News
Joomla 6.1.2 and 5.4.7 fix security flaws
Joomla 6.1.2 and 5.4.7 bring 12 security fixes and a range of maintenance changes, although administrators affected by an article-display regression should install the available hotfix.
The security work covers incorrect access control and cross-site scripting issues across several parts of the CMS. The affected components include com_media, com_contact, com_workflow, com_modules, com_privacy and com_fields webservices, along with com_templates, com_installer and other output and language-handling paths. The release also addresses XSS in MFA method management and several modal and image layouts.
Administrators should test and apply the update through the usual Joomla update process. The project also warns of a regression affecting articles shown on the front end: article-specific parameters can be ignored in favour of menu-item or global settings. This can produce an unintended layout, including for articles linked through category layouts or single-article menu items.
A corrective patch is available for affected sites while the permanent fix is scheduled for 5.4.8 and 6.1.3. The installable ArticleModel hotfix can be applied immediately. Administrators should review the result on a staging copy before deploying either the release or patch to production.
The update set also includes fixes for webservices, installer behaviour, editor duplication, mail templates, accessibility, scheduled tasks, extension updates and user filtering. Sites moving from Joomla 5.4.x to 6.x should verify extension compatibility first.
Published by the Joomla Project.