Security
Joomla fixes SQL injection in com_content webservice endpoint
Joomla administrators running 4.0.0-5.4.3 or 6.0.0-6.0.3 should upgrade to 5.4.4 or 6.0.4 to fix a Moderate SQLi vulnerability in the articles webservice endpoint.
The Joomla project has disclosed a vulnerability involving improperly constructed order clauses in the com_content articles webservice endpoint. Under the project’s classification, the impact is High, the severity is Moderate, and the exploit type is SQLi.
The issue is tracked as CVE-2026-21630. The affected Joomla! CMS releases are:
4.0.0-5.4.36.0.0-6.0.3
Administrators should update according to their major release branch. The project lists 5.4.4 as the fix for the 5.x series and 6.0.4 for the 6.x series. Sites that expose the relevant webservice functionality should treat the update as a maintenance priority, while checking application logs and access controls as part of their normal incident-review process.
The vulnerability was reported on 2026-03-05 and fixed on 2026-03-31. The Joomla Security Strike Team credits Antonio Morales from GitHub Security Lab Taskflow Agent and vnth4nhnt from CyStack with reporting the issue.
Published by the Joomla Security Centre.