# JoomClub > Independent English-language publication covering the Joomla CMS: security > advisories, releases, extensions, and practical guides for building and > running Joomla sites. Technical guidance targets Joomla 6. Content is free to read and quote with attribution and a link to the source article. Article pages are server-rendered: no JavaScript is required to read them, and the same HTML is served to every client. ## News - [Akeeba releases Grafida desktop client for Joomla](https://joomclub.net/news/akeeba-releases-grafida-desktop-client-for-joomla): Akeeba’s Grafida desktop client lets Joomla users manage content across multiple sites, with offline drafting and GitHub distribution. - [Joomla 6.1.1 and 5.4.6 fix security issues across core](https://joomclub.net/news/joomla-6-1-1-5-4-6-security-bugfix-release): Joomla 6.1.1 and 5.4.6 address 20 security issues and a broad set of bugs. Administrators should plan an update and test Joomla 6 upgrades. - [Joomla 6.1 and 5.4.5 released](https://joomclub.net/news/joomla-6-1-and-5-4-5-released): Joomla 6.1 adds Proof-of-Work CAPTCHA, visual workflows, media fields and module versioning, while 5.4.5 fixes several issues. - [Joomla 6.1 adds workflows, media fields and spam protection](https://joomclub.net/news/joomla-6-1-adds-workflows-media-fields-and-spam-protection): Joomla 6.1 adds Proof-of-Work CAPTCHA, a visual workflow editor, media custom fields, module versioning and multilingual associations. - [Joomla 6.1 adds workflow tools and broader media fields](https://joomclub.net/news/joomla-6-1-adds-workflow-tools-and-broader-media-fields): Joomla 6.1 [Nyota] adds Proof-of-Work CAPTCHA, visual workflows, media custom fields and versioning for modules. - [Joomla 5.4.5 tidies media, forms and content plugins](https://joomclub.net/news/joomla-5-4-5-media-forms-content-plugin-fixes): Joomla 5.4.5 fixes recursion, Media Manager dates, form validation, TinyMCE CSS loading and other issues across the 5.x series. - [Joomla 5.4.5 fixes editor, media and form issues](https://joomclub.net/news/joomla-5-4-5-fixes-editor-media-and-form-issues): Joomla 5.4.5 is a bugfix release addressing media, editor, custom field, validation and module-related issues. - [Joomla 6.1 RC3 puts the final package in testers’ hands](https://joomclub.net/news/joomla-6-1-rc3-final-package-testing): Joomla 6.1 Release Candidate 3 is available for testing, with extension compatibility checks ahead of the planned 14 April 2026 stable release. - [Joomla 6.1 RC2 asks extension developers to test](https://joomclub.net/news/joomla-6-1-rc2-extension-developers-test): Joomla 6.1 Release Candidate 2 is available for testing, with the stable release planned for 14 April 2026. - [Joomla 6.1 RC is ready for extension testing](https://joomclub.net/news/joomla-6-1-release-candidate-extension-testing): The Joomla 6.1 Release Candidate is available for testing, with a language freeze and a planned stable release on or about 14th April 2026. - [Joomla 6.0.4 and 5.4.4 address six security issues](https://joomclub.net/news/joomla-6-0-4-and-5-4-4-address-six-security-issues): Joomla 6.0.4 and 5.4.4 fix six security issues and bring bug fixes for administrators, developers and extension authors. - [Interim TinyMCE Firefox fix available for Joomla 5 and 6](https://joomclub.net/news/interim-tinymce-firefox-fix-joomla-5-6): An official interim patch addresses TinyMCE blinking in Firefox on Joomla 5.4.3 and 6.0.3 before its inclusion in the next release. - [Joomla 6.0.3 and 5.4.3 address bugs across the CMS](https://joomclub.net/news/joomla-6-0-3-and-5-4-3-address-bugs-across-the-cms): Joomla 6.0.3 and 5.4.3 bring bug fixes, dependency updates and improvements for site owners and extension developers. - [Joomla 6.0.2 and 5.4.2 address security bugs](https://joomclub.net/news/joomla-6-0-2-and-5-4-2-address-security-bugs): Joomla 6.0.2 and 5.4.2 fix two security issues, add PHP 8.5 support and deliver bug fixes for administrators and developers. ## Security - [Outdated PHP patches leave supported branches exposed](https://joomclub.net/security/outdated-php-patches-leave-supported-branches-exposed): mySites.guru highlights three PHP vulnerabilities and urges administrators to update supported branches to their latest patches. - [Phoca Cart patches critical unauthenticated SQL injection](https://joomclub.net/security/phoca-cart-patches-critical-unauthenticated-sql-injection): Phoca Cart 5.2.4 and 6.1.7 fix a critical unauthenticated SQL injection. Administrators on older branches must take action. - [JoomShaper fixes critical SP Page Builder flaw](https://joomclub.net/security/joomshaper-fixes-critical-sp-page-builder-flaw): mySites.guru reports critical pre-authentication vulnerabilities in Joomla's SP Page Builder. Administrators should update to 6.8.0. - [Cotton Cloud fixes two Joomla access control flaws](https://joomclub.net/security/cotton-cloud-fixes-two-joomla-access-control-flaws): Cotton Cloud 2.0.3 fixes two medium-severity Joomla access control flaws tracked as CVE-2026-67283 and CVE-2026-67284. - [Fabrik fixes critical unauthenticated RCE](https://joomclub.net/security/fabrik-fixes-critical-unauthenticated-rce): Fabrik 4.6.7 fixes a critical unauthenticated remote code execution flaw affecting versions 1.0.0 through 4.6.6. - [Critical Gridbox flaws fixed in Joomla extension update](https://joomclub.net/security/critical-gridbox-flaws-fixed-joomla-extension-update): mySites.guru reports 23 critical Gridbox vulnerabilities, including pre-auth RCE flaws. Update Joomla sites to Gridbox 2.20.2 immediately. - [JCE 2.9.99.10 fixes privileged file rename flaw](https://joomclub.net/security/jce-2-9-99-10-fixes-privileged-file-rename-flaw): JCE 2.9.99.10 fixes an authenticated file rename flaw affecting versions 2.9.99.6 to 2.9.99.9. No CVE was assigned. - [SP Page Builder 6.7.1 fixes four Joomla vulnerabilities](https://joomclub.net/security/sp-page-builder-671-fixes-four-joomla-vulnerabilities): JoomShaper has fixed four vulnerabilities in SP Page Builder for Joomla. Administrators should update to version 6.7.1 or later. - [Joomla AJAX handlers remain an overlooked security risk](https://joomclub.net/security/joomla-ajax-handlers-overlooked-security-risk): Joomla developers are warned that CSRF tokens do not replace ACL checks in com_ajax handlers and can leave administrative actions exposed. - [Joomla extension filter highlights third-party components](https://joomclub.net/security/joomla-extension-filter-highlights-third-party-components): Joomla’s extension manager includes a core-versus-third-party filter that helps administrators review components installed on a site. - [EasyStore 2.0.2 fixes three Joomla security flaws](https://joomclub.net/security/easystore-202-security-flaws): JoomShaper’s EasyStore 2.0.2 fixes invoice exposure, order forgery and SQL injection affecting version 2.0.1 and earlier. - [Regular Labs patches Joomla extensions across its catalogue](https://joomclub.net/security/regular-labs-patches-joomla-extensions-across-catalogue): Regular Labs fixed SSRF, command injection, stored XSS and other Joomla extension flaws. Administrators should update immediately. - [Regular Labs fixes security issues across Joomla extensions](https://joomclub.net/security/regular-labs-fixes-security-issues-across-joomla-extensions): Regular