Latest Product Updates and Feature Enhancements on Joomla! CMS

 

CVE-2026-48907: Joomla JCE Zero-Day Hits CVSS 10.0 [2026]

Joomla's JCE plugin has a critical zero-day vulnerability, CVE-2026-48907, with a CVSS score of 10.0. This flaw allows unauthenticated users to execute remote code, affecting approximately 2.5 millio...n Joomla sites. A patch, version 2.9.99.6, was released to mitigate the issue. The vulnerability highlights the importance of prompt updates and security audits for CMS platforms.

Read on →
 

Joomla 6.1.2 & 5.4.7 Security & Bugfix Release

Joomla has released versions 6.1.2 and 5.4.7, focusing on security and bug fixes. These updates address multiple security vulnerabilities, including incorrect access controls and XSS issues, and prov...ide various bug fixes to enhance the platform's stability and security. The releases maintain Joomla's commitment to accessible and secure web design.

Read on →
 

Max severity Joomla Content Editor extension flaw targeted in automated attacks

A critical vulnerability in Widget Factory's Joomla Content Editor (JCE) extension for Joomla CMS is being exploited, allowing remote code execution. The flaw, CVE-2026-48907, is targeted in automate...d attacks. Widget Factory urges users to update to version 2.9.99.6 for enhanced security. The update addresses input validation and entry point hardening.

Read on →
 

U.S. CISA adds Widget Factory Joomla Content Editor (JCE) flaw to its ...

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a critical vulnerability in the Widget Factory Joomla Content Editor (JCE) to its Known Exploited Vulnerabilities catalog. This ...flaw, with a CVSS score of 10.0, allows unauthorized PHP code execution. It affects JCE versions up to 2.9.99.4 and was fixed in version 2.9.99.5.

Read on →
 

Joomla, LiteSpeed Vulnerabilities Exploited in Attacks

Joomla has addressed a critical vulnerability in its Content Editor (JCE), tracked as CVE-2026-48907, which allowed unauthorized file uploads leading to PHP code execution. The flaw, exploited in the... wild, was fixed in version 2.9.99.6. Joomla urges users to update immediately to mitigate risks. The US CISA has added this vulnerability to its Known Exploited Vulnerabilities catalog.

Read on →
 

Joomla 6.1.1 & 5.4.6 Security & Bugfix Release

Joomla released versions 6.1.1 and 5.4.6, focusing on security and bug fixes. Key security updates address XSS vulnerabilities, CSRF issues, and SQL injection risks. Bug fixes enhance accessibility, ...error handling, and user interface elements. These updates reinforce Joomla's commitment to secure, inclusive web design.

Read on →
 

Joomla 6.1.1 & 5.4.6 Security & Bugfix Release

Joomla has released versions 6.1.1 and 5.4.6, focusing on security and bug fixes. These updates address vulnerabilities such as XSS, CSRF, SQL injection, and privilege escalation. The releases enhanc...e Joomla's open-source web platform, emphasizing security, accessibility, and simplicity.

Read on →
 

joomla_registration_privesc.rb

A Metasploit module exploits a vulnerability in Joomla versions 3.4.4 to 3.6.3, allowing the creation of an arbitrary account with administrative privileges. The module, created by Fabio Pires, Filip...e Reis, and Vitor Oliveira, targets Joomla's account creation and privilege escalation flaws, identified by CVE-2016-8869 and CVE-2016-8870.

Read on →
 

Joomla 5.4.5 Bugfix Release

Joomla has released version 5.4.5, a bugfix update for its 5.x series. This release addresses issues such as recursion prevention in plugins, timezone conversion fixes, and improvements in media mana...ger functionalities. The update highlights Joomla's commitment to accessible web design and security. The full list of changes is available on GitHub.

Read on →
 

Joomla 6.1 Release Candidate 3

Joomla has announced the availability of Joomla 6.1 Release Candidate 3, aimed at allowing developers to test extensions and users to explore new features before the final release on April 14, 2026. ...This version is not for production use and focuses on testing and identifying issues. Key updates include dispatcher support for the jooa11y plugin.

Read on →
 

Joomla 6.1 Release Candidate 2

Joomla has released the 6.1 Release Candidate 2, designed for testing purposes. This version allows developers to test extensions and report issues before the final release on April 14, 2026. It intr...oduces new features and invites users to explore them. The release is not suitable for production sites and focuses on testing and bug reporting.

Read on →
 

Joomla 6.0.4 & 5.4.4 Security & Bugfix Release

Joomla has released versions 6.0.4 and 5.4.4, focusing on security and bug fixes. Key improvements include ACL hardening, SQL injection prevention, and XSS vector fixes. The updates enhance Joomla's ...core functionality, maintaining its reputation for security and simplicity. Users can upgrade via the official site, with support for Joomla 5.4.x continuing until 2027.

Read on →
 

Joomla 6.1 Release Candidate

Joomla has announced the release of Joomla 6.1 Release Candidate, available for testing. This version aims to allow developers to test their extensions and users to explore new features. The final st...able release is expected on April 14, 2026. The release is not suitable for production sites and focuses on testing and bug reporting.

Read on →
 

Joomla 6.0.3 & 5.4.3 Bugfix Release

Joomla has released versions 6.0.3 and 5.4.3, focusing on bug fixes and security improvements. These updates enhance Joomla's accessibility, security, and simplicity. Key fixes include resolving PHP ...8.5 deprecation warnings and security vulnerabilities. Users can download these updates from Joomla's official site. A hotfix is available for a Firefox-related issue with the TinyMCE editor.

Read on →
 

Joomla 6.0.2 & 5.4.2 Security & Bugfix Release

Joomla has released versions 6.0.2 and 5.4.2, focusing on security and bug fixes. These updates include support for PHP 8.5 and address vulnerabilities like inadequate content filtering and XSS vecto...rs. The releases enhance Joomla's open-source web platform, emphasizing security and usability. Detailed changes and upgrade instructions are available on GitHub.

Read on →
 

Joomla 5.3.3 Bugfix Release

Joomla has released version 5.3.3, a bugfix update for its 5.x series. This release addresses issues like invalid breadcrumb JSON-LD and strict routing for frontend forms. Joomla 5.3.3 maintains the ...platform's focus on accessibility, inclusiveness, and security. Users can upgrade from Joomla 4.4.x without migration, and support for Joomla 4.4 continues until October 2025.

Read on →
Show More