Manage Multiple Joomla Sites
116 articles, newest first.

Regular Labs Publishes 24 Joomla Extension Updates Including 10 Security Fixes
Regular Labs shipped 24 Joomla extension updates on 13 September 2026. Ten fix security issues across nine CVEs, and four change behaviour on update.

Unauthenticated SQL Injection in SP Property Finder found by mySites.guru
mySites.guru found an unauthenticated blind SQL injection in JoomShaper's SP Property Finder. Any visitor could read the database. Fixed in 4.1.4.

Digital Peak patches four Joomla extensions after a Claude audit
Digital Peak shipped out-of-band fixes for DPCalendar, DPMedia, DPAttachments and DPCases on 10 September. DPAttachments is the one to do first.

Block AI training if you want. Never block AI answers.
Blocking GPTBot costs you nothing. Blocking OAI-SearchBot deletes you from ChatGPT. What 50,000 live robots.txt files show about telling them apart.

J2Store 3 Stops Getting Security Fixes on 19 October 2026
J2Commerce ends J2Store 3 support on 19 October 2026. Six in ten of the J2Store installs we monitor are on that line, and most are two releases behind.

T4 Page Builder 2.3.0 Fixes an Unauthenticated Mail Relay
JoomlArt's T4 Page Builder 2.3.0 closes an unauthenticated open mail relay we reported in August. A week on, five in six installs we see are still older.

J2Store 3.3.22, 4.0.22 and 4.1.7 fix five flaws we reported
J2Store 3.3.22, 4.0.22 and 4.1.7 fix five flaws mySites.guru reported, including anonymous PayPal order confirmation and a 9.5 backend escalation.

Release Radar, a Free Joomla and WordPress Release Tracker
A free public log of new Joomla and WordPress extension releases, including the paid ones no plugin directory covers. RSS and JSON, no account needed.

Joomla 3 Didn't Fail. Your Retainer Did.
We monitor 30,305 live Joomla 3 sites. They are five times more likely to be hacked than Joomla 6, and the agencies who migrated are doing worse.

Impostor Files: How to find every file in a core folder that core never shipped
Joomla 5.4.7 ships exactly one file directly in /administrator/. Impostor Files lists everything else sitting in folders the CMS itself owns.

DPCalendar 10.12.0 fixes an SQL injection and an XSS
Digital Peak fixed a blind SQL injection and a stored XSS in DPCalendar 10.12.0, backported to 8.19.5 for Joomla 3. Both need a logged-in user.

Helix Ultimate 2.2.10 Fixes Twelve Security Issues, Including a Pre-Login Bypass
Helix Ultimate 2.2.10 is a security release for the Joomla template framework. Every version below it is affected. Here is what it fixes and how to update.

Helix Ultimate's Third Joomla 3 Patch Since JoomShaper Said There Would Be None
JoomShaper said its Joomla 3 products would get no security patches regardless of severity. The Helix Ultimate template framework has now had four.

Slower on purpose: the new Update Queue, and why it is off by default
Firing every update at once is what takes a shared server down. mySites.guru's new Update Queue runs one update at a time per server, off by default.

Finding Rogue Admin Accounts Across Every Joomla Site You Manage
Attackers plant admin accounts to walk back in after you clean the files. How to find rogue admins across every Joomla site you manage, from one screen.

Three CVEs in miniOrange Extensions for Joomla, All Now Fixed
Two CVSS 10.0 authentication bypasses and a remote uninstall flaw naming 23 extensions. Every affected free edition now has a fixed version, released 31 August.

Summer 2026: Everything New in mySites.guru
Everything new in mySites.guru this summer: 38 new tools, 40 improvements, and the 19 Joomla extension vulnerabilities we found and disclosed ourselves.

The latest 90 reviews of mySites.guru - and what they said
Ninety people left mySites.guru a five-star review this summer. We counted what they mentioned, and the most common word was not security, updates or price.

Fabrik 4.7.2 for Joomla: A Long List of Security Fixes
Fabrik 4.7.2 for the Joomla extension closes a long list of unauthenticated vulnerabilities, most of them found and reported by mySites.guru. Update now.

