News
Joomla 6.0.4 and 5.4.4 address six security issues
Joomla 6.0.4 and 5.4.4 are now available with six security fixes, alongside bug fixes affecting administration, web services, media, workflows and scheduled tasks.
The Joomla project released 6.0.4 for the Joomla 6.x series and 5.4.4 for Joomla 5.x. Site administrators should treat both as maintenance updates, particularly because the releases address access control, injection, cross-site scripting and file deletion issues.
- ACL hardening in
com_ajax - SQL injection in the
com_contentarticles webservice endpoint - An XSS vector in the
com_associationscomparison view - XSS vectors in article title outputs
- Arbitrary file deletion in
com_joomlaupdate - An improper access check in webservice endpoints
The maintenance work also resolves administrator sidebar icon flashing, PHP warnings in the Page Break modal, scheduled tasks stopping after a stuck task, media editing controls, workflow permission warnings and several calendar, editor, asset and article display problems. Developers should also note fixes to email validation and extension-related update handling.
Joomla 5.4.x sites can move to Joomla 6.x through an upgrade rather than a migration, but the project advises testing on a copy of the production site first. Extension compatibility still needs checking; the Behaviour 6 - Backward Compatibility Plugin may be required for some extensions. Joomla 5.4.x receives bugfix patches until 13 October 2026 and security patches until 12 October 2027.
Published by the Joomla Project.