News
Joomla 6.0.2 and 5.4.2 address security bugs
The Joomla project has released 6.0.2 and 5.4.2, addressing two security issues, fixing bugs across the CMS and adding full support for PHP 8.5.
Both releases contain fixes in Joomla! Core for inadequate content filtering affecting data URLs and an XSS vector in the pagebreak plugin. The announcement does not assign severity ratings or CVE identifiers to either issue, but site administrators should plan to install the update through the normal Joomla update process.
The 6.0.2 update also improves several areas of the administrator and front-end experience. Changes include corrected menu toggle start-level handling, improved deep-submenu display, a fix for tinyMCE dark mode, better handling of broken language-file caches and fixes for email-to-Punycode conversion. Updates to Cassiopeia Extended address button hover colours and missing front-end translations. Dependency audit fixes are included as well.
Joomla sites running 5.4.x can move to the 6.x series as an upgrade rather than a migration, provided extensions are compatible. The project recommends testing on a copy of the production site first and checking extension readiness. Support for the 5.4.x branch continues with bugfix patches until 13 October 2026 and security patches until 12 October 2027.
Published by the Joomla Project.