Labs fixed SSRF, XSS, command injection and other Joomla extension issues. Administrators should update affected extensions. - [PageBuilder CK fix left Joomla RCE open to Editors](https://joomclub.net/security/pagebuilder-ck-fix-left-joomla-rce-open-to-editors): PageBuilder CK versions 3.6.0 to 3.6.2 remained vulnerable to authenticated RCE. Update to 3.6.3. - [Events Booking flaw exposed registrants’ invoices](https://joomclub.net/security/events-booking-flaw-exposed-registrants-invoices): An unauthenticated IDOR in Joomla’s Events Booking exposed registrant invoices. Update to 5.8.2 and disable invoicing until then. - [mySites.guru says Joomla .htaccess hardening has limits](https://joomclub.net/security/mysitesguru-says-joomla-htaccess-hardening-has-limits): mySites.guru warns that Joomla .htaccess rules cannot block vulnerabilities reached through the main index.php entry point. - [Membership Pro 4.6.2 fixes critical anonymous upload flaw](https://joomclub.net/security/membership-pro-462-fixes-critical-anonymous-upload-flaw): JoomDonation Membership Pro 4.6.2 fixes a critical anonymous file upload flaw. Administrators should update and run its cleanup tool. - [Events Booking flaws allowed uploads and user-data exposure](https://joomclub.net/security/events-booking-flaws-allowed-uploads-and-user-data-exposure): mySites.guru reports unauthenticated upload and user-data exposure flaws in Joomla Events Booking. Update to 5.8.1. - [DJ-Classifieds flaw allowed unauthenticated file uploads](https://joomclub.net/security/dj-classifieds-flaw-allowed-unauthenticated-file-uploads): DJ-Classifieds versions through 3.11.1 contain a high-severity unauthenticated file-upload flaw. Update to 3.11.2. - [jDownloads fixes unauthenticated upload flaw in 4.1.6](https://joomclub.net/security/jdownloads-fixes-unauthenticated-upload-flaw-4-1-6): jDownloads 4.1.0–4.1.5 contain an unauthenticated upload flaw tracked as CVE-2026-61900. Update to 4.1.6. - [Joomla extensions hit by SQL injection and stored XSS flaws](https://joomclub.net/security/joomla-extensions-hit-by-sql-injection-and-stored-xss-flaws): JoomCCK and ChronoForms have high-severity Joomla flaws. Administrators should update to JoomCCK 6.4.1 and ChronoForms 8.0.53. - [Quix Page Builder SQL injection fixed in version 6.2.2](https://joomclub.net/security/quix-page-builder-sql-injection-fixed): An unauthenticated SQL injection in Quix Page Builder affected Joomla sites running 6.2.0 and earlier. Administrators should update to 6.2.2. - [JoomShaper releases security patches for Joomla 3 extensions](https://joomclub.net/security/joomshaper-releases-security-patches-for-joomla-3-extensions): JoomShaper has patched three extensions for Joomla 3, including flaws exploited in the wild. Administrators should update and investigate sites. - [DPCalendar reports serious read-only database access flaw](https://joomclub.net/security/dpcalendar-reports-serious-read-only-database-access-flaw): Digital Peak has reported a serious DPCalendar vulnerability that may expose Joomla database data without allowing changes. - [EDocman SQL injection fixed in version 3.9.0](https://joomclub.net/security/edocman-sql-injection-fixed-version-390): mySites.guru disclosed an unauthenticated SQL injection in Joomla's EDocman. Versions 3.8 and earlier are affected; update to 3.9.0. - [DPCalendar SQL injection fixed in Joomla security update](https://joomclub.net/security/dpcalendar-sql-injection-fixed-joomla-security-update): DPCalendar versions since 8.18.0 contain an unauthenticated SQL injection. Update to 10.11.2 or 8.19.4 immediately. - [Phoca Download fixes authenticated upload RCE](https://joomclub.net/security/phoca-download-fixes-authenticated-upload-rce): Phoca Download 6.1.2 and earlier allowed authenticated PHP uploads. Update Joomla sites to version 6.1.3 or later. - [RSFiles! fixes critical unauthenticated upload flaw](https://joomclub.net/security/rsfiles-fixes-critical-unauthenticated-upload-flaw): RSJoomla has fixed a critical RSFiles! file-upload flaw allowing unauthenticated remote code execution. Update to 1.17.12 or later. - [AcyMailing SQL injection fixed in version 10.11.1](https://joomclub.net/security/acymailing-sql-injection-fixed-in-version-10-11-1): AcyMailing versions 6.0.0 through 10.11.0 are affected by an unauthenticated SQL injection. Update to 10.11.1. - [Balbooa Forms fixes two unauthenticated RCE flaws](https://joomclub.net/security/balbooa-forms-fixes-two-unauthenticated-rce-flaws): Balbooa Forms users should update to 2.4.3 or later after two unauthenticated RCE flaws, including an actively exploited file upload bug. - [Joomla 6.1.2 and 5.4.7 address core security flaws](https://joomclub.net/security/joomla-6-1-2-and-5-4-7-address-core-security-flaws): Joomla 6.1.2 and 5.4.7 fix XSS and access-control issues, restore regressions, and add more than 35 other corrections. - [Joomla com_fields access flaw affects 4.x and 6.x](https://joomclub.net/security/joomla-com-fields-access-flaw-affects-4x-and-6x): Joomla sites running affected 4.x or 6.x versions should upgrade to address CVE-2026-48958 in com_fields webservice endpoints. - [Joomla fixes access control flaw in com_privacy endpoints](https://joomclub.net/security/joomla-fixes-access-control-flaw-in-com-privacy-endpoints): Joomla administrators should upgrade to address CVE-2026-48957, an incorrect access control issue affecting com_privacy webservice endpoints. - [Joomla fixes module access-control flaw](https://joomclub.net/security/joomla-fixes-module-access-control-flaw): Joomla addresses an incorrect access-control issue in com_modules that could expose a frontend module list to users. - [Joomla workflow access flaw fixed in version 6.1.2](https://joomclub.net/security/joomla-workflow-access-flaw-fixed-in-version-612): Joomla 6.0.0 through 6.1.1 have a Moderate incorrect access control flaw in com_workflow. Upgrade to 6.1.2. - [Joomla language overrides expose sites to moderate XSS](https://joomclub.net/security/joomla-language-overrides-expose-sites-to-moderate-xss): Joomla sites running affected CMS versions should upgrade to 5.4.7 or 6.1.2 to address a Moderate XSS vulnerability. - [Joomla generic image layout exposed to XSS](https://joomclub.net/security/joomla-generic-image-layout-exposed-to-xss): Joomla! CMS administrators should upgrade to 5.4.7 or 6.1.2 to address a Moderate-severity XSS vulnerability. - [Joomla com_installer XSS fixed in 5.4.7 and 6.1.2](https://joomclub.net/security/joomla-com-installer-xss-fixed-in-547-and-612): Joomla administrators should upgrade to 5.4.7 or 6.1.2 to address a Moderate XSS vulnerability in com_installer. - [Joomla fixes XSS in modalreturn layouts](https://joomclub.net/security/joomla-fixes-xss-in-modalreturn-layouts): Joomla addresses a Moderate XSS vulnerability in modalreturn layouts with updates to 5.4.7 and 6.1.2. - [Joomla fixes XSS in com_templates file management view](https://joomclub.net/security/joomla-fixes-xss-in-com-templates-file-management-view): Joomla addresses a Moderate XSS vulnerability in com_templates. Administrators should upgrade affected installations to 5.4.7 or 6.1.2. - [Joomla MFA XSS fixed in 5.4.7 and 6.1.2](https://joomclub.net/security/joomla-mfa-xss-fixed-in-547-and-612): Joomla fixes a Moderate XSS vulnerability in MFA management views. Upgrade affected 