Live This site runs Joomla 6.1.2
JoomClub

News, security and craft for the Joomla ecosystem

News

Joomla 6.1.1 and 5.4.6 fix security issues across core

Joomla 6.1.1 and 5.4.6 are now available, bringing 20 security fixes alongside bug fixes and usability improvements for sites running the 6.x and 5.x series.

Administrators should treat these as maintenance updates, particularly because the security work covers cross-site scripting, cross-site request forgery, SQL injection, local file inclusion, path traversal, authentication bypasses and privilege escalation.

The fixes affect several areas of the core, including com_associations, com_contenthistory, com_finder, com_tags, com_config, com_media, com_users, com_scheduler and sample data plugins. The release also addresses access-control problems, cache-key construction, transport encryption downgrades and filtering issues in the Framework.

Alongside the security changes, the update improves accessibility, administration and developer-facing behaviour. Changes include fixes for calendar filters, version previews, article publishing fields, fullscreen TinyMCE, API application errors, update-archive cleanup and several template and language issues. All 5.4 bug fixes are also up-merged into 6.1.

Joomla 5.4.x remains supported with bugfix patches until 13 October 2026 and security patches until 12 October 2027. Sites moving from Joomla 5.4.x to Joomla 6.1.1 should test on a copy first and check extension compatibility; the project says this is an upgrade rather than a migration, with the Behaviour 6 - Backward Compatibility Plugin available where needed.

Published by the Joomla Project.