Security
Joomla 3 security plugin reaches version 1.0.9
A security plugin for sites still running the unsupported Joomla 3 series has reached version 1.0.9, addressing five reported vulnerabilities including cross-site scripting, SQL injection and malicious file uploads.
Joomla 3 is no longer officially supported, but many websites continue to use the series. The project behind Joomla-3-EOL-Security-Fixes says its latest update is intended to provide ongoing security maintenance for those installations.
Version 1.0.9 addresses the following issues:
CVE-2025-63083: an XSS vector in the Pagebreak plugin.CVE-2025-63082: inadequate content filtering for data URLs.CVE-2025-25226: SQL injection in the Database package.CVE-2025-22213: malicious file uploads through Media Manager.CVE-2024-40747: missing escaping in module chrome attributes.
The update therefore covers vulnerabilities in several Joomla components, from content rendering and URL filtering to database handling and media uploads. The post describes all five issues as critical and recommends that Joomla 3 administrators install and regularly update the security plugin while their sites remain on the unsupported branch.
The project is available on GitHub under the name TLWebdesign/Joomla-3-EOL-Security-Fixes. The repository is hosted at github.com/TLWebdesign/Joomla-3-EOL-Security-Fixes.