AcyMailing privilege escalation also affects Joomla sites
A privilege-escalation vulnerability identified as CVE-2026-3614 also affects Joomla installations of AcyMailing, despite public advisories describing the…
News, security and craft for the Joomla ecosystem
Security releases, vulnerabilities and hardening for Joomla.
A privilege-escalation vulnerability identified as CVE-2026-3614 also affects Joomla installations of AcyMailing, despite public advisories describing the…
Nextend’s Smart Slider 3 Pro 3.5.1.35 was a malicious release distributed through the official update channel, giving affected Joomla sites a remote…
Joomla! CMS installations running 3.0.0-5.4.3 or 6.0.0-6.0.3 are affected by an access-control issue in com_ajax. Administrators should upgrade to 5.4.4 or…
Joomla administrators running 4.0.0-5.4.3 or 6.0.0-6.0.3 should upgrade to 5.4.4 or 6.0.4 to fix a Moderate SQLi vulnerability in the articles webservice…
Administrators running Joomla! CMS 4.0.0-5.4.3 or 6.0.0-6.0.3 should upgrade to 5.4.4 or 6.0.4 to address a Moderate-severity XSS issue.
Joomla administrators running versions 4.0.0-5.4.3 or 6.0.0-6.0.3 should upgrade to 5.4.4 or 6.0.4 to fix a high-severity vulnerability in com_joomlaupdate.
Joomla! CMS versions 4.0.0-5.4.3 and 6.0.0-6.0.3 are affected by an Incorrect Access Control flaw in webservice endpoints. The Joomla project rates its…
A critical vulnerability in the Tassos/Novarain Framework for Joomla allows unauthenticated attackers to include, read and delete files and carry out SQL…
JoomDev's Astroid Framework for Joomla is affected by a critical authentication bypass that attackers are actively using to upload backdoors and inject SEO…
Tassos has released security updates for six Joomla extensions after a vulnerability in its Tassos Framework system plugin could, under certain conditions…
A security plugin for sites still running the unsupported Joomla 3 series has reached version 1.0.9, addressing five reported vulnerabilities including…
JL Content Fields Filter 4.0.0 is a major release of the free Joomla extension, adding full Joomla 6 compatibility while addressing five SQL injection issues…