Critical SQL injection fixed in JoomlaBoat YouTube Gallery
JoomlaBoat’s YouTube Gallery extension for Joomla contains a critical unauthenticated SQL injection, affecting versions through 5.7.2 and fixed in 5.7.3.
News, security and craft for the Joomla ecosystem
Security releases, vulnerabilities and hardening for Joomla.
JoomlaBoat’s YouTube Gallery extension for Joomla contains a critical unauthenticated SQL injection, affecting versions through 5.7.2 and fixed in 5.7.3.
Joomla administrators running 1.5.0-5.4.8 or 6.0.0-6.1.3 should upgrade to 5.4.9 or 6.1.4 to fix a Moderate XSS issue in InputFilter.
Administrators running Joomla! CMS 4.0.0-5.4.8 or 6.0.0-6.1.3 should upgrade to 5.4.9 or 6.1.4 to fix a Moderate-severity MFA authentication bypass involving…
Administrators running Joomla! CMS 4.0.0-5.4.8 or 6.0.0-6.1.3 should upgrade to 5.4.9 or 6.1.4 to fix CVE-2026-92226.
Joomla administrators running 4.0.0-5.4.8 or 6.0.0-6.1.3 should upgrade to 5.4.9 or 6.1.4 to fix a Moderate XSS vulnerability in the Joomla! CMS module list.
Administrators running Joomla! CMS 5.0.0-5.4.8 or 6.0.0-6.1.3 should upgrade to 5.4.9 or 6.1.4 to fix an incorrect access control vulnerability affecting…
Administrators running affected Joomla! CMS installations should upgrade to 5.4.9 or 6.1.4 to address high-severity SSRF vectors in various core extensions.
Administrators running Joomla! CMS 4.0.0-5.4.8 or 6.0.0-6.1.3 should upgrade to 5.4.9 or 6.1.4 to address a Moderate XSS vulnerability in HTML mail templates…
Administrators using Joomla! CMS 4.0.0-5.4.8 or 6.0.0-6.1.3 are affected by an XSS issue in the link toolbar layout; upgrade to 5.4.9 or 6.1.4.
Administrators running Joomla! CMS 4.0.0-5.4.8 or 6.0.0-6.1.3 should upgrade to 5.4.9 or 6.1.4. The issue is an Incorrect Access Control vulnerability with CVE…
Administrators running affected Joomla CMS releases should upgrade to the available maintenance versions to prevent unauthorized viewing of restricted content.
Administrators running Joomla! CMS 4.0.0-5.4.8 or 6.0.0-6.1.3 should upgrade to 5.4.9 or 6.1.4, respectively. The High-severity issue, tracked as…