Joomla fixes high-severity com_users privilege escalation
Joomla installations running 4.0.0-5.4.5 or 6.0.0-6.1.0 are affected by a High-severity privilege escalation issue in com_users; administrators should upgrade…
News, security and craft for the Joomla ecosystem
Security releases, vulnerabilities and hardening for Joomla.
Joomla installations running 4.0.0-5.4.5 or 6.0.0-6.1.0 are affected by a High-severity privilege escalation issue in com_users; administrators should upgrade…
Administrators running Joomla! CMS 4.0.0-5.4.5 or 6.0.0-6.1.0 should upgrade to 5.4.6 or 6.1.1, respectively, to fix an MFA authentication bypass.
Administrators running Joomla! CMS 4.0.0-5.4.5 or 6.0.0-6.1.0 should upgrade to 5.4.6 or 6.1.1 to address a Moderate-severity MFA authentication bypass.
Joomla! CMS installations running 4.0.0-5.4.5 or 6.0.0-6.1.0 should be upgraded to 5.4.6 or 6.1.1 to address a Moderate path traversal vulnerability.
Administrators running Joomla! CMS versions 3.2.1-5.4.5,6.0.0-6.1.0 should upgrade to 5.4.6,6.1.1 to address a High-severity Local File Inclusion vulnerability…
Joomla CMS administrators running affected 4.x or 6.x versions should upgrade to the corresponding fixed release for an improper access check in com_config…
Joomla administrators using versions 4.0.0-5.4.5 or 6.0.0-6.1.0 should upgrade to 5.4.6 or 6.1.1 to address an authenticated blind SQLi in com_tags, tracked as…
Administrators running Joomla! CMS 6.0.0-6.1.0 should upgrade to 6.1.1 to address a Moderate CSRF vulnerability in the user activation endpoint.
Joomla CMS installations running 4.0.0-5.4.5 or 6.0.0-6.1.0 are affected by a Moderate XSS issue in the content history component; administrators should…
Administrators running affected Joomla! CMS releases should upgrade to a fixed version to address a cross-site scripting issue in the multilingual associations…
Joomla administrators running affected CMS releases should upgrade to 5.4.6 or 6.1.1 to address a moderate XSS vulnerability in feed modules.
Sorry ransomware is targeting cPanel-hosted sites through a critical authentication bypass in cPanel and WHM, encrypting files and adding the .sorry extension.