Five Security Issues in JEM (Joomla Event Manager), and No Stable Fix Yet
mySites.guru found and reported multiple security issues in JEM (Joomla Event Manager), including an unauthenticated article overwrite. No stable fix yet.

Joomla 5.4.8 and 6.1.3 Break the Template Manager
Joomla 5.4.8 and 6.1.3 break four Template Manager actions with a Snooping out of bounds error: creating overrides and template folders. Cause and fix.

A CVSS 10.0 Unauthenticated Upload in YOOtheme ZOO, Fixed in 4.1.66
YOOtheme ZOO (com_zoo) up to 4.1.63 had an unauthenticated file upload RCE scored CVSS 10.0, plus a SQL injection, fixed in 4.1.64. Install 4.1.66.

iCagenda 4.0.12 fixes an unauthenticated SQL injection
CVE-2026-67365 is an unauthenticated SQL injection in the iCagenda Calendar module for Joomla, scored 9.2 Critical. Fixed in 4.0.12.

Sourcerer 14 and 15 did not fix CVE-2026-74253. 16.0.0 does.
Sourcerer 14 and 15 were both published as the fix for CVE-2026-74253 and neither closed it. It is exploited in the wild. Update now to 16.0.0.

Why PHP 8.5.7 Shows Amber When PHP 8.4.24 Shows Green
PHP 8.5.7 shows amber while 8.4.24 shows green because the badge checks whether you are on the newest patch in your branch, not which branch you picked.

Phoca Cart 5.2.4, 6.1.7 and 4.0.13 fix a front-end SQL injection
Phoca Cart 5.2.4, 6.1.7 and 4.0.13 patch an unauthenticated SQL injection in the Joomla extension's product filter. Joomla 5 on 6.x isn't offered it.

Unauthenticated Remote Code Execution in SP Page Builder found by mySites.guru
mySites.guru found a pre-authentication remote code execution flaw in SP Page Builder for Joomla, in the same release that fixed our earlier reports.

Cotton Cloud Patched the Login, Then the Data
Two access control flaws in Cotton Cloud for Joomla. The first fix closed the door, not the room. CVE-2026-67283 and CVE-2026-67284 are fixed in 2.0.3.

Twenty Rules for Joomla Extension Developers Handling a Security Report
A new Joomla Manual page sets out 20 rules for how extension developers should handle a security report. Republished here in full under the JEDL.

The Fabrik Fiasco: Announced, Restricted, Relabelled
Two CVSS 10.0 RCEs in the Fabrik Joomla extension, and a chaotic run of security releases since. The vendor has moved past 4.7.0; be on 4.7.2.

Joomla 6.1.2 and 5.4.7 Silently Ignore Every Article Option
Joomla 6.1.2 and 5.4.7 silently ignore every per-article Option on the front end. The root cause, how to find affected articles, and the official hotfix.

Another 23 Critical Security Vulnerabilities in Gridbox for Joomla
Balbooa asked mySites.guru to audit Gridbox for Joomla. We found 23 vulnerabilities, including a pre-auth RCE, some exploited already. Fixed in 2.20.2.

JCE 2.9.99.10 Fixes Another Security Issue
JCE 2.9.99.10 patches a file rename flaw letting a privileged user create a hidden file in the folder they were browsing. The release hardens more too.

Pre-Authentication SQL Injection and Mail Relay in SP Page Builder found by mySites.guru
mySites.guru found four vulnerabilities in SP Page Builder for Joomla: a SQL injection and a mail relay, fixed in 6.7.1. A fifth survived to 6.8.0.

Exposed Customer Invoices, Order Forgery and SQL Injection in EasyStore for Joomla found by mySites.guru
Before EasyStore 2.0.2, any logged-in customer could read every other customer's invoice by editing one URL. mySites.guru found this and two more flaws.

Regular Labs Patched Its Whole Joomla Extension Catalogue at Once
Regular Labs shipped a security-hardening update across its Joomla extension range on 22 July 2026: SSRF, command injection, stored XSS and more. No CVEs.

