. Postrider manages multiple mailing lists and sends campaigns or list discussion messages to their subscribers. This job comes up because Joomla's core `Mass Mail Users` tool is aimed at sending a message to selected user groups, not running a subscription service. Core does not provide per-list unsubscribe choices, campaign-level subscriber tracking, digest compilation, or a mail reflector. A template override cannot add that backend and delivery logic. Site owners therefore either keep using core mass mail for occasional group announcements or install an extension or external email service for list management. According to the listing, Postrider goes beyond core with separate list subscriptions, Community Builder group synchronisation and custom-field merge tags, discussion-list replies, per-recipient open/click/bounce data, consent records, one-click unsubscribe and digests. Its stated audience is membership organisations, clubs and associations using Community Builder, particularly teams that need several audiences without maintaining a second contact database. A small site sending occasional announcements to all registered users, or a site without mailing-list and Community Builder requirements, is unlikely to have a use for it. Postrider is a free download from Chris White in the Directory's `Mailing & Distribution Lists` section. The listing shows version 0.4.21 and marks it for J5, but prospective users should confirm support for their exact Joomla setup. It has no reviews, and the listing gives no broader developer track-record information. Check documentation, permissions, migration options, mail transport and queueing, bounce processing, tracking and privacy controls, Community Builder edge cases, and whether support covers production delivery. Listed on the [Joomla Extensions Directory](https://extensions.joomla.org/extension/marketing/mailing-a-distribution-lists/postrider/). --- # Easy Meta adds article-level social cards and schema controls Section: Extensions URL: https://joomclub.net/extensions/easy-meta-article-social-cards-schema Published: 2026-08-19 Easy Meta is a paid Joomla system plugin for setting social-sharing metadata, search-related tags and optional structured data without editing a template. This job exists because Joomla's built-in metadata controls do not cover the full set of tags used by Facebook, X, LinkedIn, WhatsApp and other sharing services. Core lets editors and administrators set familiar article and menu metadata such as page titles, descriptions and robots instructions; canonical output also depends on the site's routing and template setup. It does not provide a general article editor for Open Graph and X Card fields, social-image generation, sharing previews or Article and BlogPosting JSON-LD. Sites usually fill that gap in one of three ways: - use core fields and accept the template or existing SEO extension's defaults; - add tags through a template override or custom code; or - install an SEO or social-sharing extension. According to the listing, Easy Meta goes beyond core with an article Meta tab, previews, image fallbacks and generated 1200 by 630 images. It also claims controls for canonical and extended robots values, optional Schema.org JSON-LD, category and menu rules, and removal of duplicate Open Graph tags from templates such as Helix. We have not tested those claims. It is aimed at publishers, marketing teams and site administrators who need editors to check share cards before publication, or who want social metadata and structured data without changing a template. A small brochure site that rarely gets shared, or one already governed by a full SEO extension, may have no reason to add it. Infyways Solutions is listed with 95 other extensions, while Easy Meta has no reviews. The listing marks it as a paid download under GPLv2 or later but gives no price. Check its PHP 8.1+ requirement, the recommendation for GD, update and support terms, and possible conflicts with existing SEO or template plugins. It lists Joomla 4, 5 and 6 support, but does not explain migration, image-processing limits or exactly which core fields it overrides. Listed on the [Joomla Extensions Directory](https://extensions.joomla.org/extension/site-management/seo-a-metadata/easy-meta/). --- # Room Availability Calendar adds Joomla booking slots Section: Extensions URL: https://joomclub.net/extensions/room-availability-calendar-adds-joomla-booking-slots Published: 2026-08-19 Room Availability Calendar is a free Joomla component for managing reservations for rooms, appointments and other bookable time slots. This is the sort of job Joomla sites face when a business needs to show availability and accept bookings, rather than merely publish opening hours or event information. Joomla core can handle articles, menus, users, custom fields and date inputs, including its calendar form field, but it does not provide a native resource-booking workflow with conflict checking, reservation records, guest changes and notification emails. Sites usually handle that gap in one of three ways: publish a timetable with core content, build a custom booking system around a component and template overrides, or install a booking extension. A template override can change the presentation of a calendar, but it does not supply the underlying reservation logic. According to the listing, Room Availability Calendar goes beyond core with: - multiple rooms or spaces and daily, hourly or half-hour booking modes; - frontend availability and price calculation; - guest cancellation, modification and extension tools; - email notifications and administrator-managed reservations. That makes it relevant to small offices, salons, fitness businesses, classrooms, coworking operators and property or room-rental sites that do not need online payments in the basic setup. A brochure site, a site with fixed events rather than reservable resources, or a business already using an external booking service has little reason to install it. The directory lists it as a free download from Darko, under the room availability calendar section, with a GPLv2-or-later licence and Joomla 4 and 5 compatibility. The page shows no reviews and one other extension from the developer. It points to a separate Pro edition for Stripe or PayPal, an Events module and bulk import, but gives no price. Before installing, check the documentation and support arrangements, email configuration, timezone and recurrence handling, privacy implications, upgrade path, and exactly which features remain in the free edition. Listed on the [Joomla Extensions Directory](https://extensions.joomla.org/extension/calendars-a-events/room-availability-calendar/). --- # Automatic resizing and WebP conversion for Joomla images Section: Extensions URL: https://joomclub.net/extensions/automatic-resizing-and-webp-conversion-for-joomla-images Published: 2026-08-19 Aura Optimize scans Joomla image files, resizes them on the server, sends them to a cloud service for compression and can create WebP replacements. This is a site-speed task because image libraries tend to accumulate oversized uploads, uncompressed originals and formats that deliver more bytes than necessary. Joomla core provides the Media Manager and image-handling tools used by editors, but it does not generally scan an existing library, automatically compress every new image, or run a WebP replacement workflow. A template override can change how images are displayed, including responsive markup, but it does not reduce the source files themselves. That leaves site owners with manual editing, image software outside Joomla, or an extension. According to the listing, Aura Optimize goes beyond those core and presentation-layer options by combining local resizing through `Imagick` or `GD`, cloud compression, bulk queues and Joomla Scheduled Tasks. Its optional WebP process can also update image paths in several Joomla content locations, though that behaviour has not been tested by JoomClub. It is aimed at image-heavy sites, publishers or agencies maintaining existing libraries, and teams that want scheduled processing rather than asking every contributor to prepare files correctly. A small site with few images, a disciplined editorial workflow, or a CDN that already handles optimisation has less obvious reason to install it. The directory lists it as commercial with a free tier: 50 MB of monthly cloud compression is included, while Growth and Infinite plans add capacity. The listing shows Brett Ransley as developer, four other extensions, and no reviews. It specifies Joomla 5 and 6 and PHP 8.1+, but does not give plan pricing or explain API data handling, retention, failure recovery, or backup management in detail. Those points should be checked before installation. Listed on the [Joomla Extensions Directory](https://extensions.joomla.org/extension/hosting-a-servers/site-speed/aura-optimize-automatic-image-optimisation/). --- # Next Exams adds a full assessment workflow to Joomla Section: Extensions URL: https://joomclub.net/extensions/next-exams-assessment-workflow Published: 2026-08-19 Next Exams is an assessment system for building, running, grading and reporting on exams inside a Joomla site. The job is to let a Joomla site create reusable question banks, deliver timed or practice exams, mark responses and issue certificates. This need arises because Joomla core is a content management system, not a learning-management or examination platform. Core can handle users, groups, access levels, custom fields and ordinary form-based content, but it does not provide a question bank, exam timer, automatic grading, certificate workflow or invigilation board. A template override could change the presentation of an existing form, and bespoke development could assemble parts of the workflow, but sites usually reach for an extension when assessment is central. According to the listing, Next Exams goes beyond those core building blocks with nine question types, randomised exam pools, server-side timing, autosave, partial-credit grading, essay review, analytics, certificates and LTI 1.3 integration. It is aimed at training providers, schools, tutors, certification programmes and recruitment teams that want assessments hosted with their Joomla data. It may also suit a Joomla site acting as an assessment tool for another LMS. A brochure site, blog, shop or membership site with no exams, scored quizzes or certificates has no obvious use for it. Before installing, check the commercial terms: the listing does not say whether Next Exams is free or paid, or disclose a price. The developer is NextSoftware Team; the directory shows three other extensions from the developer and zero reviews for this listing. It also does not state supported Joomla versions, hosting requirements, backup or migration procedures, support arrangements, or whether every integration requires separate configuration. Those details matter for a high-stakes assessment system. Listed on the [Joomla Extensions Directory](https://extensions.joomla.org/extension/living/education-a-culture/next-exams/). --- # Room Availability Calendar Pro adds paid Joomla bookings Section: Extensions URL: https://joomclub.net/extensions/room-availability-calendar-pro-paid-joomla-bookings Published: 2026-08-19 Room Availability Calendar Pro is a paid Joomla extension for taking availability-based bookings with online payment and guest account features. Joomla core can publish accommodation, venue or service information through articles, categories, custom fields and menus, and it can handle ordinary user accounts and contact forms. It does not provide a complete resource-availability calendar with reservations, payment collection, booking history and administrative booking workflows out of the box. Sites usually fill that gap with a booking extension, or build a narrower solution with custom fields, forms and a template override. A template override can change how existing content is displayed, but it cannot by itself prevent double bookings or process payments. According to the listing, this extension goes beyond basic availability and reservation handling with Stripe and PayPal payments, payment links sent by administrators, guest booking history, CSV reservation import, editable email templates, events and reporting. It is aimed at hotels, guesthouses, apartment operators, property managers, fitness and wellness businesses, restaurants and event venues that need online payment at booking. A brochure site, a business that accepts reservations by phone, or a site that only needs a simple events calendar has little reason to install it. The listing marks it as a paid download under the GPLv2 or later licence and says there are no subscriptions, but it does not show the price here. Before installing, check payment gateway requirements, cancellation and refund handling, tax and currency support, calendar conflict rules, email delivery, privacy implications and the scope of reporting. Darko has one other directory extension listed, while this entry has no reviews. The listing states Joomla 4 and 5 compatibility, but leaves the exact payment setup, support terms and limits of the planned mobile app and multi-property features unanswered. Listed on the [Joomla Extensions Directory](https://extensions.joomla.org/extension/calendars-a-events/room-availability-calendar-pro/). --- # Cookieless analytics without Joomla database tracking Section: Extensions URL: https://joomclub.net/extensions/cookieless-analytics-without-joomla-database-tracking Published: 2026-08-17 StatJolt is a Joomla plugin that sends page-view and performance data to its external analytics service without using cookies or storing tracking records in Joomla. Its immediate job is to place an analytics snippet on every front-end page, so the service can report visitors, traffic sources, pages, devices and site performance. Joomla core does not provide a general-purpose visitor analytics dashboard. A site owner can add a provider's script to a template, a custom module or template code, while a template override is mainly for changing rendered markup rather than managing site-wide tracking. Separate analytics extensions can collect data locally, but that means database growth and additional maintenance. According to the listing, StatJolt moves collection to its own service and adds reports for Core Web Vitals, journeys, funnels and JavaScript errors. The developer also claims that it uses no cookies or personal data and therefore avoids a consent banner on most sites; those are claims to verify against the service's documentation and your legal requirements. This is aimed at publishers, small businesses, agencies and freelancers that want traffic answers without configuring GA4 or operating Matomo. Sites that need no visitor measurement, require analytics to remain entirely on their own infrastructure, or cannot accommodate the service's on-site badge have little reason to install it. - The Joomla plugin is free and GPL-licensed. The listing says the service is free for low-traffic sites, but displays a badge that cannot be disabled. - The directory marks it as new and shows zero reviews. It offers no meaningful track-record evidence for developer Gabor Liktor beyond this listing. - Check supported Joomla versions, the service's retention and export terms, data-processing arrangements, traffic limits and pricing above the free tier. The listing also leaves the external service's exact hosting, account controls and backup arrangements unanswered. Listed on the [Joomla Extensions Directory](https://extensions.joomla.org/extension/site-management/analytics/statjolt-easy-to-use-web-analytics/). --- # SkynetAccessibility adds AI captions to Joomla videos Section: Extensions URL: https://joomclub.net/extensions/skynetaccessibility-adds-ai-captions-to-joomla-videos Published: 2026-08-17 A Joomla 5 and 6 add-on that connects published videos to a metered subtitle service. It generates synchronised subtitles for videos published from a Joomla site. Video captions arise because audio content needs a text alternative for deaf and hard-of-hearing visitors, and can also help people watching without sound. Joomla core can store and publish media, while editors can embed YouTube, Vimeo, or self-hosted video and add caption markup such as an HTML `` element when they have a caption file. It does not transcribe video or automatically create timed captions. A template override can change the player markup, but not perform speech recognition. This add-on goes beyond those options by, according to the listing, sending supported videos through AI speech recognition, producing captions in more than 50 languages, and providing processing and usage information in a dashboard. It is aimed at sites with a regular video programme—newsrooms, training providers, publishers, organisations running webinars, or agencies managing many client videos—where creating caption files manually is a recurring task. A small site with few videos, captions already supplied by YouTube or Vimeo, or a team comfortable preparing `VTT` files has little obvious reason to add it. The download is listed as free, but the service uses monthly plans priced from $25 to $139 according to total playback time. Before installing, check what happens to uploaded or streamed media and transcripts, how accurate languages and speaker handling are, whether existing captions are preserved, and what “self-hosted” processing entails. The listing requires CORS access to Skynet domains and does not explain data retention, API limits, billing, or compliance guarantees. The developer has three other directory entries, but the listing shows no reviews; documentation and support are marked unavailable. Listed on the [Joomla Extensions Directory](https://extensions.joomla.org/extension/style-a-design/accessibility/skynetaccessibility-video-subtitle/). --- # External wake-ups for Joomla Scheduled Tasks Section: Extensions URL: https://joomclub.net/extensions/external-wake-ups-for-joomla-scheduled-tasks Published: 2026-08-17 QC Task Nudge & Health uses a remote service to wake Joomla's scheduler and gives administrators additional information about its condition. Joomla Scheduled Tasks only do useful work when the scheduler gets a chance to run. That usually means configuring the site's WebCron endpoint, using server-side cron or CLI tooling, or relying partly on frontend visits. Sites with long-running or resumable tasks can therefore need a more deliberate way to trigger and inspect the scheduler. Joomla core already provides the Scheduled Tasks system and WebCron support, including the task definitions and the execution of those tasks inside Joomla. According to the listing, QC Task Nudge & Health goes beyond that by registering the site's WebCron endpoint with QuantaCade's service, requesting wake-ups when work is due, increasing follow-up activity while work is reported as running, and adding an administrator dashboard for health, history, diagnostics, registration and recovery. The listing also says frontend activity can act as a scheduler-assist signal. - It is aimed at administrators of sites that depend on scheduled imports, maintenance, queues or other resumable jobs, particularly where server cron is unavailable or scheduler failures need investigation. - A