Live This site runs Joomla 6.1.2
JoomClub

News, security and craft for the Joomla ecosystem

Section

Security

Security releases, vulnerabilities and hardening for Joomla.

EDocman SQL injection fixed in version 3.9.0

mySites.guru has disclosed an unauthenticated SQL injection in the Joomla extension EDocman, allowing database contents to be read remotely. JoomDonation fixed…

Phoca Download fixes authenticated upload RCE

Phoca Download for Joomla contained an authenticated remote code execution flaw in versions up to 6.1.2, allowing eligible members to upload and run PHP files…

Joomla generic image layout exposed to XSS

Administrators running Joomla! CMS 4.0.0-5.4.5 or 6.0.0-6.1.1 should upgrade to 5.4.7 or 6.1.2 to address a Moderate-severity XSS vulnerability in the generic…