PageBuilder CK RCE fixed - again - correctly this time
PageBuilder CK's 3.6.0 fix for its file-upload RCE (CVE-2026-56290) added just a login check; any Editor could still run code. Fixed in 3.6.3. Be on 3.6.5.

Events Booking for Joomla exposes personal and financial data from invoices
An unauthenticated flaw in Events Booking for Joomla let anyone download any registrant's invoice, with their name, address, email and payment. Fixed in 5.8.2.

One VEL for Every Joomla and WordPress Site
The Joomla VEL (Vulnerable Extension List) only covers Joomla and never checks your sites. mySites.guru tracks both CMSes and flags yours directly.

Your .htaccess Won't Stop a Joomla Hack
A hardened .htaccess feels safe, but Joomla attacks ride straight through index.php. Here is why the file protects far less than most site owners think.

Membership Pro 4.6.2: A Quiet Fix for Anonymous File Uploads
Membership Pro 4.6.2 quietly fixes the same anonymous upload flaw we reported in Events Booking. Now CVE-2026-62415, rated critical. What to do about it.

Gridbox for Joomla: One Cookie and You Are a Super User
A critical unauthenticated authentication bypass in Gridbox for Joomla let anyone become a Super User by setting a single cookie. Fixed in 2.20.1. Update now.

Events Booking for Joomla: Anyone Could Upload Files to Your Server
mySites.guru found two unauthenticated flaws in Events Booking for Joomla: file upload enabled by default, and a leak of every user's name and email.

DJ-Classifieds Unauthenticated File Upload
DJ-Classifieds below 3.11.2 let anyone upload files to your Joomla site with no login, and it was being used in the wild. Update to 3.11.2 now.

jDownloads 4.1 Shipped an Unauthenticated Upload Endpoint, Now Fixed in 4.1.6
jDownloads 4.1.0 to 4.1.5 shipped a leftover test script that let anyone upload files to your Joomla site with no login. Update to 4.1.6, which removes it.

We Are Not the Only Ones Auditing Joomla Extensions
Two Joomla extension flaws went public via the Joomla CNA: a SQL injection in JoomCCK and a stored XSS in ChronoForms. Neither was ours. Update now.

Unauthenticated SQL Injection in Quix Page Builder found by mySites.guru
mySites.guru found and reported CVE-2026-58078, an unauthenticated SQL injection in Quix Page Builder for Joomla. Fixed in 6.2.1; update to 6.2.2.

JoomShaper Patched the Joomla 3 It Said It Never Would
Six days after ruling out Joomla 3 security patches, JoomShaper shipped them for Helix Ultimate, Helix3 and SP Page Builder. What is in them.

Unauthenticated SQL Injection in EDocman found by mySites.guru
mySites.guru found an unauthenticated SQL injection in EDocman for Joomla that let anyone read the whole database. Fixed in 3.9.0 - update now.

The One-Click Way to Patch JoomShaper Extensions on Joomla 3
mySites.guru backports JoomShaper's security fixes into SP Page Builder, Helix3 and Helix Ultimate on Joomla 3, across every site in your account.

Nineteen and Counting: Joomla Extension Vulnerabilities We Found and Disclosed in a Month
In just over a month mySites.guru found and responsibly disclosed nineteen security issues in popular Joomla extensions, most of them critical.

Unauthenticated SQL Injection in DPCalendar found by mySites.guru
mySites.guru found and reported an unauthenticated SQL injection in the DPCalendar Joomla extension's public events feed. Fixed in 10.11.2 and 8.19.4.

Joomla Update Error 999: a Dead Extension Redirecting to LinkedIn
The Joomla 'Invalid status code 999' update error is not a bug. It is an abandoned extension whose update site redirects to LinkedIn. Here is the fix.

What Are the .myjoomla.configuration.php.md5 Files?
Found .myjoomla.configuration.php.md5 files in your Joomla webspace? They are not malware. They are mySites.guru file-integrity lock files. Here's what they do.

Phoca Download 6.1.3 Fixes an Authenticated Upload RCE
Phoca Download for Joomla (com_phocadownload) up to 6.1.2 let a logged-in member upload a PHP file and run code on the server. Fixed in 6.1.3, update now.

