DJ-Classifieds flaw allowed unauthenticated file uploads
mySites.guru has reported a high-severity file-upload vulnerability in the Joomla extension DJ-Classifieds, which was being probed in the wild before the…
News, security and craft for the Joomla ecosystem
Security releases, vulnerabilities and hardening for Joomla.
mySites.guru has reported a high-severity file-upload vulnerability in the Joomla extension DJ-Classifieds, which was being probed in the wild before the…
Two Joomla extensions have received security fixes for high-severity, unauthenticated vulnerabilities: SQL injection in JoomCCK and stored cross-site scripting…
jDownloads has fixed a high-severity unauthenticated file-upload vulnerability affecting versions 4.1.0 through 4.1.5. Administrators should update to 4.1.6.
mySites.guru has disclosed an unauthenticated, error-based SQL injection in ThemeXpert’s Quix Page Builder for Joomla, tracked as CVE-2026-58078 and rated High…
JoomShaper has released Joomla 3 security updates for Helix Ultimate, Helix3 and SP Page Builder, reversing its recent decision to stop providing patches for…
Digital Peak has reported a serious vulnerability in its DPCalendar event-calendar component that can enable unauthorised access to data stored in a Joomla…
mySites.guru has reported three security flaws affecting JoomShaper extensions on Joomla 3, including a critical SP Page Builder vulnerability that has been…
mySites.guru has disclosed an unauthenticated SQL injection in the Joomla extension EDocman, allowing database contents to be read remotely. JoomDonation fixed…
Joomla has released versions 6.1.2 and 5.4.7 with security fixes for the core and web services, alongside more than 35 bug fixes and stability improvements…
Joomla! CMS installations running 4.1.0-5.4.6 or 6.0.0-6.1.1 are affected by incorrect access control in com_media webservice endpoints; administrators should…
Joomla sites running 4.0.0-5.4.6 or 6.0.0-6.1.1 are affected by an Incorrect Access Control issue in com_fields; administrators should upgrade to 5.4.7 or…
Joomla administrators running 4.0.0-5.4.6 or 6.0.0-6.1.1 should upgrade to 5.4.7 or 6.1.2, respectively, to fix CVE-2026-48957 in com_privacy webservice…