Live This site runs Joomla 6.1.2
JoomClub

News, security and craft for the Joomla ecosystem

Section

Security

Security releases, vulnerabilities and hardening for Joomla.

Joomla fixes module access-control flaw

Joomla CMS sites running 4.0.0-5.4.6 or 6.0.0-6.1.1 should be upgraded to 5.4.7 or 6.1.2 to address a Moderate-severity access-control issue.

Joomla generic image layout exposed to XSS

Administrators running Joomla! CMS 4.0.0-5.4.5 or 6.0.0-6.1.1 should upgrade to 5.4.7 or 6.1.2 to address a Moderate-severity XSS vulnerability in the generic…

Joomla fixes XSS in modalreturn layouts

Joomla administrators should upgrade to version 5.4.7 or 6.1.2 to address a Moderate XSS vulnerability in modalreturn layouts, tracked as CVE-2026-48951.

Joomla MFA XSS fixed in 5.4.7 and 6.1.2

Joomla! CMS versions 4.2.0-5.4.5 and 6.0.0-6.1.1 are affected by an XSS vulnerability in the MFA management views. The Joomla project rates it Moderate…