4.2.0-5.4.5 and 6.0.0-6.1.1 installs. - [Joomla fixes access control flaw in contact vCard downloads](https://joomclub.net/security/joomla-fixes-access-control-flaw-contact-vcard-downloads): Joomla addresses CVE-2026-48948, a Low-severity access control flaw in com_contact vCard downloads. - [Joomla com_media access flaw fixed in 5.4.7 and 6.1.2](https://joomclub.net/security/joomla-com-media-access-flaw-fixed-in-547-and-612): Joomla CMS administrators running affected 4.x, 5.x or 6.x releases should upgrade to address CVE-2026-48947. - [JoomShaper patches serious Helix Ultimate security flaws](https://joomclub.net/security/joomshaper-patches-helix-ultimate-security-flaws): JoomShaper's Helix Ultimate 2.2.7 fixes unauthenticated writes, stored XSS, file deletion, open redirect and other Joomla security flaws. - [Helix3 3.1.1 fixes critical Joomla security flaws](https://joomclub.net/security/helix3-311-fixes-critical-joomla-security-flaws): JoomShaper’s Helix3 3.1.1 fixes critical unauthenticated file-write and file-delete flaws. Administrators should update now. - [Hidden cron jobs can restore malware after Joomla cleanup](https://joomclub.net/security/hidden-cron-jobs-can-restore-malware-after-joomla-cleanup): mySites.guru explains how system-level cron jobs can reinfect Joomla sites after cleanup and highlights the actively exploited CVE-2026-54420. - [OVH falsely flags Joomla backup connector as malware](https://joomclub.net/security/ovh-falsely-flags-joomla-backup-connector-as-malware): mySites.guru says OVH wrongly flagged its Joomla connector and blocked hosting-plan email and outbound connections. - [SP Page Builder flaw exploited to create Joomla admins](https://joomclub.net/security/sp-page-builder-flaw-exploited-to-create-joomla-admins): SP Page Builder versions through 6.6.1 contain a critical unauthenticated upload flaw. Update to 6.6.2 and check for rogue admins. - [iCagenda flaw enabled unauthenticated RCE on Joomla 6](https://joomclub.net/security/icagenda-flaw-enabled-unauthenticated-rce-on-joomla-6): iCagenda versions up to 4.0.7 allowed unauthenticated file uploads and RCE on Joomla 6. Update to 4.0.8 or 3.9.15. - [Joomla Framework XSS fixed in cleanAttributes filtering](https://joomclub.net/security/joomla-framework-xss-fixed-cleanattributes-filtering): Joomla Framework users should upgrade to 5.4.6 or 6.1.1 to address a Moderate XSS issue in the cleanAttributes HTML filter code. - [Joomla fixes XSS in checkAttribute filtering](https://joomclub.net/security/joomla-fixes-xss-in-checkattribute-filtering): Joomla CMS versions 3.0.0-5.4.5 and 6.0.0-6.1.0 are affected by a Moderate XSS flaw. Upgrade to 5.4.6 or 6.1.1. - [Joomla fixes reset-link encryption downgrade](https://joomclub.net/security/joomla-fixes-reset-link-encryption-downgrade): Joomla administrators should upgrade affected CMS installations to address CVE-2026-48902, a Low-severity Mixed Content issue. - [Joomla InputFilter cache flaw fixed in 5.4.6 and 6.1.1](https://joomclub.net/security/joomla-inputfilter-cache-flaw-fixed): Joomla administrators should upgrade affected 4.x, 5.x and 6.x installations to address CVE-2026-48901, rated Low severity. - [Joomla fixes scheduler access control flaw](https://joomclub.net/security/joomla-fixes-scheduler-access-control-flaw): Joomla addresses CVE-2026-48900, an incorrect access control issue in com_scheduler affecting versions 4.1.0-5.4.5 and 6.0.0-6.1.0. - [Joomla sample data plugins expose access-control flaw](https://joomclub.net/security/joomla-sample-data-plugins-access-control-flaw): Joomla! CMS installations in two affected version ranges should be upgraded to address CVE-2026-48899 in sample data plugins. - [Joomla fixes privilege escalation in com_users webservices](https://joomclub.net/security/joomla-fixes-privilege-escalation-in-com-users-webservices): Joomla users of 4.0.0-5.4.5 and 6.0.0-6.1.0 should upgrade to 5.4.6 or 6.1.1 to fix CVE-2026-48904. - [Joomla fixes high-severity com_users privilege escalation](https://joomclub.net/security/joomla-fixes-high-severity-com-users-privilege-escalation): Joomla administrators should update affected 4.x and 6.x installations to address CVE-2026-48898 in the com_users batch task. - [Joomla MFA bypass fixed in security updates](https://joomclub.net/security/joomla-mfa-bypass-fixed-in-security-updates): Joomla administrators should upgrade to address a Moderate-severity MFA authentication bypass affecting Joomla! CMS 4 and 6 releases. - [Joomla MFA bypass affects 4.x and 6.x releases](https://joomclub.net/security/joomla-mfa-bypass-affects-4x-and-6x-releases): Joomla administrators should upgrade affected 4.x and 6.x installations to address CVE-2026-48896, an MFA authentication bypass. - [Joomla com_media path traversal requires an update](https://joomclub.net/security/joomla-com-media-path-traversal-update): Joomla! CMS versions 4.0.0-5.4.5 and 6.0.0-6.1.0 are affected by a moderate path traversal flaw in com_media. - [Joomla fixes high-severity LFI in HTMLView layout parameter](https://joomclub.net/security/joomla-fixes-high-severity-lfi-in-htmlview-layout-parameter): Joomla administrators should upgrade to 5.4.6 or 6.1.1 to address a high-severity local file inclusion vulnerability. - [Joomla com_config webservice access flaw fixed](https://joomclub.net/security/joomla-com-config-webservice-access-flaw-fixed): Joomla CMS administrators should upgrade affected 4.x and 6.x installations to address CVE-2026-35223 in com_config webservice endpoints. - [Joomla com_tags affected by authenticated blind SQLi](https://joomclub.net/security/joomla-com-tags-authenticated-blind-sqli): Joomla com_tags SQLi affects 4.0.0-5.4.5 and 6.0.0-6.1.0. Upgrade to 5.4.6 or 6.1.1. CVE-2026-352212. - [Joomla 6.0.0-6.1.0 affected by CSRF activation flaw](https://joomclub.net/security/joomla-6-0-0-6-1-0-csrf-activation-flaw): Joomla CMS 6.0.0-6.1.0 is affected by a Moderate CSRF flaw in com_users. Upgrade to 6.1.1. - [Joomla XSS flaw affects 4.x and 6.x installations](https://joomclub.net/security/joomla-xss-flaw-affects-4x-and-6x-installations): Joomla versions 4.0.0-5.4.5 and 6.0.0-6.1.0 are affected by a Moderate XSS flaw. Upgrade to 5.4.6 or 6.1.1. - [Joomla fixes moderate XSS in com_associations](https://joomclub.net/security/joomla-fixes-moderate-xss-in-com-associations): Joomla administrators should upgrade affected 4.x and 6.x installations to address a moderate XSS issue in com_associations. - [Joomla feed modules affected by moderate XSS flaw](https://joomclub.net/security/joomla-feed-modules-affected-by-moderate-xss-flaw): Joomla administrators should address a moderate XSS issue in feed modules by upgrading affected CMS installations to a fixed release. - [Sorry ransomware exploits critical cPanel authentication flaw](https://joomclub.net/security/sorry-ransomware-exploits-critical-cpanel-authentication-flaw): Sorry ransomware targets cPanel and WHM hosts through CVE-2026-41940. Administrators should patch, restore from clean backups and rotate credentials. - [AcyMailing privilege escalation also affects Joomla sites](https://joomclub.net/security/acymailing-privilege-escalation-also-affects-joomla-sites): AcyMailing 9.11.0–10.8.1 is affected by CVE-2026-3614 on Joomla sites. Update to 10.8.2. - [Malicious Smart Slider 3 Pro release affected Joomla