Joomla generic image layout exposed to XSS
Administrators running Joomla! CMS 4.0.0-5.4.5 or 6.0.0-6.1.1 should upgrade to 5.4.7 or 6.1.2 to address a Moderate-severity XSS vulnerability in the generic…
News, security and craft for the Joomla ecosystem
Security releases, vulnerabilities and hardening for Joomla.
Administrators running Joomla! CMS 4.0.0-5.4.5 or 6.0.0-6.1.1 should upgrade to 5.4.7 or 6.1.2 to address a Moderate-severity XSS vulnerability in the generic…
Joomla administrators running affected CMS releases should upgrade to 5.4.7 or 6.1.2, which fix a Moderate XSS vulnerability in com_installer.
JoomShaper has released Helix Ultimate 2.2.7 to fix multiple Joomla security issues, including an unauthenticated menu write that could lead to stored XSS.
JoomShaper has released Helix3 3.1.1 to address critical security vulnerabilities that could let unauthenticated attackers write and delete files on Joomla…
A mySites.guru investigation warns that Joomla sites can be reinfected by malicious cron jobs hidden outside the account-level schedules visible in hosting…
mySites.guru says OVH mistakenly identified the legitimate Joomla bfnetwork connector file bfRestore.php as malware.
mySites.guru has reported a critical iCagenda vulnerability that allowed unauthenticated attackers to upload executable files and achieve remote code execution…
A critical SP Page Builder vulnerability is being exploited against Joomla sites, allowing unauthenticated attackers to upload PHP files and create hidden…
Joomla! CMS installations running 3.0.0-5.4.5 or 6.0.0-6.1.0 are affected by a Moderate XSS issue in the Framework; upgrade to 5.4.6 or 6.1.1.
Joomla CMS sites running 3.0.0-5.4.5 or 6.0.0-6.1.0 should be upgraded to 5.4.6 or 6.1.1 to address a Moderate-severity XSS vulnerability in the Framewok…
Administrators running Joomla! CMS 3.9.0-5.4.5 or 6.0.0-6.1.0 should upgrade to 5.4.6,6.1.1 to fix a Low-severity transport encryption downgrade affecting…
Joomla installations running 4.0.0-5.4.5 or 6.0.0-6.1.0 are affected by a cache-key issue in InputFilter; administrators should upgrade to 5.4.6 or 6.1.1, as…