small site with few or no Scheduled Tasks, dependable server cron and no need for remote monitoring has little reason to install it. The directory lists it as a free download under Core Enhancements, Administration and Site Management, with a GPLv2-or-later licence. QuantaCade has eight other extensions listed, while this entry has no reviews. Before installing, check what scheduler and WebCron data the external service stores, how its credentials are protected, what happens if that service is unavailable, and whether any usage limits or account requirements apply. The listing does not answer those questions, although it lists Joomla 5 and 6 compatibility. Listed on the [Joomla Extensions Directory](https://extensions.joomla.org/extension/core-enhancements/qc-task-nudge-health/). --- # Media Organizer audits and quarantines unused Joomla files Section: Extensions URL: https://joomclub.net/extensions/media-organizer-unused-joomla-files Published: 2026-08-17 Media Organizer helps administrators identify media files that appear to be unused and move or delete them after review. Unused images and documents accumulate on Joomla sites after articles are edited, modules are retired, or extensions are removed. Joomla's core Media Manager can browse, upload, rename and delete files, and the editor can insert media, but it does not generally map every file back to references across content, modules, templates and third-party extensions. A template override is not a natural solution to that audit; administrators usually inspect the filesystem manually, write a site-specific script, or install an extension. According to the listing, Media Organizer goes beyond those core tools by scanning for references, showing its search evidence, and offering quarantine before permanent deletion. It also claims duplicate detection, image optimisation and editing, a command-line interface, scheduled reporting and monitoring for 404 requests to quarantined paths. The listing says automated scans and the command line report only, rather than deleting files without an administrator's confirmation. This is aimed at administrators of media-heavy, long-lived sites, agencies maintaining several Joomla installations, and teams that need an auditable cleanup process. A small site with few files, or one whose administrator is comfortable checking the Media Manager and filesystem manually, may have no practical use for it. It is a paid download, but the listing does not state the price. Norbert Graup's directory profile shows five other extensions and no reviews for this one. Before installing, check the Joomla 6 compatibility claim, the scope of third-party extension profiles, quarantine retention and restoration details, backup requirements, permissions, support terms, and how false positives are handled. Listed on the [Joomla Extensions Directory](https://extensions.joomla.org/extension/administration/media-organizer/). --- # Expose Phoca Download files to YOOtheme layouts Section: Extensions URL: https://joomclub.net/extensions/expose-phoca-download-files-to-yootheme-layouts Published: 2026-08-17 Phoca Download Source connects Phoca Download files and categories to YOOtheme Pro as selectable dynamic content. The job is to let a YOOtheme Pro layout display records from Phoca Download without manually coding a separate data connection. This need exists because Joomla core does not provide either Phoca Download or a native bridge between that component and YOOtheme Pro. Joomla does provide custom fields, access control, language handling and publishing controls, but those features do not by themselves expose Phoca Download documents as selectable data in a page-builder layout. A site can usually rely on Phoca Download's own views, create a template override, or build a custom integration. According to the listing, this extension goes beyond those core facilities by exposing documents, categories and Phoca Download custom fields to YOOtheme elements, with filtering and sorting options. The listing also says that links continue through Phoca Download and that access, language and publishing rules are respected. It is aimed at teams running both Phoca Download and YOOtheme Pro that want download grids, category tiles or selected files assembled in the builder. A conventional Joomla site using neither product, or a site happy with Phoca Download's standard presentation, has no obvious use for it. The listing marks it as a paid download under the GPLv2-or-later licence, but gives no price. It names Norbert Graup as developer and lists five other extensions; this listing has no reviews. Before installing, check the commercial terms, support arrangements, documentation, and the stated requirement for Joomla 6 and YOOtheme Pro 4 or 5. The listing does not explain the exact pricing, update period, or what happens if either dependency changes. Listed on the [Joomla Extensions Directory](https://extensions.joomla.org/extension/extension-specific/phoca-download-extensions/phoca-download-source/). --- # Backlinkseller puts remote ad slots in YOOtheme Pro Section: Extensions URL: https://joomclub.net/extensions/backlinkseller-yootheme-pro-ad-slots Published: 2026-08-17 Backlinkseller adds advertising slots supplied by the Backlinkseller service as a configurable element in the YOOtheme Pro page builder. This job exists because a Joomla site may need to show links supplied for a particular page by an external advertising service, rather than links written into the page by an editor. Joomla core can publish manually entered links through articles, custom HTML modules, menus, and similar content. It does not provide a native YOOtheme Pro element that fetches Backlinkseller slots, nor does it handle that service's account, channel, caching, or page-address logic. Without an extension, a site team would typically use custom PHP, a template or child-theme override, or a YOOtheme Pro template fragment to place and format the response. According to the listing, Backlinkseller goes beyond those core options by providing its own builder element, responsive list and column settings, central service configuration, caching, and filtering of returned link data. It is aimed at a Joomla site using YOOtheme Pro 4 or 5, Joomla 6, and a Backlinkseller account—particularly a team that wants externally supplied advertising links to follow the site's builder styling. A site that does not use YOOtheme Pro, does not use Backlinkseller, or only needs fixed editorial links has no evident use for it. The extension is listed as a free download, but it requires a free Backlinkseller account and the separate YOOtheme Pro product. The developer is Norbert Graup; the directory lists five other extensions, while this listing has no reviews, so there is limited directory feedback to assess. The listing says every request passes the visitor's IP address and page address to Backlinkseller, and that the service accepts unencrypted connections. Check the privacy implications, service terms, update and support arrangements, and whether the stated Joomla 6 and YOOtheme Pro requirements match your installation. Listed on the [Joomla Extensions Directory](https://extensions.joomla.org/extension/ads-a-affiliates/backlinkseller/). --- # joomLab Gallery 1.2.0 adds visible gallery previews Section: Extensions URL: https://joomclub.net/extensions/joomlab-gallery-1-2-0-adds-visible-gallery-previews Published: 2026-08-15 joomLab has released version 1.2.0 of joomLab Gallery, a Joomla plugin for inserting multiple HTML galleries into articles or modules. The update makes selected galleries visible in the editor through image thumbnails, adds another file-upload check, and introduces two layouts without sliders. The main editor change affects how a gallery is inserted. Previously, selecting a gallery in the modal window placed a shortcode such as `{gallery ID}` in the article text. Version 1.2.0 instead displays all thumbnails from the selected gallery, making the gallery location and its contents visible while editing. The release also adds an additional check when files are uploaded. The announcement does not specify the exact validation performed or describe the change as a security fix. ## New display layouts Two additional layouts have been added following a contribution from Joomla community member Dmitry K. (@kit2m2). These layouts display images without using a slider, giving site builders alternatives to the existing gallery presentation. Finally, version 1.2.0 fixes gallery output in category blog views. The extension is intended for managing gallery files, image descriptions, and effects within each gallery, and can be used in Joomla articles or modules containing HTML. Further information is available on the [joomLab Gallery extension page](https://joomlab.ru/extentions/plugins/joomlab-gallery). --- # Easy Tab Title animates browser titles and favicon badges Section: Extensions URL: https://joomclub.net/extensions/easy-tab-title-animates-browser-titles-and-favicon-badges Published: 2026-08-14 Easy Tab Title changes a browser tab’s title and favicon in response to visitor actions and site rules. This need arises because a visitor can leave a tab open while moving to another task, and Joomla’s core page-title settings only define the document title shown in that tab. Core does not provide animated titles, return messages, dynamic favicon badges, or rules based on leaving, returning, scrolling, device, visitor status, or URL. A template or custom JavaScript can handle some of this, while an extension avoids adding and maintaining that code. According to the listing, Easy Tab Title goes beyond core with editable rules, presets, sequences, targeting, favicon changes, and an API for site-specific events. It is aimed at shops, campaign sites, landing pages, and agencies that want different tab behaviour on places such as product, cart, or sign-up pages. Developers may also have a use for its JavaScript hooks when a custom application needs to trigger a title or badge change. A site that needs only a fixed page title and favicon, or one that treats animated browser chrome as distracting, has little reason to install it. - The listing marks it as a paid download, but gives no price or explanation of the purchase and renewal terms. It says the license is GPLv2 or later and lists Joomla 4, 5, and 6 with PHP 8.1+. - Infyways Solutions has 94 other extensions shown in the directory; this listing has no reviews. That is a directory record, not an assessment of support or quality. - Before installing, check browser behaviour, performance, accessibility beyond `prefers-reduced-motion`, update policy, support terms, and the documentation for the API and targeting edge cases. We have not tested it. Listed on the [Joomla Extensions Directory](https://extensions.joomla.org/extension/style-a-design/titles/easy-tab-title/). --- # DleJTicket adds ticket threads, staff notes and email replies Section: Extensions URL: https://joomclub.net/extensions/dlejticket-adds-ticket-threads-staff-notes-and-email-replies Published: 2026-08-14 DleJTicket is a paid Joomla help-desk extension for handling support conversations as tickets rather than ordinary contact-form messages. Its job is to let site users open and reply to support tickets while staff manage status, priority, assignment, replies, attachments and internal notes. This need appears when a site has ongoing customer or member support that becomes difficult to track in shared inboxes or contact forms. Joomla core provides the building blocks around it: user accounts and permissions, custom fields, Mail Templates and scheduled tasks. It does not provide a native help-desk record with a threaded conversation, ticket ownership, staff-only notes or matching replies received from a support mailbox. A template override can change the appearance of a form or ticket view, but it cannot supply that workflow. This is therefore the kind of gap sites usually address with an extension. According to the listing, DleJTicket goes beyond core by adding the ticket desk, optional email-to-ticket polling, ticket import and export, and conversion of conversations into Knowledge Base articles. It is aimed at businesses, membership organisations and service teams that need a support queue inside an existing Joomla site. A brochure site with a single contact form, or a team already working entirely in a separate help-desk service, has little reason to install it. DleJTicket is listed as a paid download, but the supplied listing does not show a price. DleJProducts has 15 other directory entries, while this listing has no reviews. The directory records Joomla 4, 5 and 6 compatibility and says the packages are separated by Joomla generation. Before buying, check the actual licence and support terms, attachment limits, privacy implications, and the requirements for mailbox polling: plus-addressing is needed, and PHP 8.4 or later needs the IMAP extension installed separately. The listing does not explain those operational details or document a migration process beyond its CSV/JSON claim. Listed on the [Joomla Extensions Directory](https://extensions.joomla.org/extension/clients-a-communities/help-desk/dlejticket/). --- # Easy Lock hides selected article text behind registration Section: Extensions URL: https://joomclub.net/extensions/easy-lock-hides-selected-article-text-behind-registration Published: 2026-08-14 Easy Lock hides selected parts of a Joomla article from guests until they log in or register. This need arises when a site wants to show enough of an article to attract readers while reserving the rest for members, subscribers, or a named user group. Joomla core can restrict an entire article, menu item, module, or other resource through access levels and user groups. It does not, by itself, provide a registration gate inside one public article with a partial preview. A template override may change presentation, but selective content removal generally calls for custom code or an extension. According to the listing, Easy Lock uses an editor shortcode to mark the protected block, optionally exposing the first paragraphs or a Read more introduction. It says the hidden HTML is removed server-side and is not included in page source, search, feeds, or modules. That is the part beyond Joomla's normal article-level access controls. The package installs content, editor-button, and system plugins, and supports Joomla 4, 5, and 6 according to the listing. The likely audience is a membership site, publication, course platform, or agency building articles with registered-only appendices. A brochure site whose pages are public, or a site already restricting complete articles rather than sections, has little reason to install it. This is listed as a paid download, although no price is shown, and it is licensed GPLv2 or later. Infyways Solutions has 94 other extensions listed; Easy Lock has no reviews. Before installing, check pricing, support and update terms, the PHP 8.1+ requirement stated in the listing, and how the shortcode behaves in your editor, feeds, caching, structured data, and multilingual setup. The listing does not explain those details, and we have not tested the software. Listed on the [Joomla Extensions Directory](https://extensions.joomla.org/extension/authoring-a-content/easy-lock/). --- # Restoring image-to-image navigation in JoomGallery 4 Section: Extensions URL: https://joomclub.net/extensions/restoring-image-to-image-navigation-in-joomgallery-4 Published: 2026-08-13 JO JoomGallery Navigation adds previous and next controls to JoomGallery's single-image view so visitors can move through a category without returning to its thumbnail grid. This gap exists because JoomGallery 3 included image-to-image navigation, while the JoomGallery 4 rewrite did not, according to the listing. Joomla core does not provide this kind of front-end browsing for JoomGallery categories: its media tools and fields can manage or display media, but they do not add navigation to another extension's image view. Site owners would normally accept JoomGallery's existing interface, build a custom integration or template override, or install an extension. The developer says this one goes beyond a template change by reading JoomGallery's tables and filtering images according to ordering, publication, approval and access settings; those are claims from the listing, not independently tested results. It is aimed at sites using JoomGallery 4 as a browsable photo archive, portfolio or catalogue where visitors are expected to inspect several images in sequence. A site with a small number of images, no JoomGallery installation, or a workflow based on Joomla's core media features has no obvious reason to install it. The listing describes it as a free download and identifies it as a system plugin in the galleries section. Before installing, check the developer's stated compatibility with Joomla 4, 5 and 6 and confirm that the navigation is appropriate for the site's template and JoomGallery configuration. JewelOsman has 55 other directory extensions listed, while this entry has no reviews. The listing does not establish how conflicts with other navigation scripts are handled, how much configuration is required, or what support and documentation cover in practice. Test it on a copy of the site, particularly if custom CSS or access rules are important. Listed on the [Joomla Extensions Directory](https://extensions.joomla.org/extension/photos-a-images/galleries/jo-joomgallery-navigation/). --- # Easy Favicon generates site and administrator icon sets Section: Extensions URL: https://joomclub.net/extensions/easy-favicon-generates-site-and-administrator-icon-sets Published: 2026-08-12 Easy Favicon is a paid Joomla system plugin that turns a supplied image into favicon assets for the frontend and administrator area. Favicons are a small but recurring Joomla task because browsers, Apple devices and Android launchers do not all use the same image size or markup. Joomla core does not provide a control panel tool that generates this pack, manages dark-mode or maskable variants, or assigns a separate administrator icon. Site owners normally place files in a template and edit its document head, use a template’s built-in favicon settings, or install an extension. A template override or custom template edit can cover basic icons; according to the listing, Easy Favicon goes beyond that by generating several sizes, injecting the tags, removing competing template declarations, and optionally handling theme color and a manifest. This is aimed at site builders and agencies maintaining Joomla 4, 5 or 6 sites that need coordinated browser, Apple, Android and backend branding without exporting each asset manually. It has little to offer a simple site that is content with one template favicon, or a team already managing icons through its template or PWA tooling. The listing identifies Easy Favicon as a paid download from Infyways Solutions and says it has GD or Imagick requirements and PHP 8.1+. It also shows 92 other extensions from the developer and no reviews for this listing. The price, update policy, refund terms, image-processing limits, permissions, uninstall cleanup and exact interaction with existing PWA or template systems are not stated. We have not tested the plugin. Listed on the [Joomla