Security
Joomla 6.1.2 and 5.4.7 address core security flaws
Joomla has released versions 6.1.2 and 5.4.7 with security fixes for the core and web services, alongside more than 35 bug fixes and stability improvements. Sites running Joomla 5.x or 6.x should be updated.
Security fixes
The releases address cross-site scripting (XSS) vulnerabilities affecting several administrative and frontend areas, including multifactor authentication (MFA) method management, com_templates, com_installer, language overrides, and image and modal output layouts.
They also correct access-control problems in web-service endpoints for com_media, com_privacy, and com_fields. Related permission issues were fixed in the contacts component, com_contact, as well as modules and workflow processes involving com_modules and com_workflow.
Other changes
More than 35 additional corrections are included in the two releases. Notable changes include:
- Extensions can now be updated directly from the command line through the CLI.
- A bug that duplicated the CodeMirror editor has been fixed.
- Pagination in modal windows has been corrected.
- Successful Joomla alert messages now receive the intended styling.
- A critical regression introduced by earlier security updates in Joomla 5.4.6 and 6.1.1 has been resolved.
- The installer no longer fails when moving to the database step if a password contains leading or trailing spaces.
All fixes from the 5.4 branch have also been carried into 6.1. Administrators maintaining sites on either supported branch should apply the relevant release.