sites](https://joomclub.net/security/malicious-smart-slider-3-pro-release-affected-joomla-sites): Nextend’s Smart Slider 3 Pro 3.5.1.35 contained a remote-code-execution backdoor. Joomla administrators should update and investigate. - [Joomla ACL issue affects com_ajax access checks](https://joomclub.net/security/joomla-acl-issue-affects-com-ajax-access-checks): Joomla administrators should upgrade to 5.4.4 or 6.0.4 to address CVE-2026-21629 in com_ajax. - [Joomla fixes SQL injection in com_content webservice endpoint](https://joomclub.net/security/joomla-fixes-sql-injection-com-content-webservice-endpoint): Joomla administrators on 4.0.0-5.4.3 or 6.0.0-6.0.3 should upgrade to 5.4.4 or 6.0.4 to address CVE-2026-21630. - [Joomla article title XSS fixed in 5.4.4 and 6.0.4](https://joomclub.net/security/joomla-article-title-xss-fixed-in-544-and-604): Joomla CMS versions 4.0.0-5.4.3 and 6.0.0-6.0.3 contain article title XSS vectors. Upgrade to 5.4.4 or 6.0.4. - [Joomla fixes high-severity file deletion flaw in com_joomlaupdate](https://joomclub.net/security/joomla-fixes-high-severity-file-deletion-flaw-in-com-joomlaupdate): Joomla administrators should upgrade to 5.4.4 or 6.0.4 to address a high-severity arbitrary file deletion vulnerability. - [Joomla webservice access flaw fixed in 5.4.4 and 6.0.4](https://joomclub.net/security/joomla-webservice-access-flaw-fixed-in-544-and-604): Joomla sites running affected CMS versions should upgrade to 5.4.4 or 6.0.4 to address CVE-2026-23899, an Incorrect Access Control flaw. - [Critical Novarain Framework flaw puts Joomla sites at risk](https://joomclub.net/security/critical-novarain-framework-flaw-puts-joomla-sites-at-risk): A critical flaw in Tassos’ Novarain Framework affects Joomla sites running versions 4.10.14 to 6.0.37. Update to 6.0.38 or later. - [Critical Astroid Framework flaw is under active exploitation](https://joomclub.net/security/critical-astroid-framework-flaw-under-active-exploitation): JoomDev's Astroid Framework for Joomla has a critical auth bypass. Update to 3.3.13 and check compromised sites for backdoors. - [Tassos Framework security patch fixes Joomla AJAX flaw](https://joomclub.net/security/tassos-framework-security-patch-joomla-ajax-flaw): Tassos has patched a Joomla vulnerability affecting six extensions, with fixes available for Joomla 3 and Joomla 4, 5 and 6. - [Joomla 3 security plugin reaches version 1.0.9](https://joomclub.net/security/joomla-3-security-plugin-version-1-0-9): Joomla-3-EOL-Security-Fixes 1.0.9 addresses five reported vulnerabilities affecting Joomla 3 sites, including XSS, SQL injection and file uploads. - [JL Content Fields Filter 4.0.0 adds Joomla 6 support](https://joomclub.net/security/jl-content-fields-filter-4-0-0-adds-joomla-6-support): JL Content Fields Filter 4.0.0 adds Joomla 6 and PHP 8.2+ support, fixes five SQL injections, and introduces a rebuilt administrator interface. - [Joomla passkey flaw enables user enumeration](https://joomclub.net/security/joomla-passkey-flaw-enables-user-enumeration): Joomla versions 4.0.0-4.4.13 and 5.0.0-5.3.3 are affected by a low-severity passkey user-enumeration flaw. ## Extensions - [Cookieless analytics without Joomla database tracking](https://joomclub.net/extensions/cookieless-analytics-without-joomla-database-tracking): StatJolt adds a Joomla plugin for external, cookieless analytics, with traffic, performance and funnel reports outside the Joomla database. - [SkynetAccessibility adds AI captions to Joomla videos](https://joomclub.net/extensions/skynetaccessibility-adds-ai-captions-to-joomla-videos): SkynetAccessibility Video Subtitle sends Joomla videos for automatic caption generation, but its metered plans and external API need checking. - [External wake-ups for Joomla Scheduled Tasks](https://joomclub.net/extensions/external-wake-ups-for-joomla-scheduled-tasks): QC Task Nudge & Health adds remote wake-ups, monitoring and recovery tools around Joomla's native Scheduled Tasks system. - [Media Organizer audits and quarantines unused Joomla files](https://joomclub.net/extensions/media-organizer-unused-joomla-files): Media Organizer scans Joomla media for unreferenced files, with quarantine, deletion checks, duplicate detection and image tools. - [Expose Phoca Download files to YOOtheme layouts](https://joomclub.net/extensions/expose-phoca-download-files-to-yootheme-layouts): Phoca Download Source connects Phoca Download records and fields to YOOtheme Pro layouts on Joomla 6 sites. - [Backlinkseller puts remote ad slots in YOOtheme Pro](https://joomclub.net/extensions/backlinkseller-yootheme-pro-ad-slots): Backlinkseller adds Backlinkseller advertising slots as a configurable YOOtheme Pro builder element for Joomla sites. - [Easy Tab Title animates browser titles and favicon badges](https://joomclub.net/extensions/easy-tab-title-animates-browser-titles-and-favicon-badges): Easy Tab Title adds rule-based browser-title effects and favicon badges for Joomla sites, with targeting and a JavaScript API. - [DleJTicket adds ticket threads, staff notes and email replies](https://joomclub.net/extensions/dlejticket-adds-ticket-threads-staff-notes-and-email-replies): DleJTicket adds frontend support tickets, staff management, internal notes, email replies and ticket-to-knowledge-base conversion to Joomla. - [Easy Lock hides selected article text behind registration](https://joomclub.net/extensions/easy-lock-hides-selected-article-text-behind-registration): Easy Lock gates selected Joomla article content behind login or registration, with optional teasers and group-based access. - [Restoring image-to-image navigation in JoomGallery 4](https://joomclub.net/extensions/restoring-image-to-image-navigation-in-joomgallery-4): JO JoomGallery Navigation adds previous and next image browsing to JoomGallery 4, with optional thumbnails, keyboard controls and looping. - [Easy Favicon generates site and administrator icon sets](https://joomclub.net/extensions/easy-favicon-generates-site-and-administrator-icon-sets): Easy Favicon generates multiple favicon formats from one image and adds separate site and administrator icons on Joomla 4, 5 and 6. - [DevArt Polls adds anonymous voting and multi-question surveys](https://joomclub.net/extensions/devart-polls-anonymous-voting-surveys): DevArt Polls adds anonymous polls and surveys to Joomla, with response management, CSV export, charts and configurable duplicate protection. - [Aura Forms adds visual multi-step form building to Joomla](https://joomclub.net/extensions/aura-forms-visual-multi-step-form-building): Aura Forms is a paid Joomla form builder for multi-step forms, surveys, submissions, notifications and spam controls. - [Aura SEO adds AI tools, sitemaps and schema controls](https://joomclub.net/extensions/aura-seo-ai-tools-sitemaps-schema-controls): Aura SEO adds audits, sitemaps, metadata, schema and optional AI content tools to Joomla, but several practical details need checking. - [Mail Log keeps Joomla mail activity in the administrator](https://joomclub.net/extensions/mail-log-keeps-joomla-mail-activity-in-the-administrator): Mail Log records Joomla-sent email, failures and selected message data for administrator review, with privacy controls and resend options. - [DPCalendar bookings entered from the Joomla backend](https://joomclub.net/extensions/dpcalendar-backend-bookings-entered-from-joomla-backend): DPCalendar - Backend Booking adds a Joomla administrator form for recording DPCalendar Pro bookings received by phone, email or paper. - [Notion databases as YOOtheme Pro content sources](https://joomclub.net/extensions/notion-databases-as-yootheme-pro-content-sources): Notion Source connects shared Notion databases to YOOtheme Pro, but its paid-download terms and operating limits need checking. - [A Joomla module for GSAP slideshow transitions](https://joomclub.net/extensions/dc-gsap-slider-gsap-slideshow-transitions): DC GSAP Slider is a free Joomla site module for responsive image slideshows with animated transitions, text overlays and links. - [Scanning Joomla PHP files for malware and backdoors](https://joomclub.net/extensions/scanning-joomla-php-files-for-malware-and-backdoors): JoomSAFE’s paid Scan Malware extension checks Joomla PHP files for suspicious code, web shells and backdoors. - [Twelve article layouts in one Joomla module](https://joomclub.net/extensions/twelve-article-layouts-in-one-joomla-module): Easy Articles Grid is a paid Joomla module for displaying com_content articles with multiple layouts, themes, Ajax loading and live search. - [A swipeable HTML5 game feed for Joomla pages](https://joomclub.net/extensions/swipeable-html5-game-feed-for-joomla-pages): Plays Games Widget embeds a swipeable HTML5 game feed in Joomla, extending core's basic HTML and iframe embedding options. - [Gated PDF viewers inside Joomla articles](https://joomclub.net/extensions/gated-pdf-viewers-inside-joomla-articles): Easy PDF adds modal, inline and download PDF presentation with login gates and protected streaming for Joomla articles. - [Product Order History adds per-product sales records to HikaShop](https://joomclub.net/extensions/product-order-history-per-product-sales-records-hikashop): Product Order history for HikaShop adds a paginated order list to each product in the Joomla backend. - [Site-Check applies approved accessibility fixes server-side](https://joomclub.net/extensions/site-check-applies-approved-accessibility-fixes-server-side): Site-Check Accessibility connects Joomla to an external service for approved HTML fixes and an optional visitor assistance overlay. - [Email Remover replaces public email addresses before HTML leaves Joomla](https://joomclub.net/extensions/email-remover-public-email-protection): Email Remover filters email addresses from Joomla front-end HTML, with options to remove, replace or render them as PNG images. - [Public gateway URLs for Joomla’s protected pages](https://joomclub.net/extensions/public-gateway-urls-for-joomlas-protected-pages): Quick Account Gateway adds public URLs that send guests to Joomla login and return them to the protected page afterwards. - [Mass Schedule Manager handles multi-church service times](https://joomclub.net/extensions/mass-schedule-manager-multi-church-service-times): Mass Schedule Manager manages church service times, seasonal changes and exceptions for Joomla sites serving one or more churches. - [JO Popup Login turns Joomla's login module into a popup](https://joomclub.net/extensions/jo-popup-login-popup-login-module): JO Popup Login places Joomla's login form in an AJAX popup, with configurable logged-in menus, redirects and appearance settings. - [Easy Accessibility adds a self-hosted visitor toolbar](https://joomclub.net/extensions/easy-accessibility-self-hosted-visitor-toolbar): Easy Accessibility is a paid Joomla module for a configurable front-end accessibility toolbar, with visitor controls for text, colour and reading. - [A server-side pass for Joomla’s missing alt and ARIA markup](https://joomclub.net/extensions/server-side-pass-for-joomlas-missing-alt-and-aria-markup): Easy WCAG is a paid Joomla system plugin that fixes selected rendered HTML gaps and flags accessibility issues for review. - [DevArt Documents builds a searchable file library for Joomla 6](https://joomclub.net/extensions/devart-documents-searchable-file-library-joomla-6): DevArt Documents adds a searchable, permission-controlled document library to Joomla 6 sites, with local and Google Drive storage options. - [Browser-based GDPR consent blocking for cached Joomla sites](https://joomclub.net/extensions/browser-based-gdpr-consent-blocking-cached-joomla-sites): DevArt Consent targets Joomla 6 sites that need GDPR consent controls and third-party blocking without session-based page variation. - [QC User Impersonation opens Joomla as another user](https://joomclub.net/extensions/qc-user-impersonation-opens-joomla-as-another-user): QC User Impersonation lets Joomla Super Users inspect a frontend session as an eligible user without using that user's password. - [Charging points for NorrCompetition contest actions](https://joomclub.net/extensions/charging-points-for-norrcompetition-contest-actions): NorrCompetition User Points adds paid point rules for contest entries and votes, connecting NorrCompetition contests to Joomla commerce sites. - [Hide admin markers from Joomla’s public titles](https://joomclub.net/extensions/hide-admin-markers-from-joomlas-public-titles): Strip Comments hides administrator-only markers in Joomla titles and other front-end output while leaving those markers visible in the back end. - [JUX Portfolio Gallery builds filtered image and video grids](https://joomclub.net/extensions/jux-portfolio-gallery-filtered-image-video-grids): JUX Portfolio Gallery is a paid Joomla module for filtered image and video portfolios, with grid, masonry and lightbox layouts. - [PublikWALL turns article listings into a tiled homepage grid](https://joomclub.net/extensions/publikwall-article-tile-grid): PublikWALL is a free Joomla module for displaying articles in a configurable tile grid, with optional JEvents event tiles. - [File baselines and malware signatures for Joomla 5 and 6](https://joomclub.net/extensions/file-baselines-malware-signatures-joomla-5-6): Integrity Checker adds file-change monitoring and signature-based malware scanning to Joomla sites, with free and paid editions. - [Easy Helpdesk adds ticket queues and agent tools to Joomla](https://joomclub.net/extensions/easy-helpdesk-ticket-queues-agent-tools): Easy Helpdesk adds customer tickets, agent queues, knowledge-base articles and email workflows to Joomla sites. - [Live JomSocial totals in a publishable Joomla module](https://joomclub.net/extensions/live-jomsocial-totals-publishable-joomla-module): PluggerBox Community Stats adds live JomSocial member, group and photo totals as a configurable Joomla module. - [Sixteen animated transitions for Joomla image slideshows](https://joomclub.net/extensions/sixteen-animated-transitions-for-joomla-image-slideshows): DC GSAP Slider is a free Joomla module for image slideshows with animated transitions, slide text, calls to action and responsive height settings. - [Scan Malware checks Joomla files for suspicious PHP code](https://joomclub.net/extensions/scan-malware-checks-joomla-files): JoomSAFE’s paid Scan Malware extension examines Joomla files for suspicious PHP code, web shells, backdoors and other signs of compromise. - [Ajax article grids and magazine layouts in Easy Articles Grid](https://joomclub.net/extensions/ajax-article-grids-magazine-layouts-easy-articles-grid): Easy Articles Grid presents Joomla articles in varied layouts with Ajax loading, category filters, live search