RSFiles! Fixes an Unauthenticated File Upload RCE
RSFiles! for Joomla (com_rsfiles) up to 1.17.11 had an unauthenticated file upload flaw letting anyone drop a PHP file and run code. Update now.

Unauthenticated SQL Injection in AcyMailing found by mySites.guru
mySites.guru found and reported CVE-2026-56292, an unauthenticated SQL injection in AcyMailing for Joomla and WordPress. Update to 10.11.1 now.

JoomShaper Ends Joomla 3 Security Fixes
JoomShaper ended Joomla 3 support with no security fixes regardless of severity, then reversed the security half six days later and shipped patches.

Balbooa Forms Fixes an Unauthenticated File Upload RCE
Balbooa Forms (com_baforms) had an unauthenticated file upload RCE, CVE-2026-56291, fixed in 2.4.1. Three more security releases followed: update to 2.4.3.2.

The Helix3 Defacement Lives in Your Database, Not Your Files
The Hacked by AntonKill defacement hits Joomla sites via Helix3, hiding in the database where file scanners never look. Clean it in one click.

Helix Ultimate 2.2.7 Closes an Unauthenticated Menu Write
Helix Ultimate 2.2.7 fixes CSRF and permission gaps in com_ajax: an unauthenticated menu write leading to stored XSS, a file delete, and an open redirect.

Helix3 Shipped a Critical Fix as "Security Update"
Helix3 3.1.1 patches an unauthenticated file write and file delete in the Helix3 ajax plugin. JoomShaper announced it but told nobody what it fixes.

PageBuilder CK File Upload RCE - June 2026
PageBuilder CK below 3.6.0 lets anyone upload and run a file on your Joomla site, no login. CVE-2026-56290, CVSS 10.0, exploited in the wild. Update to 3.6.0.

Reinfected? Check Every Crontab, Not Just Yours
Your cPanel cron jobs look clean but the site reinfects anyway. The cron rebuilding the malware is hiding in a crontab your account can't see. Here is where.

Hacked Yesterday, Exploited Today: Why One Cleanup Is Never the End
The first hack plants a dormant dropper. The real damage comes in the second wave, days or weeks later. Here is why monitoring beats one-shot cleanup.

OVH Flagged Our Plugin as Malware. It Is Not, and Here Is the Proof.
OVH's scanner flagged our legitimate bfRestore.php file as malware and cut outgoing connections and email across whole hosting plans. Here is why it is safe.

Zero Day Vulnerability Found in iCagenda Joomla Extension
mySites.guru found and confirmed an unauthenticated upload giving remote code execution on Joomla 6 sites running iCagenda. Fixed same-day in 4.0.8.
SP Page Builder Zero Day Is Being Used to Plant Fake Joomla Admins
An unauthenticated upload in the SP Page Builder Joomla extension gives remote code execution and creates hidden Super User accounts. Fixed in 6.6.2.

Joomla Update Not Possible Because the Offered Update Has Expired
Joomla shows "Update not possible because the offered update has expired"? It is usually not your site. Here is the real cause, and how to fix it.

A New mySites.guru Tool to Find, and Fix, the JCE Profiles Hack (June 2026)
mySites.guru now has a dedicated check that finds rogue JCE editor profiles and webshells across your Joomla sites, then lets you clean and patch them.

JCE Pro 2.9.99.6 Is a Hardening Release After a Full Audit of Joomla's Most-Installed Editor
JCE Pro 2.9.99.6 follows a four-day security audit of the editor, narrowing entry points and hardening input validation. Recommended for every JCE site.

JCE Free/Pro 2.9.99.5 Patches an Unauthenticated File Upload in Joomla's Most-Installed Editor
JCE Free and JCE Pro 2.9.99.5 patch an unauthenticated editor profile upload that could upload arbitrary files. Update every Joomla site running JCE.

JCE Free/Pro 2.9.99.4 Patches Two Authenticated Vulnerabilities in Joomla's Most Popular Editor
JCE Free and JCE Pro 2.9.99.4 patch an Editor Profile authentication bypass and a directory traversal in filesystem search. Update JCE today.