Extensions Directory](https://extensions.joomla.org/extension/access-a-security/easy-favicon/). --- # DevArt Polls adds anonymous voting and multi-question surveys Section: Extensions URL: https://joomclub.net/extensions/devart-polls-anonymous-voting-surveys Published: 2026-08-12 DevArt Polls gives Joomla sites a component and module for anonymous polls and multi-question surveys. This need arises when a site wants to collect a choice or a set of responses rather than publish a conventional form. Joomla core does not provide a general-purpose poll or survey manager with anonymous voting, response storage, result charts and CSV export. Articles, custom fields and the core contact form can handle some surrounding content, while a template override can change presentation but cannot supply the voting workflow. Sites needing that functionality usually install an extension. According to the listing, DevArt Polls goes beyond a single poll by adding surveys, an administrator response manager, JSON definition import/export, configurable duplicate checks and optional bot protection. Its `comdevartpolls` component and `moddevartpoll` module also separate management from frontend display. It is aimed at sites running questionnaires, feedback exercises, informal elections or simple audience research, particularly where administrators need to review responses or export them. A brochure site with no interactive research, or a site already using an external survey service, has little reason to add it. - The directory marks it as a free download under the GPLv2 or later, not a paid extension. - Kostas Stathopoulos is listed as the developer; the directory shows 21 other extensions from the developer, while this entry has no reviews. - Before installing, check privacy and retention details for stored responses and hashed visitor data, accessibility of the charts and voting interface, notification and moderation options, and how CAPTCHA services are configured. The listing specifies Joomla 6.x, PHP 8.3+ and MySQL/MariaDB, but does not explain migration, support terms or update policy. Listed on the [Joomla Extensions Directory](https://extensions.joomla.org/extension/contacts-and-feedback/polls/devart-polls/). --- # Aura Forms adds visual multi-step form building to Joomla Section: Extensions URL: https://joomclub.net/extensions/aura-forms-visual-multi-step-form-building Published: 2026-08-12 Aura Forms lets Joomla site owners build, publish and manage forms through a visual builder rather than assembling each form by hand. Forms appear on Joomla sites for more than simple contact requests: businesses collect leads, organisations run surveys, and teams need uploads, consent fields or multi-step applications. Joomla core already provides the Contact component, contact forms, mail handling and standard field customisation. A template override can change the presentation, but it does not turn the core contact form into a visual form designer. That leaves an extension when a site needs capabilities outside that basic model. According to the listing, Aura Forms goes beyond core contact handling with drag-and-drop rows and columns, multiple pages with per-page validation, conditional visibility, submissions management, CSV export and retention rules. It also offers placement through a menu item, module or content shortcode, plus listed integrations with Joomla mail, optional SMTP, Turnstile and reCAPTCHA. Its likely audience is a site builder or small web team creating several lead, registration, enquiry or survey workflows without coding each one. A site with one ordinary contact page, or one already using a suitable form extension, has little reason to add it. The listing marks Aura Forms as a paid download under the GPLv2 or later license. Brett Ransley has two other extensions listed, while Aura Forms has no reviews. Before buying, check the price, update and support terms, documentation, migration options, and how file uploads and stored submissions are secured. The listing does not explain which AI service processes prompts, whether data leaves the site, or what limits apply to the AI feature. We have not tested the extension. Listed on the [Joomla Extensions Directory](https://extensions.joomla.org/extension/contacts-and-feedback/contact-forms/aura-forms-ai-form-builder-for-joomla/). --- # Aura SEO adds AI tools, sitemaps and schema controls Section: Extensions URL: https://joomclub.net/extensions/aura-seo-ai-tools-sitemaps-schema-controls Published: 2026-08-12 Aura SEO is a paid Joomla SEO suite that combines site audits, sitemap and metadata management, structured data, and optional AI generation tools. In plain terms, Aura SEO gives administrators one place to inspect pages and manage search-related data, with optional AI assistance for creating some of it. This job arises because Joomla core covers the foundations, but not the whole SEO workflow. Articles and menu items have fields for page titles, descriptions and robots instructions, while SEF URLs and basic metadata can be configured in core. A template override can change how existing metadata or structured markup is presented. Core does not provide this listing's combined crawl audit, XML sitemap management, per-URL canonical and Open Graph controls, `llms.txt` handling, or scheduled AI article generation. The developer says Aura also adds JSON-LD tools and AI-generated metadata, schema, keyword ideas and articles, so it goes beyond Joomla's built-in editing fields rather than merely replacing them. It is aimed at site owners, agencies or content teams managing many pages and wanting central controls for technical SEO, social metadata and structured data. A small brochure site with a few manually maintained pages, or a team that already handles SEO through its template and content workflow, may have little reason to install it. The listing identifies Aura SEO as a paid download by Brett Ransley, licensed GPLv2 or later. The directory shows two other extensions from the developer and no reviews. Before buying, check the price, what the required Download ID entails, AI credit costs, the AI provider and data handling, and how scheduled content is moderated. The requirements say Joomla 5 and 6 with PHP 8.1+, while the compatibility badges also show Joomla 4; that discrepancy needs clarification. The listing also leaves audit limits, update and support terms, and non-AI feature restrictions unanswered. Listed on the [Joomla Extensions Directory](https://extensions.joomla.org/extension/site-management/seo-a-metadata/aura-seo-ai-seo-for-joomla/). --- # Mail Log keeps Joomla mail activity in the administrator Section: Extensions URL: https://joomclub.net/extensions/mail-log-keeps-joomla-mail-activity-in-the-administrator Published: 2026-08-12 Mail Log adds an administrator-side record of emails sent through Joomla, including failed sends and selected message details. Email troubleshooting and accountability come up when a site sends password resets, order notices, contact messages or other automated mail but nobody can tell what was attempted. Joomla's mailer handles sending and can report transport errors to the calling process, but core Joomla does not provide a general administrator inbox or a persistent, searchable audit trail of every message and its recipients. Joomla's action-log features cover recorded user and administrator actions, not a complete mail archive. Sites usually handle this with server or mail-provider logs, application-specific logging, or a template and component workflow where only a particular form or transaction is tracked. A mail-log extension goes further by observing mail sent through Joomla's mailer rather than requiring each component to implement its own record. According to the listing, Mail Log can store failures with the mail server's error, apply storage rules, limit sensitive content, alert administrators, export CSV, show volume and failure statistics, and resend messages. Those are additions to Joomla core, not replacements for the mail transport or proof that a message reached an inbox. It is aimed at administrators of sites with several extensions sending important mail, support teams investigating missing notifications, and organisations that need a local audit trail. A small brochure site with little automated mail, or a team already satisfied with provider-side logs, may have no reason to add it. The listing marks Mail Log as a free download from Norbert Graup, in the directory's `mail log` section, and lists Joomla 6 compatibility. It shows two other extensions by the developer but no reviews for this one. Before installing, check the exact permission model, retention and cleanup defaults, what “delivery succeeded” means, the encryption and attachment handling in practice, and whether the claimed resend safeguards fit your privacy policy. The listing does not state broader Joomla-version support, resource requirements, or the detailed configuration and update history. Listed on the [Joomla Extensions Directory](https://extensions.joomla.org/extension/administration/mail-log/). --- # DPCalendar bookings entered from the Joomla backend Section: Extensions URL: https://joomclub.net/extensions/dpcalendar-backend-bookings-entered-from-joomla-backend Published: 2026-08-12 DPCalendar - Backend Booking gives administrators a backend form for recording DPCalendar Pro bookings made by phone, email or paper. Joomla core has users, access control and custom fields, but it does not provide an event-booking system. Sites usually add an event extension, then either use its front-end booking form or build a custom administrator workflow. A template override can change how existing bookings are displayed, but it cannot by itself create this entry process. According to the listing, DPCalendar Pro already handles online bookings; this paid add-on extends that system with administrator-side entry, including its tickets, prices, fields, capacity rules and booking statuses. The likely audience is a club, venue, course provider or events team that receives registrations through several channels and needs staff to record them centrally. It may also suit teams handling group bookings, guest records or waiting lists from the backend. A site that does not use DPCalendar Pro, accepts bookings only online, or has no event-registration workflow has no obvious reason to install it. Before installing, note that the listing marks it as a paid download and requires DPCalendar Pro 10.11.x with its booking system. It lists Joomla 6 compatibility. The developer is Norbert Graup; the directory shows two other extensions and no reviews for this listing, which is limited evidence of directory track record. The page does not state the price, licensing terms for DPCalendar Pro, support arrangements, or how updates are handled. We have not tested the add-on, so claims about validation, recurring events and permissions should be checked against the documentation and a staging site. Listed on the [Joomla Extensions Directory](https://extensions.joomla.org/extension/calendars-a-events/dpcalendar-backend-booking/). --- # Notion databases as YOOtheme Pro content sources Section: Extensions URL: https://joomclub.net/extensions/notion-databases-as-yootheme-pro-content-sources Published: 2026-08-12 Notion Source lets YOOtheme Pro sites use shared Notion databases as content sources. This job comes up when a team keeps structured information in Notion but publishes its website through Joomla and YOOtheme Pro. Joomla core can manage articles, categories, custom fields and other native content, and a developer can use a template override to change how that content is displayed. Core does not provide a Notion connector or turn a Notion database into selectable YOOtheme Pro data. According to the listing, Notion Source goes beyond those options by reading shared databases, exposing their properties to the builder, and applying filters, sorting and field mapping. It is aimed at sites whose editorial or operational data already lives in Notion: directories, catalogues, team resources or other structured collections assembled by a small web team. A conventional Joomla site using articles and custom fields, or a site with no YOOtheme Pro dependency, has little reason to install it. It is also not a general-purpose Notion synchronisation layer based on the information provided. The listing marks it as a paid download, while saying the extension itself can be used with a free Notion integration token; a Download Key is required for automatic updates. It requires YOOtheme Pro 4 or 5 and Joomla 6. Norbert Graup has two other extensions listed, and this entry has no reviews. Before committing, check the price, update-key terms, support arrangements, Notion API limits, handling of deleted or changed records, and whether caching is suitable for the site's publishing needs. The listing does not explain those points, nor does it state a broader Joomla compatibility range. Listed on the [Joomla Extensions Directory](https://extensions.joomla.org/extension/content-sharing/notion-source/). --- # A Joomla module for GSAP slideshow transitions Section: Extensions URL: https://joomclub.net/extensions/dc-gsap-slider-gsap-slideshow-transitions Published: 2026-08-12 DC GSAP Slider turns a sequence of images into a responsive presentation module with animated transitions, text overlays and links. Its job is to display image slides with configurable animation, navigation, autoplay and optional headings, descriptions and call-to-action links. This need arises when a Joomla site wants a visual hero, campaign opener or portfolio feature rather than a static image or a basic carousel. Joomla core provides the Media Manager, custom content and module positions, but it does not provide a general-purpose slideshow module with an administration interface for repeatable slides and GSAP-style transition modes. A developer can use a template override or custom JavaScript to build a presentation around core content, while many site owners use a slideshow extension instead. According to the listing, DC GSAP Slider goes beyond those core building blocks with 16 transition modes, per-device height settings, overlay controls, and wheel, touch or drag navigation. It is aimed at designers, agencies and site teams creating image-led homepages, landing pages, portfolios or campaign pages where motion is part of the presentation. A mostly text-based site, or one needing only a single image, an article intro or a simple static module, has little reason to install it. The listing identifies it as a free download from Pawel Nosko and shows GPLv2 or later licensing. The directory lists 17 other extensions by this developer, but this entry has no reviews. Check the apparent compatibility mismatch: the requirements say Joomla 6.x and PHP 8.3 or later, while the directory compatibility badges show J5 and J6. The listing also leaves accessibility behaviour, performance on image-heavy pages, image optimisation, browser fallback details and the scope of support or documentation unclear. Listed on the [Joomla Extensions Directory](https://extensions.joomla.org/extension/photos-a-images/slideshow/dc-gsap-slider/). --- # Scanning Joomla PHP files for malware and backdoors Section: Extensions URL: https://joomclub.net/extensions/scanning-joomla-php-files-for-malware-and-backdoors Published: 2026-08-12 Scan Malware is a paid Joomla extension from JoomSAFE that checks PHP files for code associated with malware, web shells and backdoors. Malware checks become relevant when a Joomla site has been hacked, inherits an uncertain deployment, or needs a way to investigate unexplained redirects, resource use or unauthorised access. Joomla core provides updates, user and permission management, and the normal tools for maintaining the CMS; it does not include a general-purpose scanner that inspects installed PHP files for malicious code. A template override is also the wrong tool for this job: overrides change output, not server-side file contents. Site owners commonly use host-level malware scanning, inspect files manually, restore from a known-clean backup, or install a security extension. According to the listing, Scan Malware goes beyond Joomla core by examining PHP files for suspicious patterns and threats associated with infected Joomla installations. The page does not explain its detection method, whether it can quarantine or remove files, or how it handles false positives. This is aimed at administrators, agencies and incident-response teams responsible for Joomla sites where file integrity needs checking. A small, newly deployed site with trusted hosting scans and a clean, controlled deployment may have little reason to add it. The Directory lists it in `Scan Malware` under Access & Security as a paid download, licensed GPLv2 or later. It says Joomla 4, 5 and 6 are supported, but gives no price. The listing shows no reviews and provides no broader developer track record beyond the JoomSAFE name. Before buying, check scan coverage, cleanup and quarantine features, resource use, exclusions, update and support terms, backup requirements, and the handling of false positives. The page mentions the Joomla Update System, a demo and documentation, but does not provide enough detail here to assess them. Listed on the [Joomla Extensions Directory](https://extensions.joomla.org/extension/access-a-security/scan-malware/). --- # Twelve article layouts in one Joomla module Section: Extensions URL: https://joomclub.net/extensions/twelve-article-layouts-in-one-joomla-module Published: 2026-08-12 Easy Articles Grid is a paid Joomla site module for presenting standard Joomla articles in configurable grids, lists, carousels and other layouts. Joomla already handles basic article presentation through category blog and list menu items, featured-article pages, and modules such as Latest Articles and Articles Category. Those core options provide familiar ordering, pagination and article links, while a template override can change the markup and styling. A site needing a different presentation often turns to an extension instead of maintaining those overrides. According to the listing, Easy Articles Grid goes beyond that baseline with twelve structural layouts and ten visual themes in one module. It also claims Ajax-based load more, infinite scroll and numbered pagination, plus optional category pills and live search. Image sources and display treatment, typography, colour tokens and per-instance custom CSS are configurable. Joomla core does not offer this particular combination as a single article-display module; its Smart Search is also not the same as a live, module-scoped title and intro search. It is aimed at editors or site builders running a magazine, newsroom, blog, portfolio or content hub who want several article presentations without hand-building overrides or using a page builder. A small brochure site with a handful of pages, or a site satisfied with Joomla’s category blog and standard article modules, is unlikely to need it. The directory lists Infyways Solutions as the developer and places the extension in `articles display`. It is a paid download, but the listing gives no price or licence terms beyond GPLv2 or later. The developer has 91 other directory extensions, although that number says nothing about