and visual controls. - [A swipeable HTML5 game feed for Joomla sites](https://joomclub.net/extensions/swipeable-html5-game-feed-for-joomla-sites): Plays Games Widget embeds a browsable HTML5 game feed in Joomla, extending core’s basic content and iframe options. - [Easy PDF adds gated PDF viewing to Joomla articles](https://joomclub.net/extensions/easy-pdf-gated-viewing-joomla-articles): Easy PDF presents PDFs inside Joomla articles with viewer modes, access gates and download controls, according to its directory listing. - [A backend order trail for HikaShop products](https://joomclub.net/extensions/backend-order-trail-for-hikashop-products): Product Order history for HikaShop adds a paginated list of product orders to the HikaShop product page in Joomla's administrator. - [What Site-Check Accessibility adds to Joomla](https://joomclub.net/extensions/what-site-check-accessibility-adds-to-joomla): Site-Check Accessibility connects Joomla to an external service that applies approved accessibility fixes to delivered HTML. - [Email Remover takes a different approach to Joomla email protection](https://joomclub.net/extensions/email-remover-joomla-email-protection): Joomla's free Email Remover plugin removes or replaces email addresses in front-end HTML instead of merely cloaking them. - [A gateway layer for Joomla’s protected pages](https://joomclub.net/extensions/quick-account-gateway-context): Quick Account Gateway adds public entry URLs for protected Joomla pages, with login and return redirects handled for visitors. - [A Joomla schedule manager for parish websites](https://joomclub.net/extensions/joomla-mass-schedule-manager-parish-websites): Mass Schedule Manager adds church schedules, exceptions and next-Mass displays to Joomla sites serving parishes and religious communities. - [Joomla extension manager highlights third-party entries](https://joomclub.net/extensions/joomla-extension-manager-highlights-third-party-entries): Joomla’s extension manager includes a Core - Third Party filter, helping administrators identify non-core extensions during site checks. - [joomLab Article Slider 1.1.0 adds AJAX content filtering](https://joomclub.net/extensions/joomlab-article-slider-1-1-0-ajax-filtering): joomLab Article Slider 1.1.0 adds AJAX filtering by Joomla categories and tags to its responsive article slideshow module. - [Joomla 6 component generates llms.txt files](https://joomclub.net/extensions/joomla-6-component-generates-llms-txt-files): A Joomla 6 component generates llms.txt and llms-full.txt files from sitemap data, metadata, articles and menu items. - [WT LLMs brings AI-readable site files to Joomla](https://joomclub.net/extensions/wt-llms-brings-ai-readable-site-files-to-joomla): WT LLMs is a Joomla 5+ component that generates llms.txt, llms-full.txt and llms.json for AI agents and structured site access. - [WT LLMs adds llms.txt and llms.json support to Joomla](https://joomclub.net/extensions/wt-llms-adds-llms-txt-and-llms-json-support-to-joomla): WT LLMs is a Joomla 5+ component for generating llms.txt, llms-full.txt and llms.json files for AI agents and structured site access. - [NorrCompetition 3.0 adds native Joomla 6 support](https://joomclub.net/extensions/norrcompetition-3-0-native-joomla-6-support): NorrCompetition 3.0 brings native Joomla 6 support, email OTP voting confirmation, new rating scales and updated submission tools. - [SP Page Builder 6.5.0 adds CAPTCHA and schema support](https://joomclub.net/extensions/sp-page-builder-6-5-0-adds-captcha-and-schema-support): SP Page Builder 6.5.0 adds CAPTCHA support for Joomla 6.1, Schema.org integration, pagination and fixes across its addons. - [RadicalForm plugin brings article creation to Joomla 5 and 6](https://joomclub.net/extensions/radicalform-plugin-article-creation-joomla-5-6): A free RadicalForm plugin for Joomla 5 and 6 creates articles from form submissions and maps form fields to custom article fields. - [RadicalForm 4.0.0 adds Joomla 6 support](https://joomclub.net/extensions/radicalform-4-0-0-adds-joomla-6-support): RadicalForm 4.0.0 introduces a new architecture, Joomla 5 and 6 support, and expanded anti-spam and upload protections. - [RadicalForm 3.1.6 adds anti-spam tools for Joomla 3 and 4](https://joomclub.net/extensions/radicalform-3-1-6-adds-anti-spam-tools): RadicalForm 3.1.6 is the final release for the Joomla 3 and 4 architecture and adds an Anti-Spam section for form submissions. - [JoomShopping adds an alpha REST API extension for Joomla](https://joomclub.net/extensions/joomshopping-alpha-rest-api-extension-joomla): JoomShopping has introduced an alpha REST API add-on for Joomla, exposing more than 40 shop resources for integrations and applications. - [Joomill adds checklist management to Joomla’s administrator](https://joomclub.net/extensions/joomill-admin-checklist-for-joomla): Joomill’s Admin Checklist adds task lists, categories, status tracking and administrator-area integration to Joomla sites. - [JoomShopping 5.9.1 fixes order and product issues](https://joomclub.net/extensions/joomshopping-5-9-1-fixes-order-and-product-issues): JoomShopping 5.9.1 fixes duplicate order numbers and product attribute image uploads, while adding configuration and logging changes. - [WT Article Select adds article data to Joomla custom fields](https://joomclub.net/extensions/wt-article-select-adds-article-data-to-joomla-custom-fields): WT Article Select is a free Joomla custom-field plugin for selecting articles and exposing their data during field rendering. - [Phoca demonstrates an AI workflow for Joomla websites](https://joomclub.net/extensions/phoca-demonstrates-ai-workflow-for-joomla-websites): Phoca presents a Joomla workflow combining AI content and design generation with a template and module-building extension. - [joomLab Gallery 1.1.0 adds Joomla 6 support](https://joomclub.net/extensions/joomlab-gallery-1-1-0-adds-joomla-6-support): joomLab Gallery 1.1.0 adds Joomla 6 support and lets administrators place galleries in standard HTML modules. - [JoomShopping extension links products by shared characteristics](https://joomclub.net/extensions/joomshopping-extension-links-products-by-shared-characteristics): A JoomShopping 5+ extension helps administrators create related-product groups by selecting shared characteristics. - [Quantum Manager 3.3.0 adds Joomla 6 compatibility](https://joomclub.net/extensions/quantum-manager-3-3-0-adds-joomla-6-compatibility): Quantum Manager 3.3.0 is fully compatible with Joomla 6, adds SVG filtering options, restores safe SVG previews and updates EXIF support. - [WT Layout Select brings PHP layout selection to Joomla fields](https://joomclub.net/extensions/wt-layout-select-php-layout-selection-joomla-fields): WT Layout Select adds a Joomla custom field for choosing PHP layouts, including active template overrides and LayoutHelper rendering. - [JoomGallery 4.3.0 adds a frontend user panel](https://joomclub.net/extensions/joomgallery-4-3-0-adds-frontend-user-panel): JoomGallery 4.3.0 adds a frontend user panel, allowing registered Joomla users to manage their own categories and images. - [Health Checker for Joomla reaches version 3.1.1](https://joomclub.net/extensions/health-checker-for-joomla-311): Health Checker for Joomla 3.1.1 audits more than 130 site and server settings, with a separate YOOtheme Pro plugin offering 