Skip to main content

Joomla 6.1.4 & 5.4.9 Are Out: 16 Security Fixes, Update Now

Decorative image
Share this

What's been fixed on the security side

The 16 advisories fall into a few groups.

Cross-site scripting (XSS). This is the largest group. Several core output areas were patched, including the HTMLHelper::link method, the generic media layouts, HTML mail templates, the link toolbar layout, and the module list. Two issues are especially important because they involve Joomla's own InputFilter, the component that is supposed to stop XSS in the first place. Attackers could bypass it through an HTML5 entity-decoding mismatch or by placing whitespace characters inside HTML data URIs.

Access control (ACL) gaps. Several areas were not checking permissions properly. These include the web services API endpoints for access levels and various edit tasks, the content history comparison view, output for tagged items, and workflow stage changes. In short, some users could see or change things they shouldn't have been able to.

Authentication and account issues. Two fixes stand out here:

  • An MFA bypass through "remember me" cookies, which could weaken multi-factor authentication.
  • Unauthorised user account creation through the profile.save controller.

Server-side issues. The release also fixes an arbitrary directory deletion flaw in the cache purge action and closes several SSRF vectors across core extensions.

You can read the full details for each advisory in the Joomla Security Centre.

Bug fixes worth mentioning

Alongside the security work, around 35 bug fixes landed. All 5.4 fixes are also merged into 6.1. Some highlights:

  • TOTP codes are now compared with hash_equals, which is a small but useful hardening of two-factor login.
  • Banner tracking CSV exports now escape formula characters, which prevents CSV injection when the file is opened in Excel.
  • Schema.org JSON-LD now outputs absolute logo URLs and valid jobLocationType values. This matters if you rely on structured data for SEO.
  • Tags no longer create duplicate #__ucm_content rows on every article save, and alias uniqueness plus a menu URL parameter bug were fixed.
  • Multilingual sites: category associations are no longer lost when a translation is unpublished.
  • Media Manager: the image editor can now save files that have non-ASCII filenames, which is good news for Greek filenames. Duplicate selections no longer cause 404 errors on delete.
  • Template Manager: several errors were fixed, including archive extraction and access to non-source files.
  • Accessibility: the calendar field now supports keyboard navigation.
  • Smart Search indexing now works properly on PostgreSQL.

The full lists are on GitHub for 6.1.4 and 5.4.9.

How to update

For most sites, this is the usual process:

  1. Take a full backup of your files and database.
  2. Go to System → Update → Joomla in the administrator and run the update.
  3. Clear the cache and check the front end, forms, and logins.

Manual packages are available here if you need them:

A note for Joomla 5 users

Bugfix support for Joomla 5.4 ends on 13 October 2026, which is only two weeks away. Security patches will continue until 12 October 2027, so your site isn't at risk if you stay on 5.4 for now. Still, it's a good time to start planning your move to Joomla 6.

Moving from 5.4 to 6 is an upgrade, not a migration. Extensions that are free of deprecated code should work, and many others will run with the Behaviour – Backward Compatibility 6 plugin enabled. Check your extensions in the Joomla Extensions Directory, and test the upgrade on a staging copy before touching production. The official 5-to-6 upgrade guide walks you through it.

_Support