their maintenance or support record. Before installing, check the actual purchase terms, update policy, accessibility and SEO output, cache and Ajax behaviour, custom-field requirements, and whether the stated Joomla 4, 5 and 6 and PHP 8.1+ support matches the target site. Listed on the [Joomla Extensions Directory](https://extensions.joomla.org/extension/news-display/articles-display/easy-articles-grid/). --- # A swipeable HTML5 game feed for Joomla pages Section: Extensions URL: https://joomclub.net/extensions/swipeable-html5-game-feed-for-joomla-pages Published: 2026-08-12 Plays Games Widget embeds a feed of browser-based HTML5 games in Joomla pages so visitors can play them without leaving the site. Joomla can already place external content on a page through a Custom HTML module or an editor that permits the required HTML, including an `iframe`. A site owner could also build a bespoke game listing with articles, custom fields and template overrides. Those options cover displaying one or several known embeds, but they do not provide a maintained game catalogue, swipeable discovery interface, game categories or visitor interactions. That is the gap this extension claims to fill: the listing says it supplies a feed of thousands of free HTML5 games, with category filtering, likes, automatic updates and adjustable display dimensions. It is therefore aimed at a gaming site, entertainment portal, magazine, blog or community that wants playable material to be a central part of the site rather than an occasional embedded game. A standard business website, documentation site or brochure-style Joomla installation has little reason to add a continuously changing game feed. Developers wanting complete control over game selection, markup, accounts or moderation may also prefer a custom implementation. According to the listing, Plays Games Widget is a free download from Rabarijaona, in the Games section, and is released under GPLv2 or later. It lists Joomla 5 and 6 compatibility and says the component includes its documentation. The directory currently shows no reviews, so there is little public user feedback there about the developer's track record or the extension itself. Before installing, check where the games and interaction data come from, their licensing and privacy implications, how moderation and removal work, and what happens if the external service changes. The listing also leaves performance, accessibility, analytics, support arrangements and the exact administration workflow unanswered. Listed on the [Joomla Extensions Directory](https://extensions.joomla.org/extension/sports-a-games/games/plays-games-widget/). --- # Gated PDF viewers inside Joomla articles Section: Extensions URL: https://joomclub.net/extensions/gated-pdf-viewers-inside-joomla-articles Published: 2026-08-12 Easy PDF places PDF documents in Joomla articles with selectable viewing modes and access controls. Joomla sites often need to publish manuals, forms, brochures or member-only documents without sending visitors to a separate document library. Core Joomla can store files in Media and editors can link to a PDF, or add suitable HTML such as an iframe where the editor and template permit it. Article and menu access levels can restrict surrounding content, but core does not provide a packaged PDF modal, thumbnail opener, viewer toolbar controls or file-level login gate. A template override is generally not the natural solution for a reusable PDF block, so site owners commonly turn to an extension. According to the listing, Easy PDF goes beyond those core options with modal, inline and download-only modes, an editor button and shortcode syntax. It also claims controls for download and printing, login or registration prompts, optional access levels, and signed streaming intended to make direct file-path guessing less useful. The listing explicitly describes those download and print restrictions as soft deterrents rather than complete protection. This is aimed at sites publishing documents inside article pages, particularly membership sites, product-support portals, training sites and brochure-led websites. A basic site that only needs a downloadable public PDF link has little reason to add it; so does a team already handling documents through a dedicated library or DRM service. - Easy PDF is listed as a paid download from Infyways Solutions. The directory shows 91 other extensions from the developer, but this listing has no reviews. - The listing says Joomla 4, 5 and 6 and PHP 8.1+, but leaves pricing, update and support terms unclear. Check how access rules interact with ACL, caching and direct Media URLs, and assess whether signed streaming meets the site's actual security and accessibility requirements. Listed on the [Joomla Extensions Directory](https://extensions.joomla.org/extension/style-a-design/print-a-pdf/easy-pdf/). --- # Product Order History adds per-product sales records to HikaShop Section: Extensions URL: https://joomclub.net/extensions/product-order-history-per-product-sales-records-hikashop Published: 2026-08-12 Product Order history for HikaShop shows the orders containing a selected product inside that product’s backend page. This is a back-office reporting task rather than a storefront feature. Joomla core has no ecommerce catalogue or order system, so it cannot provide this history on its own. HikaShop supplies the product and order records, but the listing describes an additional view that connects one product to its related orders. According to the listing, the view includes order number, customer, dates, quantity, status and total, with ten rows per page and a link to open each order. Sites can handle this manually by searching orders in HikaShop, exporting data, or commissioning custom development. A template override is not the natural solution: the requested change is in the administrator product screen, not the public product layout. This plugin goes beyond Joomla core and, according to the listing, beyond HikaShop’s standard product page by presenting the product-specific order history there. It is aimed at stores whose staff need to investigate sales of individual products, check purchasing history, or review product-level order data without repeatedly searching the order list. A brochure site, content site, or HikaShop installation with few products and no need for that operational view has little reason to install it. The directory marks it as a free download and lists Hikari Software Team as the developer, with 71 other extensions shown on the developer profile. Before installing, note the conflicting license information: the text says GPL v3, while the metadata says GPLv2 or later. The listing requires HikaShop 3.3 or newer and shows Joomla 3 through 6 compatibility, but does not explain update policy, support arrangements, permissions, performance on large order tables, or whether the displayed customer data is affected by privacy controls. Documentation is listed as unavailable, and there are no reviews. Listed on the [Joomla Extensions Directory](https://extensions.joomla.org/extension/extension-specific/hikashop-extensions/product-order-history-for-hikashop/). --- # Site-Check applies approved accessibility fixes server-side Section: Extensions URL: https://joomclub.net/extensions/site-check-applies-approved-accessibility-fixes-server-side Published: 2026-08-12 Site-Check Accessibility connects Joomla to a Site-Check account so approved accessibility changes can be applied to the HTML delivered by the site. Accessibility work comes up because Joomla core does not audit a finished site or automatically correct every accessibility issue in its rendered pages. Core provides accessible templates and markup improvements, while developers can fix known problems in template code or use template overrides for component and module output. That is workable when the issues are understood and limited in scope. A service connector such as this goes beyond core by retrieving externally approved changes and, according to the listing, applying them server-side without editing the template. It also exposes an optional visitor assistance overlay; neither automated remediation nor such an overlay is a general Joomla core feature. This is aimed at site owners, agencies, or compliance teams managing established sites where accessibility findings are handled in a separate Site-Check workflow and need to be propagated without maintaining multiple overrides. A small site with a well-maintained accessible template, no external audit process, or no Site-Check account has little reason to install it. The extension is a free download, but it is not standalone: an active Site-Check account or subscription is required, and the listing gives no price. The developer is shown as “---”; although the page mentions 10 other extensions, it provides no identifiable developer track record to assess. Check the service terms, privacy and data handling, the exact fixes covered, rollback behaviour, and subscription limits. Support and documentation are listed as unavailable. The listing states Joomla 4, 5, and 6 with PHP 8.1 or newer. Listed on the [Joomla Extensions Directory](https://extensions.joomla.org/extension/style-a-design/accessibility/site-check-accessibility/). --- # Email Remover replaces public email addresses before HTML leaves Joomla Section: Extensions URL: https://joomclub.net/extensions/email-remover-public-email-protection Published: 2026-08-12 Email Remover is a free Joomla system plugin that changes how email addresses appear in the generated front-end page. Email addresses end up in page source through article text, modules, custom HTML and contact details. That makes them easy targets for automated harvesting. Joomla already includes the `Email Cloaking` content plugin, which obfuscates email addresses while generally preserving a usable address for visitors. A template override is not normally the right tool, because the address may come from many components and content fields. Sites that need a stricter result usually add an extension that processes the rendered response. According to the listing, Email Remover goes beyond core cloaking by removing addresses altogether, substituting text or HTML such as a contact-form link, or creating a PNG instead of leaving literal address text in the source. The developer also says it handles both plain text and `mailto:` links, with address and domain exceptions. That makes it relevant to public sites that publish staff or departmental contact details but want to limit harvesting, especially where a form or image-based presentation is acceptable. It has little to offer a site with no public email addresses, or one that needs every address to remain selectable and machine-readable for accessibility, copying or integration. - The listing marks it as a free download under GPLv2 or later. - It shows no reviews, says documentation is not available, and lists the developer as having one other directory extension. - Before installing, check accessibility and indexing implications of PNG output, whether the required GD support is available, how it behaves with cached or dynamically inserted content, and whether replacing addresses affects structured data or legal contact requirements. The claims have not been tested here. Listed on the [Joomla Extensions Directory](https://extensions.joomla.org/extension/access-a-security/site-security/email-remover/). --- # Public gateway URLs for Joomla’s protected pages Section: Extensions URL: https://joomclub.net/extensions/public-gateway-urls-for-joomlas-protected-pages Published: 2026-08-12 Quick Account Gateway creates public URLs that send visitors through Joomla’s login process before taking them to a protected page. The job is to give a protected Joomla destination a public-looking entry URL, redirect guests to login, and preserve the destination for the return journey. This comes up because sites often want to share a stable link to a download, support area, or member page without exposing the protected URL in the first link. Joomla core already supplies user accounts, access levels, protected menu items and content, plus login modules and menu items with configurable redirects. A template override can change the login page’s presentation, but it is not normally the tool for creating destination-specific gateway paths. The developer says this extension goes further by adding those public gateway URLs and automatically returning users to the originally requested page after authentication, rather than sending everyone to one configured destination. That makes it relevant to membership sites, customer portals, support sites and teams publishing several protected resources where each shared link should lead to a particular destination. A small brochure site with only public content, or one protected area with an adequate fixed login redirect, has little reason to install it. Quick Account Gateway is listed as a free download in the Directory’s `site access` section. The listing identifies Stephan Römer as the developer and shows 20 other extensions, but no reviews. It states compatibility with Joomla 4.4, 5 and 6. Before installing, check how gateways are configured, whether aliases can conflict with existing routes, how multilingual URLs and failed logins are handled, and whether arbitrary return URLs are restricted safely. The listing provides no documentation or support, and does not explain those details or the update and maintenance arrangements. Listed on the [Joomla Extensions Directory](https://extensions.joomla.org/extension/access-a-security/site-access/quick-account-gateway/). --- # Mass Schedule Manager handles multi-church service times Section: Extensions URL: https://joomclub.net/extensions/mass-schedule-manager-multi-church-service-times Published: 2026-08-12 Mass Schedule Manager manages and publishes Mass times for one or more churches, including seasonal schedules and date-specific exceptions. This is a recurring scheduling problem because church timetables are not just static pages: Saturday vigils, feast days, summer hours and parish-specific exceptions can all change what visitors should see next. Joomla core can publish articles, custom fields and modules, and its publishing dates can handle some one-off timing. A team could also maintain a timetable in an article and use a template override to control its presentation. Core does not provide a dedicated recurring schedule model with vigil calculations, date-range replacements or a “next Mass” result. According to the listing, this extension adds those rules, plus a separate `mod_messe` module for placing a church’s schedule in a module position. The intended audience is a parish, diocese or religious community with several churches, changing seasonal timetables, or administrators who need to update schedules without editing page markup. A single-church site with a fixed weekly timetable, or a site that only needs an occasional announcement, probably has no use for it and can use an article or custom fields instead. Before installing, note that the listing does not state a price or label the package as free; it does say the source is released under GPL v2 or later. It identifies Gioacchino Cipriano as the developer, but shows zero reviews and no broader directory track record. The listing specifies Joomla 5.x or 6.x, PHP 8.1 or higher, and MySQL or MariaDB with InnoDB and utf8mb4. It does not explain migration or import options, timezone handling, frontend accessibility, update support, or how existing timetable data should be recovered if the component is removed. Listed on the [Joomla Extensions Directory](https://extensions.joomla.org/extension/living/religious-events/mass-schedule-manager/). --- # JO Popup Login turns Joomla's login module into a popup Section: Extensions URL: https://joomclub.net/extensions/jo-popup-login-popup-login-module Published: 2026-08-12 JO Popup Login places Joomla's standard user login form in a popup so visitors can authenticate without leaving the page they are viewing. This need comes up on sites where login is a secondary action rather than a destination: community portals, member areas, shops, and sites where users may sign in repeatedly while browsing. Joomla core already provides the `mod_login` module and `com_users` authentication, including login and logout, redirects, Remember Me, password recovery, registration links, and access-controlled menu items. What core does not provide in the standard module is this popup presentation or an AJAX login flow that keeps the visitor on the current page. Without an extension, a developer can build that behaviour with JavaScript and a template override, while accepting the maintenance burden of connecting it to Joomla's login endpoints. JO Popup Login packages that extra interface as a module. According to the listing, it also adds configurable trigger styling, animations, a fullscreen backdrop, and a logged-in dropdown that can use an existing menu. It is aimed at site owners who want a prominent sign-in control without sending users to a separate login view, especially teams that do not want to maintain custom template code. A conventional content site with no registered users, or one happy with Joomla's normal login page or module, has little reason to install it. The listing marks it as a free download and says it supports Joomla 4, 5, and 6. JewelOsman has 54 other extensions listed, while this entry has no reviews. Before installing, check its behaviour with caching, security extensions, template JavaScript, multilingual labels, and custom authentication plugins. The listing does not explain update or support arrangements, browser testing, accessibility testing beyond its own claim, or how failed AJAX requests and third-party login methods are handled. We have not tested the extension. Listed on the [Joomla Extensions Directory](https://extensions.joomla.org/extension/access-a-security/jo-popup-login/). --- # Easy Accessibility adds a self-hosted visitor toolbar Section: Extensions URL: https://joomclub.net/extensions/easy-accessibility-self-hosted-visitor-toolbar Published: 2026-08-12 Easy Accessibility is a paid Joomla site module that gives visitors a configurable front-end toolbar for changing how content is displayed. Accessibility work arises because a Joomla site’s template, content and third-party components may not suit every visitor’s needs. Joomla core provides the underlying markup, menu and module systems, access controls, language assignment and template structure, but it does not provide a general-purpose front-end toolbar for changing text size, colours, reading modes or speech. A developer can address individual problems with CSS, JavaScript and a template override; that is often the right route for fixing headings, focus states, contrast and other source-level issues. An extension is the more direct option when visitors need adjustable preferences without a custom interface. According to the listing, Easy Accessibility goes beyond core by providing those visitor controls in one module. It says administrators can reorder or disable controls, change the launcher’s appearance and assign it to selected menus. The claimed controls include text and spacing adjustments, contrast and colour filters, reading aids, skip-to-content