Joomla XSS affects generic media output layouts
Administrators running Joomla! CMS 4.0.0-5.4.8 or 6.0.0-6.1.3 should upgrade to 5.4.9 or 6.1.4 to address a Moderate XSS issue in the generic media output…
News, security and craft for the Joomla ecosystem
Security releases, vulnerabilities and hardening for Joomla.
Administrators running Joomla! CMS 4.0.0-5.4.8 or 6.0.0-6.1.3 should upgrade to 5.4.9 or 6.1.4 to address a Moderate XSS issue in the generic media output…
Administrators running Joomla! CMS 1.5.0-5.4.8 or 6.0.0-6.1.3 should upgrade to 5.4.9 or 6.1.4, respectively, to address an unauthorized user-account creation…
AcyMailing 11.1.0 fixes two serious security flaws affecting earlier versions with certain features enabled, including an arbitrary file-write issue and a…
JoomShaper has released EasyStore 3.0.1 for Joomla, fixing seven security vulnerabilities that affected every version below 3.0.1, including 2.0.1 and 3.0.0.
Balbooa has released Gridbox 2.20.3.1 for Joomla to fix a high-severity, unauthenticated blind SQL injection in the extension’s public blog author filter.
OrdaSoft's OS Gallery for Joomla contains four vulnerabilities in versions through 6.2.6, including a critical SQL injection that requires no login. Version…
JoomGallery 4.0.0 through 4.4.1 contains an unauthenticated file-upload vulnerability that is fixed in version 4.4.2.
J2Commerce has fixed six security vulnerabilities in J2Store, including an unauthenticated SQL injection that could expose a shop’s database.
JoomShaper has fixed five security vulnerabilities in the Joomla SP Page Builder extension, including a High-severity SQL injection and a Medium-severity…
A critical flaw in the miniOrange OAuth Client extension for Joomla allows unauthenticated account takeover, including access to administrator accounts.
mySites.guru says it found 19 vulnerabilities in 17 Joomla extensions during June and July 2026, including five rated CVSS 10.0.
Multiple security issues in JEM, the Joomla Event Manager component, affect versions below 5.0.1, including stable 5.0.0. The most serious allows anonymous…