Live This site runs Joomla 6.1.2
JoomClub

News, security and craft for the Joomla ecosystem

Section

Security

Security releases, vulnerabilities and hardening for Joomla.

Joomla MFA bypass fixed in 5.4.9 and 6.1.4

Administrators running Joomla! CMS 4.0.0-5.4.8 or 6.0.0-6.1.3 should upgrade to 5.4.9 or 6.1.4 to fix a Moderate-severity MFA authentication bypass involving…

Joomla module list XSS fixed in CMS updates

Joomla administrators running 4.0.0-5.4.8 or 6.0.0-6.1.3 should upgrade to 5.4.9 or 6.1.4 to fix a Moderate XSS vulnerability in the Joomla! CMS module list.

Joomla SSRF flaw affects core extensions

Administrators running affected Joomla! CMS installations should upgrade to 5.4.9 or 6.1.4 to address high-severity SSRF vectors in various core extensions.

Joomla fixes XSS flaw in HTML mail templates

Administrators running Joomla! CMS 4.0.0-5.4.8 or 6.0.0-6.1.3 should upgrade to 5.4.9 or 6.1.4 to address a Moderate XSS vulnerability in HTML mail templates…