navigation and device-based speech. The listing also says preferences remain on the visitor’s device. This is a presentation aid, not a replacement for accessible content or template code: the developer explicitly says it does not rewrite article source and does not claim WCAG AA certification. It is aimed at site owners or teams that want an optional accessibility panel across public content, especially where they need configurable controls without loading a third-party overlay. Sites with a carefully maintained accessible template and no demand for visitor-side adjustments may have no reason to install it. Before installing, note that the directory marks it as a paid download and lists Joomla 4, 5 and 6 compatibility, PHP 8.1+, and no jQuery or CDN widget. Infyways Solutions has 91 other extensions shown in the directory, but the listing provides no independent assessment of that track record. Check the price, licensing and support terms, browser and assistive-technology coverage, performance on your pages, and whether its filters work with your template and protected elements. Reviews are currently absent, and the listing does not explain update terms or provide test results. Listed on the [Joomla Extensions Directory](https://extensions.joomla.org/extension/style-a-design/accessibility/easy-accessibility/). --- # A server-side pass for Joomla’s missing alt and ARIA markup Section: Extensions URL: https://joomclub.net/extensions/server-side-pass-for-joomlas-missing-alt-and-aria-markup Published: 2026-08-12 Easy WCAG is a paid Joomla system plugin that modifies rendered HTML to address selected accessibility gaps and flags others for review. Easy WCAG, from Infyways Solutions, processes the HTML response after Joomla has built a page. According to the listing, it can add or adjust items such as image `alt` text, iframe titles, form labels, language attributes, skip links and link attributes, while reporting issues it says are unsafe to invent. These problems arise because Joomla’s core can provide accessibility-related fields and markup, but the final result also depends on the template, extensions and editor content. A site owner can correct individual output with content changes or a template override. Core does not generally provide a post-render pass that checks duplicate IDs, broken ARIA references or unnamed controls across the delivered page. The extension goes beyond those options by rewriting the live response, offering a report-only mode, and allowing custom replacements, regular expressions, attributes or PHP rules. The listing says it does not address colour contrast, keyboard traps, heading order or meaningful image descriptions. It is aimed at site owners, agencies and developers maintaining several templates or legacy pages, especially where a first audit and repeatable HTML corrections are useful. A small site with carefully maintained content and an accessible template may have little reason to add it; it is not a substitute for a human accessibility review or certification. - It is listed as a paid download; the page does not state the price. - Infyways Solutions has 91 other directory extensions listed, while Easy WCAG has no reviews at the time shown. - Before installation, check the actual rule behaviour, false-positive handling, performance on cached pages, update and support terms, and whether custom rules can damage output. The listing does not provide independent test results or explain the payment details. Listed on the [Joomla Extensions Directory](https://extensions.joomla.org/extension/style-a-design/accessibility/easy-wcag/). --- # DevArt Documents builds a searchable file library for Joomla 6 Section: Extensions URL: https://joomclub.net/extensions/devart-documents-searchable-file-library-joomla-6 Published: 2026-08-12 DevArt Documents is a Joomla package for publishing, searching and delivering downloadable files through a managed document library. Joomla already provides the Media Manager for uploading and organising files, while articles, categories, tags, custom fields and access levels can supply a basic way to describe and restrict related content. A site can also link files from articles or build a presentation with a template override. Those tools do not, by themselves, create a document catalogue with individual records, download counters, protected storage, per-document open and download permissions, or a dedicated search index. That is the gap this extension claims to fill. It goes beyond a layout change by adding its own component, search handling, access rules, storage integration and scheduled tasks. It is aimed at sites that publish a substantial collection of manuals, policies, forms, technical files or other downloads, particularly where administrators need category-level permissions, local protected storage, Google Drive integration, batch imports or scheduled indexing. A small site with a few PDF links in articles has little reason to add this much infrastructure; Joomla core and a sensible article layout may be enough. The directory lists DevArt Documents as a free download from Kostas Stathopoulos, in the Downloads section, and shows 20 other extensions from the developer but no reviews. The listing specifies Joomla 6.0 or newer, PHP 8.3 or newer, and MySQL or MariaDB supported by Joomla 6. It says to install the full package rather than the standalone component. Before committing, check the Google API setup, migration and backup process, storage and indexing costs, support arrangements, and how the claimed ACL filtering behaves for your data. The listing also gives conflicting licence wording: its description says GPL version 3 or later, while the directory metadata says GPLv2 or later. Listed on the [Joomla Extensions Directory](https://extensions.joomla.org/extension/directory-a-documentation/downloads/devart-documents/). --- # Browser-based GDPR consent blocking for cached Joomla sites Section: Extensions URL: https://joomclub.net/extensions/browser-based-gdpr-consent-blocking-cached-joomla-sites Published: 2026-08-12 DevArt Consent adds a consent banner and blocks selected third-party scripts and embeds until visitors grant permission. This problem arises when a site embeds services such as Google Analytics, YouTube, Maps, advertising pixels or social widgets before it has consent. Joomla core provides privacy tools and consent handling for certain forms and user interactions, but it does not provide a complete, site-wide cookie banner that categorises and blocks arbitrary third-party resources. Site owners usually handle the gap with template or extension overrides, manual script changes, or a dedicated consent manager. According to the listing, DevArt Consent goes beyond a banner by applying consent in the browser while serving identical HTML to visitors. The developer also says it can remove protected scripts and embeds during PHP rendering, observe dynamically created nodes, support Google Consent Mode v2, and optionally record decisions. Those claims matter particularly on sites using Joomla page caching, reverse proxies, CDNs or Cloudflare, but the listing does not establish how every cache or third-party integration behaves. It is aimed at Joomla 6 websites with several analytics, advertising or embedded-content providers, especially where a team wants administrator-managed categories and blocking rules without adding per-visitor session state. A simple brochure site with no non-essential third-party scripts, or a site already handling consent through its hosting stack or another privacy platform, is unlikely to need it. - The listing describes it as a free download under GPLv2 or later, requiring Joomla 6.0 or newer and PHP 8.3 or newer. - The directory shows 20 other extensions from Kostas Stathopoulos, but this listing has no reviews. - Support is marked unavailable; documentation and updates are said to be in the project repository. Check accessibility, legal coverage, actual CDN purge behaviour, integration with your extensions, and whether the claimed blocking covers your own embeds before installing. Listed on the [Joomla Extensions Directory](https://extensions.joomla.org/extension/site-management/devart-consent/). --- # QC User Impersonation opens Joomla as another user Section: Extensions URL: https://joomclub.net/extensions/qc-user-impersonation-opens-joomla-as-another-user Published: 2026-08-12 QC User Impersonation is a free QuantaCade extension for checking a Joomla frontend from an eligible user's point of view. Its job is to let an authenticated Joomla Super User open the frontend as another eligible user without obtaining or changing that user's password. This need arises because Joomla's core user groups, access levels and permissions control what visitors see, but core Joomla does not provide a general “view this site as that user” workflow. A template override cannot create that missing login context. In practice, administrators use test accounts, ask customers for screenshots or temporary credentials, or reset passwords; some teams install a specialised extension instead. According to the listing, QC User Impersonation goes beyond core by starting the session from the administrator area, handing it to a separate frontend tab, keeping the administrator session open and providing a way to end the impersonation. The listing also says the extension excludes Super Users and blocked or otherwise ineligible accounts. This is aimed at support teams, developers and site administrators troubleshooting membership content, customer portals, account pages, menus, modules and permission-dependent layouts. A brochure site with one public audience, or a team already satisfied with test accounts and manual checks, has little reason to add it. Before installing, note that the listing calls it a free download under GPLv2 or later and states compatibility with Joomla 5 and 6. QuantaCade has seven other extensions shown in the directory, while this listing has no reviews. The listing does not explain how its audit records are viewed or retained, how it interacts with third-party authentication, caching or membership extensions, or what happens in more complex multi-site setups. Those points, plus the operational risk of granting Super Users this capability, warrant testing on a staging site. Listed on the [Joomla Extensions Directory](https://extensions.joomla.org/extension/access-a-security/qc-user-impersonation/). --- # Charging points for NorrCompetition contest actions Section: Extensions URL: https://joomclub.net/extensions/charging-points-for-norrcompetition-contest-actions Published: 2026-08-12 NorrCompetition User Points charges users points for actions in NorrCompetition contests, including submitting entries and voting. This job arises when a Joomla site runs a competition as more than a simple poll: the owner may want to control participation, reward contestants, or charge for entries and votes. Joomla core provides users, access levels, content permissions, and workflow features, but it does not provide a general-purpose points wallet or a contest-specific payment system. A template override can change how a contest or form looks, but it cannot by itself maintain balances or connect transactions to actions. That leaves an extension as the usual route. According to the listing, this integration adds point rules to `NorrCompetition` for creating, publishing, unpublishing, trashing, approving, and unapproving entries, as well as submitting and withdrawing votes. It also distinguishes points paid by voters from points received by contestants. The stated extension-level addition is therefore the points accounting and commerce connection; the underlying contest functionality belongs to NorrCompetition, not Joomla core. It is aimed at a site already using NorrCompetition that wants a paid-entry or paid-voting model, or a team building a participation-based revenue stream around contests. A normal Joomla site, a site with no contests, and a competition that only needs free voting have little reason to install it. A developer may also prefer a custom integration when the payment and scoring rules are unusual. The directory marks it as a paid download, but gives no price. The developer is NorrNext; the listing shows 22 other extensions from that developer and no reviews for this product. Before buying, check which Joomla e-commerce extensions are supported, how points are purchased, refunded, expired, or protected against abuse, and whether NorrCompetition is required at a particular version. The listing does not specify those details, nor does it explain licensing terms beyond GPLv2 or later. Listed on the [Joomla Extensions Directory](https://extensions.joomla.org/extension/e-commerce/e-commerce-integrations/norrcompetition-user-points/). --- # Hide admin markers from Joomla’s public titles Section: Extensions URL: https://joomclub.net/extensions/hide-admin-markers-from-joomlas-public-titles Published: 2026-08-11 Strip Comments lets Joomla administrators add private identifying notes to names without displaying those notes on the public site. The `Strip Comments` system plugin removes markers such as `{-- My City --}` from rendered front-end output, while leaving them in administrator-visible names. This problem arises when a site has several similarly named modules, articles or menu items and editors need a quick way to tell them apart. Joomla core provides fields and naming conventions for managing those records, but it does not provide a general, administrator-only annotation syntax that can be placed in titles and then removed across the front end. A template override could hide or alter output in particular layouts, but that means handling each relevant rendering path. A system plugin is the extension-based alternative: according to the listing, Strip Comments processes the rendered output across places including module titles, article titles and menu items. That is its specific step beyond core, not a new content-management feature. It is aimed at administrators and editorial teams managing complex sites with repeated labels or multiple localised, client-specific or otherwise similar records. A small site with distinctive titles, or a team that has no need for private naming notes, has little reason to install it. The listing marks it as a free download from ferino, in the “extensions specific non sorted” directory section, and says it supports Joomla 5 and 6. The directory shows one other extension from the developer, while the listing provides no broader track-record evidence; it also says support is not available and shows no reviews. Before installing, check how the marker syntax behaves with escaped text, caching, third-party extensions and titles produced outside the named examples. The listing does not explain configuration options, processing limits, performance implications, update policy or whether all front-end output contexts are covered. This note is based on the listing; we have not tested the plugin. Listed on the [Joomla Extensions Directory](https://extensions.joomla.org/extension/extension-specific/extensions-specific-non-sorted/strip-comments/). --- # JUX Portfolio Gallery builds filtered image and video grids Section: Extensions URL: https://joomclub.net/extensions/jux-portfolio-gallery-filtered-image-video-grids Published: 2026-08-11 JUX Portfolio Gallery is a paid Joomla module for displaying image and video portfolios in grid or masonry layouts. The job is to present a collection of projects or media as a browsable gallery, with categories, search, filtering, lightboxes and links to individual projects. This need arises because Joomla core can store and organise files in Media Manager, publish images through articles, and place content in menus and modules. It does not provide a general-purpose front-end portfolio gallery with masonry layouts, media lightboxes, category filtering, AJAX loading, or built-in YouTube, Vimeo and MP4 presentation. A developer can assemble some of this with articles, custom fields, a template override and JavaScript, but that involves designing the data structure and interface. A gallery extension is the shorter route when those features are part of the brief. According to the listing, JUX Portfolio Gallery goes beyond core by combining those presentation and filtering functions in one module, with folder-based image management and responsive column settings. It is aimed at photographers, agencies, designers, creative businesses and project-heavy sites that need a visual showcase rather than a standard article list. A site with a few static images, a conventional Joomla blog, or no portfolio content has little reason to install it. The directory lists it as a paid download from JoomlaUX, under the portfolio section, and shows 87 other extensions from that developer. That is directory activity, not a substitute for testing. The listing does not state the price, support terms, update duration, accessibility details, image-sizing or performance behaviour, import options, permissions model, or whether all listed video sources work without additional configuration. It does list Joomla 4, 5 and 6 compatibility, but prospective users should still check the demo, documentation and licensing details before paying. Listed on the [Joomla Extensions Directory](https://extensions.joomla.org/extension/directory-a-documentation/portfolio/jux-portfolio-gallery/). --- # PublikWALL turns article listings into a tiled homepage grid Section: Extensions URL: https://joomclub.net/extensions/publikwall-article-tile-grid Published: 2026-08-11 PublikWALL is a Joomla module for presenting articles, and optionally JEvents events, as a configurable tile grid. This is a presentation job: it selects Joomla articles and lays them out as linked tiles with images, excerpts, and configurable ordering. According to the listing, it can also insert upcoming JEvents items into the same grid. Joomla already covers the basic article-listing task through modules such as `mod_articles_category`, `mod_articles_latest`, and `mod_articles_popular`. Those modules can filter or order articles, while a template override can turn their output into a card or multi-column layout. A separate extension becomes relevant when the site needs the listing's particular combination of image extraction, tile pagination, display controls, or event integration. PublikWALL goes beyond core by mixing JEvents events with article tiles and by claiming to find a suitable image inside article text while skipping certain graphics. It is aimed at publishers, community sites, event organisations, and homepage layouts that need more visual editorial discovery than a conventional article list. A site with a small number of articles, a standard blog layout, or no JEvents installation has little reason to add it. It is also not useful simply to create a general-purpose events calendar. - The directory marks it as a free download under the AGPL license. It lists Michael Gaki as developer, with one other extension and no reviews, so the directory provides limited evidence of the developer's track record. - Check whether JEvents is required for any configured features, how the image detection behaves with your content, and whether the output meets your template's accessibility, performance, and responsive requirements. The