Joomla fixes moderate XSS in com_associations
Administrators running affected Joomla! CMS releases should upgrade to a fixed version to address a cross-site scripting issue in the multilingual associations…
News, security and craft for the Joomla ecosystem
Security releases, vulnerabilities and hardening for Joomla.
Administrators running affected Joomla! CMS releases should upgrade to a fixed version to address a cross-site scripting issue in the multilingual associations…
Joomla administrators running affected CMS releases should upgrade to 5.4.6 or 6.1.1 to address a moderate XSS vulnerability in feed modules.
Sorry ransomware is targeting cPanel-hosted sites through a critical authentication bypass in cPanel and WHM, encrypting files and adding the .sorry extension.
A privilege-escalation vulnerability identified as CVE-2026-3614 also affects Joomla installations of AcyMailing, despite public advisories describing the…
Nextend’s Smart Slider 3 Pro 3.5.1.35 was a malicious release distributed through the official update channel, giving affected Joomla sites a remote…
Administrators running Joomla! CMS 4.0.0-5.4.3 or 6.0.0-6.0.3 should upgrade to 5.4.4 or 6.0.4 to address a Moderate-severity XSS issue.
Joomla administrators running 4.0.0-5.4.3 or 6.0.0-6.0.3 should upgrade to 5.4.4 or 6.0.4 to fix a Moderate SQLi vulnerability in the articles webservice…
Joomla! CMS installations running 3.0.0-5.4.3 or 6.0.0-6.0.3 are affected by an access-control issue in com_ajax. Administrators should upgrade to 5.4.4 or…
Joomla administrators running versions 4.0.0-5.4.3 or 6.0.0-6.0.3 should upgrade to 5.4.4 or 6.0.4 to fix a high-severity vulnerability in com_joomlaupdate.
Joomla! CMS versions 4.0.0-5.4.3 and 6.0.0-6.0.3 are affected by an Incorrect Access Control flaw in webservice endpoints. The Joomla project rates its…
A critical vulnerability in the Tassos/Novarain Framework for Joomla allows unauthenticated attackers to include, read and delete files and carry out SQL…
JoomDev's Astroid Framework for Joomla is affected by a critical authentication bypass that attackers are actively using to upload backdoors and inject SEO…