Joomla fixes module access-control flaw
Joomla CMS sites running 4.0.0-5.4.6 or 6.0.0-6.1.1 should be upgraded to 5.4.7 or 6.1.2 to address a Moderate-severity access-control issue.
News, security and craft for the Joomla ecosystem
Security releases, vulnerabilities and hardening for Joomla.
Joomla CMS sites running 4.0.0-5.4.6 or 6.0.0-6.1.1 should be upgraded to 5.4.7 or 6.1.2 to address a Moderate-severity access-control issue.
Administrators running Joomla! CMS 6.0.0-6.1.1 should upgrade to 6.1.2 to address a Moderate Incorrect Access Control vulnerability in com_workflow, tracked as…
Joomla! CMS sites running versions 3.0.0-5.4.5 or 6.0.0-6.1.1 are affected by a Moderate XSS vulnerability in language overrides; administrators should upgrade…
Administrators running Joomla! CMS 4.0.0-5.4.5 or 6.0.0-6.1.1 should upgrade to 5.4.7 or 6.1.2 to address a Moderate-severity XSS vulnerability in the generic…
Joomla administrators running affected CMS releases should upgrade to 5.4.7 or 6.1.2, which fix a Moderate XSS vulnerability in com_installer.
Joomla administrators should upgrade to version 5.4.7 or 6.1.2 to address a Moderate XSS vulnerability in modalreturn layouts, tracked as CVE-2026-48951.
Joomla installations in the affected 4.x, 5.x and 6.x ranges should be upgraded to 5.4.7 or 6.1.2 to address a Moderate XSS vulnerability in com_templates…
Joomla! CMS versions 4.2.0-5.4.5 and 6.0.0-6.1.1 are affected by an XSS vulnerability in the MFA management views. The Joomla project rates it Moderate…
Administrators running Joomla! CMS versions 3.0.0-5.4.5 or 6.0.0-6.1.1 should upgrade to 5.4.7 or 6.1.2 to address a Low-severity Incorrect Access Control…
A critical SP Page Builder vulnerability is being exploited against Joomla sites, allowing unauthenticated attackers to upload PHP files and create hidden…
Joomla! CMS installations running 3.0.0-5.4.5 or 6.0.0-6.1.0 are affected by a Moderate XSS issue in the Framework; upgrade to 5.4.6 or 6.1.1.
Joomla CMS sites running 3.0.0-5.4.5 or 6.0.0-6.1.0 should be upgraded to 5.4.6 or 6.1.1 to address a Moderate-severity XSS vulnerability in the Framewok…