listing shows Joomla 4, 5, and 6 compatibility, but leaves support policy, update history, dependency details, and pagination or override documentation unclear. Listed on the [Joomla Extensions Directory](https://extensions.joomla.org/extension/style-a-design/modules-styling/publikwall/). --- # File baselines and malware signatures for Joomla 5 and 6 Section: Extensions URL: https://joomclub.net/extensions/file-baselines-malware-signatures-joomla-5-6 Published: 2026-08-11 Integrity Checker compares Joomla site files with a trusted baseline and checks them for known malware patterns. Joomla core can update the CMS and installed extensions through its update system, but it does not provide a general file-integrity baseline or a malware-signature scanner for the whole site. A template override is not the usual answer either: overrides change presentation output, not the contents of every PHP and asset file. Site owners commonly rely on hosting-provider scanners, manual comparisons with clean packages and backups, external security services, or a dedicated extension. According to the listing, Integrity Checker goes beyond core by fingerprinting files, reporting additions, changes and deletions, and scanning content for signatures associated with webshells, backdoors, obfuscation and cryptocurrency miners. It also claims to offer quarantine, exclusions, reports and scan history. The listing says the free download provides manual scans and five recent history entries; scheduled scans, email alerts and other additions are part of Pro at €22 per site per year. This is aimed at administrators of Joomla sites where unauthorised file changes need investigation, particularly agencies or teams managing several sites. A small, rarely changed site with dependable hosting security, backups and manual checks may have little reason to add another security layer. Before installing, note that the directory lists GOUINEAU as the developer, places it in the integrity checker section, and shows no reviews. The listing says Joomla 5 and 6 are supported and PHP 8.1 or newer is required. It does not explain false-positive handling, signature-update arrangements, scan resource use, quarantine recovery, or how a trustworthy initial baseline is established. Listed on the [Joomla Extensions Directory](https://extensions.joomla.org/extension/access-a-security/integrity-checker/). --- # Easy Helpdesk adds ticket queues and agent tools to Joomla Section: Extensions URL: https://joomclub.net/extensions/easy-helpdesk-ticket-queues-agent-tools Published: 2026-08-11 Easy Helpdesk turns a Joomla site into a place where customers can submit support tickets and staff can manage the resulting conversations. The job is to provide a ticketing workflow: customers open and follow requests, while support staff assign, answer, prioritise and close them. This comes up when a contact form and an inbox stop being enough. Joomla core provides the Contacts component for contact forms, plus articles, categories, search, users and access control that can support a basic help area. A template override can change the presentation of those pieces, but it does not create a ticket queue or a shared conversation record. Some teams connect forms and email manually; others install a help-desk extension when they need assignments, private notes, statuses, attachments, canned replies, customer history, or `SLA` tracking. According to the listing, Easy Helpdesk goes beyond core by combining those support workflows with a knowledge base, two-way email, a frontend staff console and guest ticket access. It is aimed at extension vendors, agencies, membership organisations and other teams handling recurring customer or member requests. A site with a small volume of enquiries, a simple contact form, or support handled entirely through a shared mailbox has little reason to add it. It may also be unnecessary if an organisation already has an external service desk it must keep as the system of record. Before installing, check the commercial terms: the listing does not say whether Easy Helpdesk is free or paid, nor does it show a price. The directory lists Infyways Solutions with 89 other extensions, while Easy Helpdesk has no reviews shown. The page also leaves Joomla version compatibility, update policy, support terms, hosting requirements for mailbox polling, and attachment and security limits unanswered. Those details matter for a production support desk. Listed on the [Joomla Extensions Directory](https://extensions.joomla.org/extension/clients-a-communities/help-desk/easy-helpdesk/). --- # Live JomSocial totals in a publishable Joomla module Section: Extensions URL: https://joomclub.net/extensions/live-jomsocial-totals-publishable-joomla-module Published: 2026-08-11 PluggerBox Community Stats For JomSocial displays selected live counts from JomSocial in a Joomla module position. This job arises when a community site wants visitors to see activity and scale without maintaining figures by hand. Joomla can place modules in template positions and assign them to menu items, while a Custom module can display text or manually entered numbers. Its core modules do not, however, provide a built-in view of JomSocial's member, group or photo totals. A template override is only useful when the required data and output already exist in a component or module. For live JomSocial figures, site owners generally need JomSocial-specific code or an extension. According to the listing, PluggerBox goes beyond Joomla core by reading those totals from JomSocial and letting administrators choose and relabel the figures displayed. It does not replace JomSocial; it presents data from it. This is aimed at JomSocial community sites that want a small statistics block in a sidebar, footer or landing page, especially where the site team does not want to build and maintain a custom module. A standard Joomla site without JomSocial, or a community that does not need public counts, has no apparent use for it. - The download is paid and licensed under GPLv2 or later. - The listing identifies PluggerBox as the developer, shows no reviews, and offers no documentation. - Check the price, support terms, the exact totals available, update policy and whether the module handles empty or private data as expected. The listing says it supports Joomla 4, 5 and 6 with PHP 8 or newer, but the software has not been tested here. Listed on the [Joomla Extensions Directory](https://extensions.joomla.org/extension/clients-a-communities/communities/pluggerbox-community-stats-for-jomsocial/). --- # Sixteen animated transitions for Joomla image slideshows Section: Extensions URL: https://joomclub.net/extensions/sixteen-animated-transitions-for-joomla-image-slideshows Published: 2026-08-10 DC GSAP Slider is a Joomla site module for image slideshows with configurable animated transitions, slide text and calls to action. This is for presenting a sequence of images as a more heavily animated slideshow, with optional headings, descriptions, buttons and links on each slide. The job arises when a Joomla site needs a visual hero or campaign panel rather than a static image. Joomla core provides the building blocks: the Media Manager stores images, Custom modules can place images and HTML in template positions, and menu assignments control where a module appears. Core does not provide a dedicated slideshow module with a set of transition modes, per-slide fields and touch, drag or wheel navigation. A template override can change the markup and presentation of existing output, but it does not by itself supply this editing interface or animation layer. Sites usually reach for an extension when they want those functions without building a custom module. According to the listing, the module adds sixteen GSAP-based transition styles, autoplay, responsive height settings and controls for overlays and transition colours. That makes it relevant to a marketing site, portfolio, agency homepage or campaign landing page with an editor-managed visual header. A site that only needs one image, a basic content block, or a conventional static carousel has little reason to add it. DC GSAP Slider is listed as a free download from Pawel Nosko. The directory shows 17 other extensions by the developer, while this listing has no reviews. The requirements say Joomla 6.x and PHP 8.3 or later, although the compatibility badges show both J5 and J6, so that discrepancy should be clarified before installation. The listing does not explain accessibility behaviour, performance on image-heavy pages, support terms, documentation depth, or how updates are maintained. Listed on the [Joomla Extensions Directory](https://extensions.joomla.org/extension/photos-a-images/slideshow/dc-gsap-slider/). --- # Scan Malware checks Joomla files for suspicious PHP code Section: Extensions URL: https://joomclub.net/extensions/scan-malware-checks-joomla-files Published: 2026-08-10 Scan Malware examines Joomla files for suspicious PHP code that could indicate malware, a web shell or a backdoor. This job arises because a Joomla site can be compromised through an extension, an outdated component, stolen credentials or a vulnerable server. Malicious code may be hidden inside otherwise ordinary PHP files, and Joomla’s normal administration screens do not provide a general malware scan. Core Joomla can update the CMS and extensions, manage installed packages and users, and provide some maintenance and security controls. It does not, however, inspect the site’s PHP files for signs of injected code. A template override is useful for changing output or behaviour without editing core files; it is not a malware-detection method. Site owners usually turn to a security extension, a hosting scanner or a manual comparison with known-good files. According to the listing, Scan Malware goes beyond Joomla core by analysing files for suspicious PHP patterns and Joomla-related threats. The listing says it can detect, analyse and handle such files, but does not explain the handling in enough detail to judge whether that means quarantine, deletion or reporting. It is aimed at administrators, agencies and hosting teams responsible for Joomla sites where file integrity needs a dedicated check, particularly after a suspected compromise. A small, low-risk site with a managed host’s existing malware monitoring, or a site that only needs routine Joomla updates, may have no reason to add it. - Scan Malware is a paid download, licensed under GPLv2 or later. - The directory lists compatibility with Joomla 4, 5 and 6. - The listing shows no reviews, so it provides little evidence of JoomSAFE’s track record there. - Before buying, check scan scope, false-positive handling, remediation and restore options, resource use, scheduled scans, reporting, support terms and pricing. The listing does not provide those details, nor does it state how detection is performed. Listed on the [Joomla Extensions Directory](https://extensions.joomla.org/extension/access-a-security/scan-malware/). --- # Ajax article grids and magazine layouts in Easy Articles Grid Section: Extensions URL: https://joomclub.net/extensions/ajax-article-grids-magazine-layouts-easy-articles-grid Published: 2026-08-10 Easy Articles Grid is a Joomla site module for presenting articles in configurable grids, lists, magazine layouts and other visual formats. This is a presentation problem rather than a content-management one: a site may have plenty of `com_content` articles but need a more deliberate front-page section, archive, newsroom or portfolio view. Joomla core already provides article modules such as Latest Articles, Most Read, Featured Articles and Articles Category, along with category blog and list menu layouts. Those cover standard article output, while a template override can reshape the markup and styling. An extension becomes relevant when editors want to change several presentation patterns from module settings instead of maintaining override code. According to the listing, Easy Articles Grid goes beyond those core displays with twelve layouts, ten themes, image controls, category pills, live title and intro search, and Ajax options for load-more, infinite-scroll or numbered pagination. It also claims support for tags, featured state, language and access levels, plus URL state and custom-field image sources. We have not tested these features. It is aimed at magazine, blog, news, portfolio and content-hub sites where editors need repeated article blocks with different visual treatments, or agencies supporting several Joomla installations. A small brochure site with a handful of pages, or a site already satisfied with core modules and its template styling, has little reason to add it. The listing marks it as a paid download but gives no price. It states Joomla 4, 5 and 6 compatibility and PHP 8.1+, and identifies Infyways Solutions as having 89 other directory extensions; this listing has no reviews. Before buying, check the actual licence and support terms, documentation, accessibility and performance of the Ajax views, upgrade policy, and how custom fields, multilingual content and URL state behave in the target template. Listed on the [Joomla Extensions Directory](https://extensions.joomla.org/extension/news-display/articles-display/easy-articles-grid/). --- # A swipeable HTML5 game feed for Joomla sites Section: Extensions URL: https://joomclub.net/extensions/swipeable-html5-game-feed-for-joomla-sites Published: 2026-08-10 Plays Games Widget adds an embedded, browsable HTML5 game feed to a Joomla site. This job arises when a site wants visitors to play browser games within its own pages rather than sending them to a separate games portal. Joomla core can display an external game with an article or Custom HTML module containing an `iframe`, subject to editor and content-filter settings. A template override could alter the surrounding presentation, but it would not provide a catalogue of games. The extension goes beyond those options, according to its listing, by supplying a feed with category filtering, adjustable display dimensions, likes and other user interactions, and automatic game updates. That makes it relevant to a games site, entertainment portal, magazine, blog or community that wants a ready-made stream of third-party HTML5 games without building its own catalogue and integration. A conventional company site, documentation site, portfolio or publication with no gaming content has little reason to install it. Teams wanting complete control over game selection, branding, player data or hosting may also prefer a manually managed solution. The listing marks it as a free download under GPLv2 or later and says it supports Joomla 5 and 6. It identifies Rabarijaona as the developer, but provides no wider directory track record; the listing currently shows zero reviews. Before installation, check where the games and interaction data come from, the licensing and privacy terms for those services, whether the feed can be moderated, and how third-party iframes affect performance, accessibility and security. The listing also leaves support arrangements, update policy and migration or removal behaviour unclear. Listed on the [Joomla Extensions Directory](https://extensions.joomla.org/extension/sports-a-games/games/plays-games-widget/). --- # Easy PDF adds gated PDF viewing to Joomla articles Section: Extensions URL: https://joomclub.net/extensions/easy-pdf-gated-viewing-joomla-articles Published: 2026-08-10 PDF handling is a small publishing problem that becomes more complicated when access and presentation matter. Easy PDF lets editors place a PDF viewer, opener or download link inside a Joomla article and set viewing or saving rules for that file. Joomla core already covers the basic case: upload a PDF through Media, link to it from an article, or add an HTML `iframe` or download link. Article and menu access levels can restrict the page containing the link. A template override or custom markup can alter the surrounding presentation, but core does not provide this package's claimed modal viewer, thumbnail openers, per-file print and download switches, login or registration prompts, or signed streaming of protected files. Those requirements are why sites commonly turn to an extension rather than assembling the behaviour themselves. This is aimed at publishers of manuals, forms, brochures and member documents, especially teams that want reusable shortcode insertion and different rules for public and logged-in readers. A site that only links to occasional public PDFs has little reason to install it. Before installing, note that the listing marks Easy PDF as a paid download from Infyways Solutions, under the Directory's *Print a PDF* section. It states support for Joomla 4, 5 and 6 and PHP 8.1+, but gives no price in the supplied listing. The page shows 89 other extensions from the developer, while this listing has no reviews. Check the licence and support terms, accessibility and mobile behaviour, large-file limits, how the signed URLs expire, and what “soft” download and print blocking can actually prevent. The listing also does not provide independent test results. Listed on the [Joomla Extensions Directory](https://extensions.joomla.org/extension/style-a-design/print-a-pdf/easy-pdf/). --- # A backend order trail for HikaShop products Section: Extensions URL: https://joomclub.net/extensions/backend-order-trail-for-hikashop-products Published: 2026-08-10 Product Order history for HikaShop adds a paginated list of orders containing a product to that product's administrator page. This need exists because Joomla core is a content management system, not an ecommerce system, so it has no native product catalogue or order history to display. HikaShop supplies those product and order records, but a store manager may still need to move between a product and its orders when checking sales, quantities, customers or order status. HikaShop's own administrator screens cover product and order management, while a custom administrator view or database report could connect the two. A template override is generally not the right tool: this is backend data, not a front-end layout problem. According to the listing, this extension goes beyond Joomla core and adds the connection directly to the HikaShop product page, showing ten orders at a time with pagination and a link to each order. It is aimed at HikaShop stores whose staff regularly investigate the sales history of individual products. A small site with few orders, or a Joomla installation without HikaShop, has no obvious use for it. Teams already maintaining bespoke reporting may also have little reason to add another administrator view. The listing describes it as a free download and shows GPLv2 or later in the licence field, although another part of the page says GPL v3. It requires HikaShop 3.3 or newer, lists Joomla 3 through 6 and PHP 5 minimum, and identifies Hikari Software Team as the developer. The directory shows 71 other extensions from that developer but no reviews for this listing. Documentation is marked unavailable, so check current installation and support arrangements, the licence discrepancy, and whether the stated compatibility matches the versions in use. Listed on the [Joomla Extensions