35 additional checks. - [SW JProjects 2.6.1 expands update server version handling](https://joomclub.net/extensions/sw-jprojects-261-update-server-version-handling): SW JProjects 2.6.1 improves update server schema inheritance, includes non-stable releases, and updates its default template. - [Kunena 7.0 brings native Joomla 6 support](https://joomclub.net/extensions/kunena-7-0-native-joomla-6-support): Kunena 7.0 is now available for Joomla 5.4 and 6.0, with updated events, CAPTCHA handling, scheduled tasks and spam checks. - [JL Like 5.3.0 adds Threads and Reddit support](https://joomclub.net/extensions/jl-like-530-adds-threads-and-reddit-support): JL Like 5.3.0 adds Threads and Reddit buttons, five button styles, drag-and-drop ordering and improved fixed-button positioning. - [YOOtheme Pro 5 drops Joomla 3 and 4 support](https://joomclub.net/extensions/yootheme-pro-5-drops-joomla-3-and-4-support): YOOtheme Pro 5 adds cookie controls, date filtering and new builder features, but requires Joomla 5 or later and includes breaking changes. - [CFI 2.0.0 brings full Joomla article CSV import and export](https://joomclub.net/extensions/cfi-2-0-0-joomla-article-csv-import-export): CFI 2.0.0 adds full Joomla article CSV import and export, filtering, custom-field support and Joomla 6 compatibility. - [TelePost connects Telegram channels with Joomla publishing](https://joomclub.net/extensions/telepost-connects-telegram-channels-with-joomla-publishing): The free TelePost Joomla plugin imports Telegram posts as articles, supports media and hashtags, and is built for Joomla 5 and 6. - [Astroid Framework 3.3.7 fixes layout file loading](https://joomclub.net/extensions/astroid-framework-3-3-7-fixes-layout-file-loading): Astroid Framework 3.3.7 fixes layout file loading and follows the broader UI, builder, and styling improvements introduced in 3.3.6. - [Revo PageBuilder Toolkit 1.6.2 adds layout error checks](https://joomclub.net/extensions/revo-pagebuilder-toolkit-1-6-2-layout-error-checks): Revo PageBuilder Toolkit 1.6.2 adds network recovery, layout error highlighting and improved support for YOOtheme Pro 5 and CodeMirror 6. - [Content Cart 4.0.0 brings security and performance changes](https://joomclub.net/extensions/content-cart-4-0-0-security-performance-update): JoomLine has released Content Cart 4.0.0 for Joomla 5 and 6, with security fixes, caching changes and configurable cart TTL. - [WT IndexNow package brings IndexNow submissions to Joomla](https://joomclub.net/extensions/wt-indexnow-package-brings-indexnow-submissions-to-joomla): WT IndexNow supports manual and automatic IndexNow URL submissions from Joomla 4.3+ sites, with integrations for several Joomla extensions. ## Development - [Joomla 6.2 to add native multi-category support](https://joomclub.net/development/joomla-6-2-native-multi-category-support): Joomla 6.2 is set to add native multi-category support, allowing content and other entities to appear in multiple categories. - [Connect Your IDE to a Live Joomla Database Over SSH](https://joomclub.net/development/connect-ide-to-joomla-database-over-ssh): Query a production Joomla database from PhpStorm without exposing MySQL to the internet — SSH tunnel setup, and the safeguards to put in place first. - [Package a Joomla Extension So It Installs and Updates Cleanly](https://joomclub.net/development/package-a-joomla-extension): The manifest, the install package and the update server — what an extension needs so users can install it once and update it forever. - [Custom Fields or a Content Construction Kit?](https://joomclub.net/development/custom-fields-or-a-content-construction-kit): Joomla has custom fields in core. Where they are enough for structured content, and where a construction kit still earns the dependency. - [Submit a Joomla Form With a File Upload Over Ajax](https://joomclub.net/development/ajax-file-upload-joomla-form): FormData and fetch replace the old hidden-iframe trick. How to post a file to Joomla over Ajax with a valid CSRF token and server-side checks. - [Find the Top-Level Category of Any Joomla Category](https://joomclub.net/development/find-top-level-joomla-category): Nested sets make walking up the Joomla category tree a single query. A helper that returns the top-level ancestor, with the caching mistake to avoid. - [How to preserve UIkit attributes in Joomla TinyMCE](https://joomclub.net/development/preserve-uikit-attributes-joomla-tinymce): A Joomla TinyMCE setting can preserve UIkit attributes such as uk-grid when editing article markup in WYSIWYG mode. - [Joomla team works toward an MCP server for AI administration](https://joomclub.net/development/joomla-team-works-toward-mcp-server-ai-administration): Joomla developers are working on an MCP server for AI-assisted administration, with token authentication and extensible plugin-based tools. - [Joomla trials a redesigned feature-request workflow](https://joomclub.net/development/joomla-trials-redesigned-feature-request-workflow): Joomla is testing a redesigned feature-request workflow intended to make planning more transparent and predictable for maintainers and contributors. ## Templates & Frontend - [See Every Module Position in a Joomla Template](https://joomclub.net/frontend/preview-module-positions-joomla): Joomla can outline every module position in the front end. Turn the preview on in Template Manager options, then append ?tp=1 to any URL. - [Stop Extensions Loading Assets Your Template Does Not Use](https://joomclub.net/frontend/stop-extensions-loading-unused-assets-joomla): A module or component pulls Bootstrap into every page even though your template does not use it. Find the culprit and disable the asset properly. - [Your Main Menu Has Too Many Items](https://joomclub.net/frontend/main-menu-too-many-items): Thirteen top-level menu items is a decision nobody made. How to cut a Joomla main menu down to what visitors actually came for. - [What Belongs on a Front Page, and What Does Not](https://joomclub.net/frontend/what-belongs-on-a-front-page): Weather widgets, currency rates and ten reasons to choose us. A practical pass over the front page of a small business site, deciding what earns its place. - [Images That Are Killing Your Page Weight](https://joomclub.net/frontend/image-optimisation-for-joomla-sites): Resizing in the browser is not resizing. Picking formats, compression levels and srcset so a Joomla page loads in the weight it looks like it should. - [Article Markup Mistakes That Break Your Template](https://joomclub.net/frontend/article-markup-mistakes-joomla): Fake lists, fake headings, pasted Word markup and a readmore in the wrong place — the editing habits that quietly wreck a Joomla layout. - [Generate and Cache Derived Images in a Joomla Template](https://joomclub.net/frontend/generate-and-cache-derived-images-joomla): When CSS cannot produce the thumbnail you need, generate it once with GD and cache the result — including the path checks that keep it safe. - [Styling and Extending the Joomla Menu Module](https://joomclub.net/frontend/styling-the-joomla-menu-module): The markup mod_menu produces, the classes worth styling against, and how to override the layout for a dropdown without breaking keyboard access. - [Icons in a Joomla Template Without the Sprite Sheet Era](https://joomclub.net/frontend/icons-in-joomla-templates): Icon