Joomla 5.4.6 and 6.1.1 Patch TEN Security Issues
Joomla 5.4.6 and 6.1.1 close ten security issues including an MFA bypass and a com_users privilege escalation. The patch order for 30+ sites.

How to Enable Joomla Extension Auto-Updates Safely
How to enable auto-updates for Joomla extensions across one site or hundreds, with backup and rollback steps that keep client sites safe if an update breaks.

AcyMailing Vulnerability Also Affects Joomla Sites
CVE-2026-3614 is listed as a WordPress bug. We diffed the 10.8.1 and 10.8.2 source and the same vulnerable code ships to Joomla sites too.

How to Enable POW Captcha in Joomla 6.1
Joomla 6.1 ships a built-in proof-of-work captcha replacing Google reCAPTCHA. How to enable it on one site or a whole portfolio with mySites.guru.

How to Turn On Module Versioning in Joomla 6.1
Joomla 6.1 finally brings version history to modules. How to enable save_history manually, and how mySites.guru flips it on across every site.

Joomla 6.1.0 Released - What's New
Joomla 6.1 ships a visual workflow editor, built-in POW captcha, media custom fields for audio and video, and a new Cassiopeia child template.

AJAX Endpoints Are A Big CMS Security Blind Spot
Five AJAX and API vulnerabilities hit Joomla and WordPress in March 2026, all sharing one root cause. Here is what went wrong and how to protect your sites.

Joomla's Compat Plugin Is a Crutch, Not a Fix
Joomla's backward compatibility plugins keep broken extensions alive. Why that's technical debt, how to test without them, and how to recover.

Novarain Framework Vulnerability: Check Your Joomla Sites for nrframework
CVE-2026-21627 (CVSS 9.5) - Tassos/Novarain Framework for Joomla allows unauthenticated file inclusion, deletion, and SQL injection.

Detect Locked Joomla Scheduled Tasks Before They Cause Problems
Joomla's Task Scheduler can leave tasks stuck in a locked state after crashes or timeouts. mySites.guru detects and unlocks them across all your sites.

How to Check Your Joomla Database Security with mySites.guru
Your Joomla database might be running with the default jos_ prefix, a root user, or excessive privileges. Here's how to flag each issue and fix it.

Joomla TinyMCE Editor Broken in Firefox 148 - How to Fix It
Firefox 148 broke the TinyMCE editor in Joomla 4, 5, and 6. The editor flickers and reloads endlessly. Joomla 5.4.4 and 6.0.4 fix it permanently.

How to Clean Up Dangerous Files Left on Your Joomla Web Server
ZIP archives, SQL dumps, and PHP error logs left on your Joomla server are security risks waiting to be exploited. Find and remove them before an attacker does.

How to Check if Your Joomla Site's robots.txt is Hurting Your SEO
Joomla's default robots.txt blocks media and template folders from search engines, killing your image SEO. Here's how to fix it.

How to Verify Your Joomla Site's Email Configuration Actually Works
Joomla and WordPress contact forms can silently fail. Check SMTP settings, test mail delivery, and catch email misconfigurations across all your sites.

How to Compare Joomla Templates Across All Your Sites
See which template every Joomla site uses, spot legacy or default templates, and export the full list as CSV from one dashboard.

How to Disable Automated Joomla Core Upgrades in Joomla 5.4+ and 6.0
Joomla 5.4 and 6.0 auto-update your site without asking. How to disable Joomla automatic updates, why agencies should, and the TUF security model behind them.

Build a Morning Routine for Checking All Your Joomla Sites in 5 Minutes
A practical morning workflow for agency owners to check uptime, backups, updates, and alerts across hundreds of Joomla sites in under 5 minutes.

How to Prevent Accidental Joomla Version Jumps with Update Channel Management
One wrong Joomla update channel setting can jump your site from Joomla 4 to 5 or 5 to 6. Here is how mySites.guru detects and prevents this.

How to Find and Disable the Guided Tours Plugin on Your Joomla Sites
Joomla Guided Tours wastes resources on live sites. Why you should disable it in production and how mySites.guru handles it automatically.