Directory](https://extensions.joomla.org/extension/extension-specific/hikashop-extensions/product-order-history-for-hikashop/). --- # What Site-Check Accessibility adds to Joomla Section: Extensions URL: https://joomclub.net/extensions/what-site-check-accessibility-adds-to-joomla Published: 2026-08-10 Site-Check Accessibility is a free Joomla connector for applying accessibility changes supplied by the external Site-Check service. Its job is to retrieve approved accessibility fixes from a Site-Check account and apply them to the HTML Joomla sends to visitors. Accessibility work arises because Joomla does not automatically audit and remediate every template, article, form, image, or third-party component used on a site. Core Joomla provides the content and page-rendering framework, and developers can adjust output with template overrides, but it does not include a general external accessibility testing and fix-delivery service. Teams commonly handle the work manually through content and template changes, or use an extension or separate auditing service. According to the listing, this connector goes beyond those core mechanisms by inserting fixes server-side and by optionally adding a visitor assistance overlay; the analysis, approval, and configuration happen at `site-check.de`. This is aimed at organisations with an active Site-Check workflow, particularly teams that want approved changes delivered across a Joomla site without editing each template. A small site with few accessibility issues, a developer already maintaining its markup, or a site that does not use Site-Check has no obvious reason to install it. The directory calls the download free, but an active Site-Check account or subscription is required. The developer is shown as “---”; although the page lists 10 other extensions, it provides no identifiable track record. The listing says Joomla 4, 5, and 6 with PHP 8.1 or newer, but leaves the exact fixes, data handling, performance impact, service pricing, and rollback behaviour unanswered. It also shows no documentation, support, or reviews. Listed on the [Joomla Extensions Directory](https://extensions.joomla.org/extension/style-a-design/accessibility/site-check-accessibility/). --- # Email Remover takes a different approach to Joomla email protection Section: Extensions URL: https://joomclub.net/extensions/email-remover-joomla-email-protection Published: 2026-08-10 Email Remover is a free Joomla system plugin that removes email addresses from front-end page output or replaces them with text, HTML, or images. Email addresses appear on Joomla sites because organisations still publish contact details, support addresses and required legal contacts. Joomla core already provides the `Email Cloaking` content plugin, which obfuscates addresses in rendered content so they are less immediately readable to automated harvesters. Site owners can also avoid exposing an address by using a contact form, or control a particular display through a template override. Those approaches do not amount to removing every matching address from the final HTML, however. According to the listing, Email Remover works at the system-plugin level across public front-end output, and can delete addresses, substitute custom text or markup, or turn them into PNG images. It also claims to cover both `mailto:` links and plain text, with exceptions for specified addresses or domains. That makes this relevant to sites publishing several addresses across articles, modules or template output, especially where a form or ordinary cloaking is not sufficient. A small site with one deliberately public contact address, or one already using a contact form, may have little reason to add it. The listing says it is free, GPLv2 or later, and supports Joomla 3 through 6. It shows ferino as having one other directory extension, but there are no reviews. Documentation is marked unavailable, and the listing does not explain hosting requirements for PNG generation, support arrangements, or how the plugin behaves with every kind of generated or cached output. Those points are worth checking before installation. Listed on the [Joomla Extensions Directory](https://extensions.joomla.org/extension/access-a-security/site-security/email-remover/). --- # A gateway layer for Joomla’s protected pages Section: Extensions URL: https://joomclub.net/extensions/quick-account-gateway-context Published: 2026-08-10 Quick Account Gateway is aimed at sites that want a short, shareable URL to lead visitors through authentication and on to a restricted Joomla page. Its job is to map a public gateway URL to a protected Joomla destination, sending guests to log in and then back to that destination. Joomla already handles the underlying access control: administrators can restrict menu items and content with ACL access levels, while the core login component and login menu items or modules provide authentication and configurable redirects. A direct link to restricted content can therefore be protected without an extra extension. What core does not generally provide as a ready-made site feature is a set of friendly public aliases that remember the requested page through login and then forward an authenticated visitor to it. A template override can change the presentation of a login page, but it is not normally the right tool for adding this routing logic; teams wanting that workflow usually add custom code or an extension. This is relevant to membership sites, customer download areas, support portals and other sites where links such as `/download` are easier to publish than a deeply nested protected URL. A brochure site with only public content, or a site whose restricted pages are reached through ordinary logged-in navigation, has little reason to install it. According to the listing, Quick Account Gateway is a free download from Stephan Römer in the `site access` section. The directory shows 20 other extensions from the developer and no reviews. Before installing, check how gateway-to-destination mappings are configured, whether return URLs are validated against open redirects, and how multilingual routes and failed logins are handled. The listing claims Joomla 4.4, 5 and 6 compatibility, but provides no documentation or support contact, and does not explain update policy, configuration limits or security testing. Listed on the [Joomla Extensions Directory](https://extensions.joomla.org/extension/access-a-security/site-access/quick-account-gateway/). --- # A Joomla schedule manager for parish websites Section: Extensions URL: https://joomclub.net/extensions/joomla-mass-schedule-manager-parish-websites Published: 2026-08-10 Mass Schedule Manager stores Mass times for one or more churches and publishes the relevant schedule on a Joomla site. This is a job that arises when a parish website must publish recurring times that change for Sundays, Saturday vigils, feast days and seasonal periods. Joomla core can display a timetable as an article, custom HTML module or menu-linked content, but it does not provide a dedicated schedule model that calculates the next event or applies date-specific replacements. A template override can change the presentation of existing content; it does not remove the need to maintain those rules. Administrators can therefore manage simple schedules manually in core, use an override for a custom presentation, or install an extension when exceptions and multiple locations make manual editing cumbersome. According to the listing, Mass Schedule Manager goes beyond that core approach with: - separate records for multiple churches, including Roman or Ambrosian rite; - weekday, vigil and holiday slots, plus seasonal periods and date-specific exceptions; - four choices for handling anticipated weekday feast Masses; - a frontend component and `mod_messe` module for the next Mass or full schedule. It is aimed at parish, diocesan and religious-community teams responsible for several churches or frequently changing calendars. A small site with one church and a stable timetable may have no reason to add a component instead of maintaining an article or module. The listing identifies Gioacchino Cipriano as the developer and shows no reviews, but gives no wider directory track record. It does not state whether the package is paid or free, nor does it describe support or update arrangements. It does specify Joomla 5.x or 6.x, PHP 8.1+, and InnoDB/utf8mb4 requirements; those should be checked against the hosting environment before installation. Listed on the [Joomla Extensions Directory](https://extensions.joomla.org/extension/living/religious-events/mass-schedule-manager/). --- # Joomla extension manager highlights third-party entries Section: Extensions URL: https://joomclub.net/extensions/joomla-extension-manager-highlights-third-party-entries Published: 2026-07-24 Joomla’s full extension list includes a “Core - Third Party” filter that lets site administrators quickly identify third-party extensions recorded by the CMS, a useful review aid as Joomla sites face more frequent security checks. The filter is available in Joomla’s `System > Extensions > Manage` area, which contains the complete list of extensions known to the installation. Selecting the third-party option narrows that list to extensions that are not part of Joomla’s core. Separating core and third-party entries can make an extension inventory easier to review. It provides a direct way to see which additional components, plugins or other extensions are registered on a site without having to assess the complete list manually. This distinction is particularly relevant when checking a Joomla installation for potential weak points. Third-party extensions form a separate part of the site’s extension footprint, so identifying them is a practical step when reviewing what is installed and determining which entries require closer attention. The filter does not replace a broader site review, but it offers a focused view inside Joomla’s extension management interface. Administrators carrying out routine checks can use it to isolate the non-core portion of an installation before examining individual extensions. --- # joomLab Article Slider 1.1.0 adds AJAX content filtering Section: Extensions URL: https://joomclub.net/extensions/joomlab-article-slider-1-1-0-ajax-filtering Published: 2026-07-18 joomLab has released Article Slider 1.1.0, adding AJAX filtering by categories and tags to a Joomla module that displays articles in a responsive slideshow. The update allows filtering to take place within any module instance on a page after the module has loaded. Article Slider loads its content dynamically through AJAX. This approach is intended for pages that contain many content modules, particularly when each module displays a large number of articles. By loading article data dynamically, the module can help limit the amount of content loaded with the initial page. In version 1.1.0, site visitors can filter the articles shown in a module by one or more Joomla categories and/or tags. The filtering is also handled through AJAX, so the displayed content can be updated without a full page reload. The results are presented as a responsive slideshow using `swiper.js`. The new filtering capability applies to any Article Slider module on the page, according to the release announcement. ## Availability joomLab provides the extension page at [joomlab.ru/extentions/modules/joomlab-article-slider](https://joomlab.ru/extentions/modules/joomlab-article-slider). A demonstration of the AJAX article view is available at [demo.joomlab.ru/ajax-article](https://demo.joomlab.ru/ajax-article). --- # Joomla 6 component generates llms.txt files Section: Extensions URL: https://joomclub.net/extensions/joomla-6-component-generates-llms-txt-files Published: 2026-07-16 A new Joomla 6 component generates `llms.txt` and `llms-full.txt` files, using a site's sitemap, article metadata and selected menu items to create structured context for large language models. The component produces a basic `llms.txt` file and an expanded `llms-full.txt` version containing an annotated list of site content. Generated files can be viewed in the component's workspace before being regenerated after configuration changes. ## Content and URL selection Initial URL collection is based on `sitemap.xml`. The component also checks the sitemap against `robots.txt` restrictions and `noindex` and `nofollow` tags. This means the quality and completeness of the site's sitemap remains important to the resulting AI-oriented files. Link descriptions are built from `Meta Description` values in `com_content` articles and from selected site menu items. The extension's documentation therefore advises using unique, relevant descriptions that meet basic SEO requirements. Content can be grouped by category, while administrators can exclude specific categories, articles and menu items. The component also supports synchronization with `sitemap.xml` and creates a `.bak` backup on each generation. Configuration is available through Joomla's standard administrator interface. A step-by-step guide is included in the component settings for editors with basic Joomla administration knowledge. The extension was developed by community member Alexander Kuznetsov, known as `@newvksan`. --- # WT LLMs brings AI-readable site files to Joomla Section: Extensions URL: https://joomclub.net/extensions/wt-llms-brings-ai-readable-site-files-to-joomla Published: 2026-07-15 WT LLMs is a new Joomla component for sites that need to expose structured, machine-readable information to large language models, AI agents and AI-focused search workflows. It generates `llms.txt`, `llms-full.txt` and `llms.json`, and is designed for Joomla 5 and later. The extension follows the approach described by [llmstxt.org](https://llmstxt.org/). Its administration interface can be used to maintain a site profile, an intent map and canonical pages associated with those intents. The resulting files are intended to provide an AI-readable overview of a Joomla site without requiring manual assembly of Markdown or JSON. ## Component and Markdown plugin WT LLMs includes a Joomla system plugin that adds an alternative Markdown representation of site pages. This version presents page content in a cleaner text format for AI agents, LLMs, search systems and technical integrations. The plugin also adds links to the AI-related files in the page ``. A REST API is available for automatically populating the extension's data, while a public schema instruction can be exposed for AI agents. The concept is also referenced in Google's Lighthouse documentation for agentic browsing. The project's published materials include an [extension page](https://web-tolk.ru/dev/components/wt-llms?utm_source=telegram-joomlafeed) and a [GitHub repository](https://github.com/WebTolk/WT-LLMs). --- # WT LLMs adds llms.txt and llms.json support to Joomla Section: Extensions URL: https://joomclub.net/extensions/wt-llms-adds-llms-txt-and-llms-json-support-to-joomla Published: 2026-07-15 WT LLMs is a Joomla component for sites running Joomla 5+ that generates `llms.txt`, `llms-full.txt` and `llms.json` files, giving AI agents and other machine-reading systems structured access to site information. The extension is built around the [llms.txt](https://llmstxt.org/) concept and provides an administration interface for defining a site's profile, mapping user intents and selecting canonical pages for those intents. Its stated goal is to make this information available without manually assembling Markdown or JSON files. WT LLMs can publish an AI-oriented site map and generate the three files automatically. It also includes a REST API intended for automated data population, along with a public schema instruction that AI agents can use when processing the site's information. ## Markdown page output The package includes a Joomla system plugin that adds an alternative Markdown representation of site pages. This version presents page content in a cleaner text format for LLMs, AI agents, search systems and technical integrations. The plugin also adds links to the AI-related files in the site's `` section. The extension documentation references the [Google Lighthouse documentation](https://developer.chrome.com/docs/lighthouse/agentic-browsing/llms-txt?hl=ru) in connection with `llms.txt`. Project resources are available through the [extension page](https://web-tolk.ru/dev/components/wt-llms) and the [GitHub repository](https://github.com/WebTolk/WT-LLMs). --- # NorrCompetition 3.0 adds native Joomla 6 support Section: Extensions URL: https://joomclub.net/extensions/norrcompetition-3-0-native-joomla-6-support Published: 2026-06-18 NorrNext has released NorrCompetition 3.0, moving the contests and voting component to native Joomla 6 code. The update removes the need for a backward-compatibility plugin and adds email-based vote confirmation, new rating scales and several tools for managing user submissions. NorrCompetition is designed for contests, voting, ratings and user competitions on Joomla websites. Its use cases include photo contests, project voting and other interactive mechanics built around user entries and ratings. ## Changes in version 3.0 - Votes can be confirmed by email using one-time password (OTP) codes. - Rating options now include five-star and 10-star systems. - The extension integrates with the Joomla Template System. - A new custom field type, “Editor”, is available for submissions. - Administrators can configure the recipients of notifications about new submissions. - The “My submissions” section has been updated. - Joomla 6 is fully supported. The Joomla 6 migration is the central technical change in the release. NorrNext says NorrCompetition now works without the backward-compatibility plugin, with code intended to be cleaner, faster and more closely integrated with the current Joomla platform. The new email verification option adds a confirmation step to voting, while the expanded rating systems provide alternatives to the component’s existing voting and rating workflows. The updated submission area and notification controls address the administration of entries after users submit them. --- # SP Page Builder 6.5.0 adds CAPTCHA and schema support Section: Extensions URL: https://joomclub.net/extensions/sp-page-builder-6-5-0-adds-captcha-and-schema-support Published: 2026-05-11 JoomShaper has released SP Page Builder 6.5.0 for Joomla, adding CAPTCHA support for forms in Joomla 6.1, Schema.org markup support and several dynamic-content improvements alongside a broad set of addon fixes. ## New and updated features The release adds CAPTCHA support to all SP Page Builder forms for confirming operation in Joomla 6.1. Pages can also use markup schemas through the Joomla System - Schema.org plugin. Dynamic Content and Dynamic Articles now support numbered pagination. Dynamic content date filtering has gained a date-offset option for filtering against the current date, while dynamic-content addons can now display source labels. All carousel addons have a pause-on-hover option. Accordion addon headings can display a background image, and the Div addon’s display settings now include a Grid element. The Social Share addon now refers to X instead of Twitter, and the Accordion addon receives accessibility improvements for users with visual impairments. ## Fixes in 6.5.0 - Fixed the status issue affecting the