fonts, SVG sprites and inline SVG in a Joomla template — what Joomla already ships, and how to add icons without loading a whole library. - [Conditional Layouts in Joomla Templates](https://joomclub.net/frontend/conditional-layouts-joomla-templates): Collapse a sidebar when its modules are unpublished, widen the content area, and branch on the active view — the conditions every Joomla template needs. - [jdoc Placeholders and Module Chrome in Joomla 6](https://joomclub.net/frontend/jdoc-placeholders-module-chrome-joomla): Every jdoc type a Joomla 6 template can use, and how to write your own module chrome as a layout instead of the old modChrome functions. - [Make Article Images Link to the Article](https://joomclub.net/frontend/link-intro-images-to-articles-joomla): Visitors click the picture expecting to open the article. In Joomla 6 that behaviour is a setting, not a template hack — here is where it lives. - [Build a Joomla Template From an Empty Folder](https://joomclub.net/frontend/build-a-joomla-template-from-scratch): The three files a Joomla 6 template needs, where its CSS actually belongs, and the jdoc placeholders that turn HTML into a working template. - [How to Organise Stylesheets in a Joomla 6 Template](https://joomclub.net/frontend/organise-stylesheets-joomla-template): Custom properties, cascade layers and a build step only where it earns its place — structuring template CSS so it survives more than one redesign. - [Build a Custom Error Page in Your Joomla Template](https://joomclub.net/frontend/custom-error-page-joomla-template): Give 404s the same design as the rest of the site: copy error.php into your template, render modules on it, and know what the error page cannot do. - [Put the Joomla Login Form in a Modal Dialog](https://joomclub.net/frontend/joomla-login-form-modal-dialog): Override mod_login with an alternative layout and open it in a native dialog element — no jQuery, no MooTools, no extension required. - [Using Bootstrap in a Joomla 6 Template Without Loading All of It](https://joomclub.net/frontend/using-bootstrap-in-a-joomla-6-template): Joomla ships Bootstrap 5 as separate assets. Load the two components you actually use, or drop it entirely — both are one line in your template. ## SEO - [Heading Structure and Front-Page Duplicates in Joomla](https://joomclub.net/seo/heading-structure-front-page-duplicates-joomla): Kill the /index.php and menu-alias copies of your front page, and check what heading level Joomla is really giving your articles before overriding anything. - [Technical SEO Checklist for a New Joomla Site](https://joomclub.net/seo/technical-seo-checklist-joomla): URLs, canonicals, redirects, sitemap and robots.txt — the technical groundwork a Joomla site needs before content work is worth doing. - [Where Joomla Sets a Canonical URL and Where You Must](https://joomclub.net/seo/canonical-urls-in-joomla): Joomla ships no canonical tag by default. Where to emit one, why pagination must stay self-canonical, and the cases a canonical cannot fix. - [Redirect Old Query-String URLs After Moving to Joomla](https://joomclub.net/seo/redirect-query-string-urls-joomla-migration): The old site used index.php?cid=2&tid=3&fid=345 and Joomla's redirect manager ignores the parameters. Three ways to map those URLs that survive an update. - [Structured Data in Joomla 6 Is Already Switched On](https://joomclub.net/seo/structured-data-in-joomla-6): Joomla ships schema.org output as core plugins — Article, BlogPosting, Event, Person, Recipe and more. Where to configure it and when to add your own. - [Seven Ways to Remove Duplicate Content in Joomla](https://joomclub.net/seo/seven-ways-to-remove-duplicate-content-in-joomla): Canonical tags, 301 redirects, robots directives and the Joomla settings that stop duplicate URLs from reaching the index. Practical fixes for Joomla 6. - [Duplicate Content in Joomla: Where It Comes From and How to Find It](https://joomclub.net/seo/duplicate-content-in-joomla-causes): Why a Joomla site serves the same article under several URLs, how menu structure creates duplicates, and how to find them before search engines do. - [Do You Still Need a Third-Party SEF Extension?](https://joomclub.net/seo/do-you-need-a-third-party-sef-extension): Joomla 6 routes URLs, removes IDs and manages redirects on its own. What is actually left for an SEF extension, and what one costs you. ## Hosting & Maintenance - [A Backup Routine That Actually Restores](https://joomclub.net/hosting/joomla-backup-routine-that-restores): What a Joomla backup must contain, where it must not live, and the restore rehearsal that separates a backup from a folder of files. - [Choosing Hosting for a Joomla 6 Site](https://joomclub.net/hosting/choosing-hosting-for-joomla-6): Joomla 6 needs PHP 8.3 or newer. Beyond that, the things that decide whether a host is workable are shell access, backups and how updates behave. ## Migration & Upgrades - [Moving a Legacy Joomla Site to Joomla 6](https://joomclub.net/migration/moving-a-legacy-joomla-site-to-joomla-6): There is no upgrade path from Joomla 1.5 or 2.5 to 6. What the migration actually involves, and why the extensions decide the timeline. ## Community - [Getting an Extension Listed in the JED](https://joomclub.net/community/getting-an-extension-listed-in-the-jed): What the Joomla Extensions Directory expects from a submission, the requirements that get listings rejected, and what to do after approval. - [What Joomla Is Actually Good At](https://joomclub.net/community/what-joomla-is-actually-good-at): Not a pitch. Where Joomla's access control, multilingual handling and update policy make it the right choice — and where it plainly is not. - [Joomla World Conference returns in Germany in October 2026](https://joomclub.net/community/joomla-world-conference-germany-october-2026): The Joomla World Conference will take place in Germany from 16 to 18 October 2026, with English and German sessions. - [Joomla launches user documentation portal for version 5+](https://joomclub.net/community/joomla-user-documentation-portal-version-5): A new English-language portal provides user and administrator documentation for Joomla 5+, while older docs remain available for earlier releases. - [Joomla wins two CMS Critic Awards in 2025](https://joomclub.net/community/joomla-wins-two-cms-critic-awards-in-2025): Joomla has been named Best Free CMS and Best Open Source CMS in the CMS Critic Awards People's Choice Awards 2025. - [Joomla selected for Google Summer of Code 2026](https://joomclub.net/community/joomla-selected-for-google-summer-of-code-2026): Joomla will participate in GSoC 2026 with proposed projects covering Ajax, workflows, multi-category content and translation quality. - [Joomla community sets Pizza, Bugs & Fun for January 2026](https://joomclub.net/community/joomla-pizza-bugs-fun-january-2026): Pizza, Bugs & Fun returns on 29–30 January 2026, giving Joomla contributors a way to test code, fix bugs and improve documentation. - [NorrNext publishes final interviews from its first magazine issue](https://joomclub.net/community/norrnext-publishes-final-interviews-first-magazine-issue): NorrNext’s first magazine issue concludes with 25 English-language interviews featuring Joomla contributors from around the world. ## Full text - [Every article in one file](https://joomclub.net/llms-full.txt)