Astroid Framework Vulnerability - What Happened and How to Check Your Joomla Site
CVE-2026-21628 (CVSS 10.0) - Astroid Framework for Joomla had a critical auth bypass letting attackers upload backdoors. What happened and what to do.

Joomla 6 Technical Requirements (2026)
Joomla 6 requires PHP 8.3+, MySQL 8.0.13+, or MariaDB 10.4+. Check if your server is ready in 30 seconds with our free bulk compatibility scanner.

What Users Really Think of mySites.guru
What agencies and site owners actually say about managing their Joomla and WordPress sites with mySites.guru. Named reviewers only, no anonymous testimonials.

Automatic Updates for Any Joomla Extension
Enable automatic updates for any Joomla extension that uses a Joomla update site - set per-site or across all connected sites with two clicks.

Backup 1000s of Sites from One Dashboard
Schedule and manage Akeeba Backup across thousands of Joomla and WordPress sites from a single mySites.guru dashboard.

End-of-Life Version Support in mySites.guru
mySites.guru monitors end-of-life Joomla and WordPress versions from 1.5 to 6, alerting you when sites run unsupported software that puts them at risk.

Get Expert Help for Your Sites Instantly
mySites.guru subscribers get direct access to Phil Taylor for fast expert help with any Joomla or WordPress problem - set fees, no ticket queues.

Remove Fluff Files After Joomla Updates
mySites.guru can automatically delete leftover installation folders, readme files and other fluff left behind after Joomla core updates.

Disable "Send Copy to Submitter" in Joomla
Use mySites.guru to bulk-disable the Joomla Send Copy to Submitter contact form setting across all your sites to stop it being abused for spam.

Fix Joomla 3 Security Issues in One Click
Patch every known Joomla 3 security vulnerability across all your sites with a single toggle in mySites.guru - no manual file edits, no eLTS subscription.

Install Extensions to Multiple Joomla Sites
Push a Joomla extension install to hundreds of sites simultaneously from the mySites.guru dashboard, with full success and failure notifications per site.

Manage and Monitor Any PHP App with mySites.guru
The mySites app works with any PHP-based web application, not just WordPress and Joomla. Connect any PHP site to get security audits, snapshots, and alerts.

Upgrade 100s of Sites from One Dashboard
Run core and extension updates across hundreds of Joomla and WordPress sites from the mySites.guru dashboard.

Auto-Upgrade 1000s of Plugins & Extensions
Update Joomla extensions, WordPress plugins, and CMS cores across all your sites from one mySites.guru dashboard. Select all, click upgrade, done.

Track SSL Certificate Expirations Easily
mySites.guru checks every site's SSL certificate issuer, expiry date and full chain validity on every snapshot, alerting you before they expire.

Best Practice for Joomla & WordPress Sites
Every mySites.guru snapshot and audit check comes with a detailed Learn More page explaining the best practice recommendation, the risk and how to fix it.

Manage Your Joomla 4 Sites with mySites.guru
mySites.guru fully supports Joomla 4 with the same audit, backup, update, and monitoring toolset available for every Joomla version since 1.5.

Migrating to Modern Joomla When Using mySites.guru
How to keep your sites connected to mySites.guru when migrating from Joomla 3 to Joomla 4, 5, or 6. Step-by-step connector swap process.

One-Click Admin Login to Any Site
Skip the login page entirely. One click from mySites.guru logs you straight into any Joomla or WordPress admin console - no passwords stored, fully encrypted.

The mySites.guru Command Palette Navigation
Press Cmd+K anywhere in mySites.guru to open the command palette and instantly navigate to any site, tool or account setting without touching the mouse.

Deep Security Audit for WordPress & Joomla
Surface-level scanners miss hidden malware. File-level audits check every line of code against 1,500+ patterns to find backdoors other tools miss.

The Best Multi-Site Management Dashboard
Manage unlimited WordPress, Joomla and PHP sites from one secure dashboard. Security audits, backups, uptime monitoring and more for GBP 19.99/month.

Emails from AuditMailerTest@myjoomla.io
Explains why you may receive test emails from AuditMailerTest@myjoomla.io and what they mean for your mySites.guru audit notifications.