6. Extensions, uploads and the Web Services API
Extensions are where most risk lives
Core Joomla is reviewed by a security team; third-party extensions vary widely. Before installing one:
- Check the Vulnerable Extensions List (VEL) for the extension and the developer. The VEL itself notes it may not be complete, so it is a first check, not a clearance.
- Prefer extensions with recent releases, a public changelog and support for your Joomla major version.
- Install only from the developer or the Joomla Extensions Directory, never from "nulled" copies.
- Uninstall, don't just disable, anything you no longer use. Disabled code is still on disk and may still be reachable.
Keep Media Manager's upload filters on
Content → Media → Options controls uploads. On 6.1.4 the defaults are safe: Restrict Uploads on, Check MIME Types on, and an allow-list of image, audio, video and document extensions with no php, svg or html.
Tested through the Media Manager upload API as a logged-in Super User:
|
File uploaded |
Result |
|---|---|
|
|
Rejected: "This file type is not supported." |
|
|
Rejected: "This file type is not supported." |
|
|
Rejected: "This file type is not supported." |
|
|
Rejected: "Illegal mime type detected" |
|
|
Accepted (allowed type) |
Do not add svg, html, js or archive types to the allow-list unless you must. Joomla's shipped .htaccess sends Content-Security-Policy: script-src 'none' for .svg files, which limits but does not remove the risk of script in SVGs.
Disable or block the API if you don't use it
Joomla's Web Services API (/api/index.php/v1/...) is on by default, with 18 webservice plugins enabled on the test install. Unauthenticated requests returned 401. Still, every enabled endpoint is attack surface, as the September 2026 ACL fix for webservice edit tasks showed.
- Disable the Web Services plugins for content you never expose (System → Plugins, filter type webservices). Tested: with the Web Services - Users plugin disabled,
/api/index.php/v1/userschanged from401to404 Resource not found. - If nothing uses the API, block it at the server with rule 3 in section 4. Tested:
/api/...returned403; the site and admin were unaffected. - Leave API Authentication - Basic Auth disabled (the default). It accepts a username and password on every request.
