Live This site runs Joomla 6.1.2
JoomClub

News, security and craft for the Joomla ecosystem

News

Joomla 6.0.4 and 5.4.4 address six security issues

Joomla 6.0.4 and 5.4.4 are now available with six security fixes, alongside bug fixes affecting administration, web services, media, workflows and scheduled tasks.

The Joomla project released 6.0.4 for the Joomla 6.x series and 5.4.4 for Joomla 5.x. Site administrators should treat both as maintenance updates, particularly because the releases address access control, injection, cross-site scripting and file deletion issues.

  • ACL hardening in com_ajax
  • SQL injection in the com_content articles webservice endpoint
  • An XSS vector in the com_associations comparison view
  • XSS vectors in article title outputs
  • Arbitrary file deletion in com_joomlaupdate
  • An improper access check in webservice endpoints

The maintenance work also resolves administrator sidebar icon flashing, PHP warnings in the Page Break modal, scheduled tasks stopping after a stuck task, media editing controls, workflow permission warnings and several calendar, editor, asset and article display problems. Developers should also note fixes to email validation and extension-related update handling.

Joomla 5.4.x sites can move to Joomla 6.x through an upgrade rather than a migration, but the project advises testing on a copy of the production site first. Extension compatibility still needs checking; the Behaviour 6 - Backward Compatibility Plugin may be required for some extensions. Joomla 5.4.x receives bugfix patches until 13 October 2026 and security patches until 12 October 2027.

Published by the Joomla Project.