JoomShaper releases security patches for Joomla 3 extensions
JoomShaper has released Joomla 3 security updates for Helix Ultimate, Helix3 and SP Page Builder, reversing its recent decision to stop providing patches for…
News, security and craft for the Joomla ecosystem
Security releases, vulnerabilities and hardening for Joomla.
JoomShaper has released Joomla 3 security updates for Helix Ultimate, Helix3 and SP Page Builder, reversing its recent decision to stop providing patches for…
Digital Peak has reported a serious vulnerability in its DPCalendar event-calendar component that can enable unauthorised access to data stored in a Joomla…
mySites.guru has disclosed an unauthenticated SQL injection in the Joomla extension EDocman, allowing database contents to be read remotely. JoomDonation fixed…
Digital Peak has fixed a high-severity, unauthenticated SQL injection in its DPCalendar extension for Joomla, which could expose the site database to anonymous…
RSJoomla has fixed a critical security flaw in RSFiles! for Joomla that could let unauthenticated visitors upload and execute PHP code on affected websites.
Phoca Download for Joomla contained an authenticated remote code execution flaw in versions up to 6.1.2, allowing eligible members to upload and run PHP files…
AcyMailing versions 6.0.0 through 10.11.0 contain an unauthenticated SQL injection affecting Joomla and WordPress installations. Administrators should update…
Joomla administrators using com_baforms should update to version 2.4.3 or later after two unauthenticated remote code execution flaws were disclosed in Balbooa…
Joomla has released versions 6.1.2 and 5.4.7 with security fixes for the core and web services, alongside more than 35 bug fixes and stability improvements…
Joomla! CMS sites running versions 3.0.0-5.4.5 or 6.0.0-6.1.1 are affected by a Moderate XSS vulnerability in language overrides; administrators should upgrade…
Administrators running Joomla! CMS 4.0.0-5.4.5 or 6.0.0-6.1.1 should upgrade to 5.4.7 or 6.1.2 to address a Moderate-severity XSS vulnerability in the generic…
Joomla administrators running affected CMS releases should upgrade to 5.4.7 or 6.1.2, which fix a Moderate XSS vulnerability in com_installer.