user profile image plugin. - Resolved a responsive display problem with code mirroring in the frontend editor. - Fixed custom background-image positioning. - Resolved an issue where inserting text inside the Collection addon could disable the addon. - Fixed the image carousel width issue that occurred when images were placed inside the Tabs addon. - Original descriptions and images now display correctly on single-view dynamic-content pages. - Fixed the redirect problem in the Subscription Form addon. - Resolved issues with Google Fonts URLs. --- # RadicalForm plugin brings article creation to Joomla 5 and 6 Section: Extensions URL: https://joomclub.net/extensions/radicalform-plugin-article-creation-joomla-5-6 Published: 2026-05-06 A free Joomla plugin can create articles when a Radical Form submission is received, extending the form workflow for user-submitted content and feedback mechanisms on Joomla 5 and Joomla 6 sites. The plugin, named **RadicalForm NewArticle**, is a new version of an earlier plugin for Joomla 3. It is intended for sites that use Radical Form and need submitted form data to result in a Joomla article rather than only being handled as a contact request. One of the changes in this version is support for matching Radical Form fields with Joomla article custom fields. This allows the form structure to be connected to the custom-field structure used by the resulting article. ## Background and availability The Joomla 3 version of the plugin is available on GitHub as `plg-radicalform-newarticle`. The new release is described as a reimplementation for Joomla 5 and Joomla 6, using the newer approaches for programmatically creating articles with custom fields. Possible uses mentioned for the extension include simplifying article publication by site users and building a review system. The plugin is free. It was developed by community member Dmitry Denisov. Additional background on the underlying article-creation process is available in Dmitry Rekun’s guide on programmatically creating Joomla articles with configurable fields, and in Sergey Tolkachev’s article covering custom fields in Joomla 5 and later. The extension page and download are published by Codersite. - [RadicalForm NewArticle for Joomla 3 on GitHub](https://github.com/JPathRu/plg-radicalform-newarticle) - [Extension page and download](https://www.codersite.ru/dev/joomla/sozdanie-materiala-pri-otpravke-formy-radicalform) --- # RadicalForm 4.0.0 adds Joomla 6 support Section: Extensions URL: https://joomclub.net/extensions/radicalform-4-0-0-adds-joomla-6-support Published: 2026-04-25 RadicalMart has released RadicalForm 4.0.0, a new version of its Joomla contact-form plugin that supports Joomla 5 and Joomla 6, including Joomla 6 installations without the backward-compatibility plugin. The release includes a new plugin architecture and adds a dedicated “Anti-Spam” section for configuring form submission controls. The available blocking criteria include submission timing, IP address, User-Agent, and the contents of submitted fields. RadicalForm 4.0.0 also checks the CSRF token when a file upload is loaded. This adds a request-validation step to forms that accept uploaded files. ## Compatibility and project changes The release is not compatible with Joomla 3 or Joomla 4. Installing this version on either of those Joomla versions is not supported and it will not work there. The project repository has moved to the RadicalMart organization. The release announcement also credits Dmitry Vasyukov, known as `@fictionlabs`, for a pull request that significantly accelerated the code migration. --- # RadicalForm 3.1.6 adds anti-spam tools for Joomla 3 and 4 Section: Extensions URL: https://joomclub.net/extensions/radicalform-3-1-6-adds-anti-spam-tools Published: 2026-04-18 RadicalMart has released RadicalForm 3.1.6, described as the final version of the extension for the Joomla 3 and 4 architecture. The update adds an Anti-Spam section that evaluates form content and submission timing to help address attacks by more advanced bots. The release targets existing websites that still run Joomla 3 or Joomla 4. The source announcement notes that both Joomla versions are no longer supported and cannot be used for new websites, while many previously built sites remain exposed to automated attacks. RadicalForm 3.1.6 introduces the new Anti-Spam section as the main change in this release. Its controls are intended to distinguish suspicious form activity by examining two factors: - the content submitted through a form; - the time at which the form is submitted. This approach is aimed at bots that can produce more realistic requests than basic automated spam tools. The announcement does not provide additional technical details about the available settings or the detection rules in the new section. As the last release for the Joomla 3 and 4 architecture, version 3.1.6 also marks the end of the extension’s development line for those platform versions. Sites that continue using them will therefore need to account for both the unsupported CMS environment and the future limits of the RadicalForm branch available for it. RadicalForm has also moved to the [radicalmart.ru](https://radicalmart.ru/) website. The release announcement is available from RadicalMart at [radicalmart.ru/novosti/vyshla-versiya-radicalform-3-1-6](https://radicalmart.ru/novosti/vyshla-versiya-radicalform-3-1-6). --- # JoomShopping adds an alpha REST API extension for Joomla Section: Extensions URL: https://joomclub.net/extensions/joomshopping-alpha-rest-api-extension-joomla Published: 2026-04-15 JoomShopping developers have introduced a REST API add-on for Joomla that exposes more than 40 online-store resources, enabling integrations with mobile applications, external services and AI agents. The extension is an alpha release and is not recommended for production sites. The add-on provides an API layer for JoomShopping functionality normally managed through the Joomla administrator interface. Its base URL is `/api/index.php/v1/shop/{resource}`. ## Available resources The endpoints cover the main areas of a JoomShopping installation, including: - **Catalog:** products, categories, manufacturers, productlabels, productimages, productsvideos and productsfiles - **Attributes and product data:** attributes, attributesgroups, attributesvalues, freeattributes, productsattrs, productsattr2s, productfields, productfieldvalues, productsoptions, productsprices and productsrelations - **Orders and transactions:** orders, orderitems, orderhistorys, orderstatus, payments, paymenttrxs and paymenttrxdatas - **Shipping and store settings:** shippings, shippingsprices, shippingmethodpricecountries, shippingmethodpriceweights, deliverytimes, currencies, countries, taxs, exttaxes, units, coupons, languages and addons - **Configuration and users:** configs, configseos, configstatictexts, importexports, users, usergroups, vendors and reviews ## Authentication and status Authentication uses Joomla’s built-in mechanisms. Joomla’s user-token authentication plugin is enabled by default, but token access is limited to the Super Users group unless additional groups are added in the `api-authentication` plugin settings. Alternatively, the “API Authentication - Basic Authentication” plugin can be enabled to allow REST API authentication with a user’s login and password. The developers warn that the add-on is currently an alpha release and should not be used on live production projects. A YouTube demonstration also shows the extension being used with the Claude AI agent. A separate page is available for the JoomShopping MCP Server add-on. --- # Joomill adds checklist management to Joomla’s administrator Section: Extensions URL: https://joomclub.net/extensions/joomill-admin-checklist-for-joomla Published: 2026-04-13 Joomill’s Admin Checklist extension brings task and checklist management into Joomla’s administrator area, helping administrators, developers and support teams track routine work and connect tasks with specific backend pages. The extension is built around lists of tasks that can be grouped into categories and assigned a completion status. Tasks can also be linked to particular pages in the Joomla administrator, keeping operational instructions close to the part of the CMS where the work is carried out. ## What the package includes - A component for managing tasks and categories - An administrator module for displaying checklists in the control panel - Plugins that integrate the extension with system events, including action logging Import and export functions are included for moving task data. The user-action logging plugin records who completed a task and tracks changes to task statuses, providing an activity record for administrative work. The feature set is split between the standard extension and a paid PRO version. PRO adds the ability to assign tasks to individual performers and create recurring tasks. The available information does not specify a Joomla version or PHP requirement. Admin Checklist is listed by Joomill on its extension site at [joomill-extensions.com](https://www.joomill-extensions.com/extensions/admin-checklist?utm_source=telegram-joomla-feed). --- # JoomShopping 5.9.1 fixes order and product issues Section: Extensions URL: https://joomclub.net/extensions/joomshopping-5-9-1-fixes-order-and-product-issues Published: 2026-04-11 JoomShopping 5.9.1 is now available for Joomla sites, bringing fixes for duplicate order numbers during manual administrator-side order creation and for image uploads in product attributes, along with new configuration options and payment-code logging. The release focuses on administration and product-management issues in the Joomla shopping component. The duplicate-number fix applies when an order is created manually in the administrator panel, while the image-upload correction affects product attributes. ## Changes in 5.9.1 - A new parameter has been added to the `onAfterRemoveProductField` trigger. - Three new parameters are available in `config.php`: `product_img_show_all_if_no_attr`, `prod_attr_load_data_by_partial_selection`, and `user_password_gen_in_shop`. - The component now displays a message when a discount code has been applied successfully. - The payment code is now saved in the component logs. The configuration additions affect product-image display when no attribute is selected, loading data based on partial attribute selection, and password generation in the shop. The trigger change may also require attention from developers whose integrations respond to product-field removal events. JoomShopping users can review the new settings and the updated trigger behavior when planning an upgrade. The release announcement also references the component’s version history and download pages. --- # WT Article Select adds article data to Joomla custom fields Section: Extensions URL: https://joomclub.net/extensions/wt-article-select-adds-article-data-to-joomla-custom-fields Published: 2026-04-06 WT Article Select is a free Joomla custom-field plugin that lets an administrator choose an article through Joomla’s standard article-selection modal and optionally makes the selected article’s data available during field rendering. The plugin is designed for custom-field contexts. Alongside storing the selected article, it can load the complete article object and the article’s custom fields, allowing those values to be used in custom field output layouts. ## Available options - **Load article data:** loads the complete selected article object and makes it available as `$field->article`. - **Load article fields:** loads the selected article’s custom fields into `$field->jcfields`. - **Show create article button:** adds access to Joomla’s standard new-article window from the administrative form. - **Show edit article button:** adds access to Joomla’s standard editing window for the selected article. ## Values available during rendering Field layouts can access the selected article through several properties: - `$field->value` contains a link to the selected article. - `$field->rawvalue` contains the field’s original saved value. - `$field->article_id` contains the selected article ID. - `$field->article_title` contains the article title used to display the link. - `$field->article` contains the complete article object when article-data loading is enabled. - `$field->jcfields` contains the article’s custom fields when field loading is enabled. This makes the plugin useful for layouts that need more than the selected article’s identifier or link, while keeping article selection within the standard Joomla administrative interface. --- # Phoca demonstrates an AI workflow for Joomla websites Section: Extensions URL: https://joomclub.net/extensions/phoca-demonstrates-ai-workflow-for-joomla-websites Published: 2026-03-17 Phoca has demonstrated a Joomla-based workflow for creating and maintaining websites with artificial intelligence, combining the Phoca AI component, Phoca AI Template, and Phoca Particles. The experiment, presented by Czech Joomla developer Jan Pavelka, shows how the three extensions work together to generate content, layouts, and individual Joomla modules. The demonstration is centred on Phoca AI, a Joomla component that connects the CMS with artificial intelligence models. Its role in the workflow extends beyond text generation: the component is also used to help create design elements for a site. ## Three-part Joomla workflow Phoca AI Template provides the base for the layouts produced through the process. Rather than treating each generated design as an isolated output, the workflow uses the Joomla template as the foundation for the resulting pages. The third element is Phoca Particles, a module for creating individual Joomla modules. This separates smaller page components from the broader site layout and gives the workflow a way to produce standalone modules within Joomla. Together, the extensions illustrate an approach in which AI-assisted generation remains connected to Joomla's existing content and layout structure. The focus is not only on producing a site, but also on supporting it inside the CMS after the initial creation process. The project is presented as an experiment by Jan Pavelka rather than as a general Joomla release announcement. Further details are available in the Phoca blog article, while a video demonstrates how the component, template, and module extension are used together. --- # joomLab Gallery 1.1.0 adds Joomla 6 support Section: Extensions URL: https://joomclub.net/extensions/joomlab-gallery-1-1-0-adds-joomla-6-support Published: 2026-03-14 joomLab Gallery 1.1.0 is now available for Joomla, adding Joomla 6 support and a new way to place image galleries in standard HTML modules as well as content. The update expands where the plugin can be used on a Joomla site. Galleries can now be inserted into the platform's standard HTML modules, making it possible to position them in module-defined areas rather than limiting them to articles or other content items. joomLab Gallery is designed to support an unlimited number of galleries within an article or HTML module. Each gallery can have its files and visual effects managed separately, according to the extension's description. ## JavaScript components The plugin uses `Swiper.js` for gallery organisation and effects. It also uses `FancyBox` to display the original images in an enlarged view. Version 1.1.0 includes two listed changes: - Support for Joomla 6 - Gallery insertion in standard HTML modules joomLab Gallery is developed by Alexander Novikov, identified in the announcement as a member of the Joomla community. --- # JoomShopping extension links products by shared characteristics Section: Extensions URL: https://joomclub.net/extensions/joomshopping-extension-links-products-by-shared-characteristics Published: 2026-03-13 A new extension for JoomShopping 5+ provides a semi-automated way to link products through shared characteristics, helping administrators create logical product groups while retaining manual control over the final relationships. The extension is designed for catalogs that need more flexible product relationships than those provided by a standard Related Products workflow. Administrators can use an existing characteristic—such as model, series, volume, or type—to find products that share the same value. The linking process is semi-automatic: - An administrator selects the characteristic used to form a product group. - The system filters the catalog and displays products with the same characteristic value. - The administrator selects the products that should be linked. This approach reduces the effort needed to locate matching products without making the relationships fully automatic. The administrator remains responsible for deciding which products are included in each group. The product flow assigned to an individual item is continuous. This provides an automatic connection between related products and allows the flow to be adjusted from each product to which it applies. The extension is intended for JoomShopping 5+ installations. Further details are available on the [extension page](https://nevigen.com/ru/addons/products-flow-joomshopping-5). --- # Quantum Manager 3.3.0 adds Joomla 6 compatibility Section: Extensions URL: https://joomclub.net/extensions/quantum-manager-3-3-0-adds-joomla-6-compatibility Published: 2026-03-04 Quantum Manager 3.3.0 has been released for Joomla sites, adding full compatibility with Joomla 6 without requiring the backward compatibility plugin. The media manager also removes legacy Joomla 3 code, adds SVG filtering controls and restores safe SVG image previews. The release is a substantial codebase update as well as a compatibility release. Code inherited from versions designed for Joomla 3 has been completely removed, leaving the extension aligned with the newer Joomla platform. ## SVG and metadata changes Quantum Manager 3.3.0 introduces new settings for filtering SVG files. Its safe SVG preview function has also been improved: updated filtering mechanisms restore the ability to preview SVG images while applying the extension’s safety controls. The update additionally fixes issues involving EXIF data and updates the EXIF library used by the media manager. ## Related extension update The `Radicalmultifield` user-field plugin has also been updated for compatibility with the new Quantum Manager release. The corresponding GitHub release is numbered `3.3.1`. Site administrators planning a Joomla 6 migration can therefore check both Quantum Manager 3.3.0 and the updated `Radicalmultifield` plugin before upgrading media-management functionality. --- # WT Layout Select brings PHP layout selection to Joomla fields Section: Extensions URL: https://joomclub.net/extensions/wt-layout-select-php-layout-selection-joomla-fields Published: 2026-02-28 WT Layout Select is a Joomla custom-field plugin that lets editors choose a PHP layout from configured folders, while accounting for overrides in the active site template. The field stores the selected layout and base path as JSON and exposes a value suitable for rendering with Joomla’s `LayoutHelper`. The plugin scans specified directories for PHP layouts and presents the available options in a dropdown. It also checks the corresponding override locations under `/templates/