Helix3 3.1.1 fixes critical Joomla security flaws
JoomShaper has released Helix3 3.1.1 to address critical security vulnerabilities that could let unauthenticated attackers write and delete files on Joomla…
News, security and craft for the Joomla ecosystem
Security releases, vulnerabilities and hardening for Joomla.
JoomShaper has released Helix3 3.1.1 to address critical security vulnerabilities that could let unauthenticated attackers write and delete files on Joomla…
A mySites.guru investigation warns that Joomla sites can be reinfected by malicious cron jobs hidden outside the account-level schedules visible in hosting…
mySites.guru says OVH mistakenly identified the legitimate Joomla bfnetwork connector file bfRestore.php as malware.
A critical SP Page Builder vulnerability is being exploited against Joomla sites, allowing unauthenticated attackers to upload PHP files and create hidden…
mySites.guru has reported a critical iCagenda vulnerability that allowed unauthenticated attackers to upload executable files and achieve remote code execution…
Joomla! CMS installations running 3.0.0-5.4.5 or 6.0.0-6.1.0 are affected by a Moderate XSS issue in the Framework; upgrade to 5.4.6 or 6.1.1.
Joomla CMS sites running 3.0.0-5.4.5 or 6.0.0-6.1.0 should be upgraded to 5.4.6 or 6.1.1 to address a Moderate-severity XSS vulnerability in the Framewok…
Administrators running Joomla! CMS 3.9.0-5.4.5 or 6.0.0-6.1.0 should upgrade to 5.4.6,6.1.1 to fix a Low-severity transport encryption downgrade affecting…
Joomla installations running 4.0.0-5.4.5 or 6.0.0-6.1.0 are affected by a cache-key issue in InputFilter; administrators should upgrade to 5.4.6 or 6.1.1, as…
Administrators running affected Joomla versions should upgrade to 5.4.6 or 6.1.1 to address an incorrect access control issue in com_scheduler.
The Joomla project says Joomla! CMS installations running 4.0.0-5.4.5 or 6.0.0-6.1.0 are affected by an access-control flaw in sample data plugins…
Joomla! CMS installations running 4.0.0-5.4.5 or 6.0.0-6.1.0 are affected by a privilege escalation flaw in com_users webservice endpoints. Administrators…