Joomla 3
26 articles tagged Joomla 3, newest first.

1,000+ Days After Joomla 3's End of Life, Everything You Need Is on One Site
joomla3security.com puts the Joomla 3 end-of-life dates, 46 vendors' positions, 39 unpatched core advisories and your options to stay or migrate in one place.

14 More Joomla 3 Security Fixes, Each Tested on a Real 3.10.12 Site
Joomla 5.4.9 fixed 16 core issues. We backported every one reaching Joomla 3 to the mySites.guru one-click patch tool, each proved on a real 3.10.12 site.

SP Page Builder's Joomla 3 Security Patch Was Incomplete. Version 1.0.3 Fixes It.
JoomShaper's first Joomla 3 security patch for SP Page Builder left the captcha bypass live and the XSS fix incomplete. Version 1.0.3 closes both.

Joomla 5.4.9 and 6.1.4 Fix 16 Security Issues, Two Rated High
Joomla 5.4.9 and 6.1.4 fix 16 core security issues, including cache directory deletion, SSRF, an MFA bypass and account creation with registration switched off.

Six more J2Store flaws fixed in 3.3.23, 4.0.23 and 4.1.8
J2Store 3.3.23, 4.0.23 and 4.1.8 fix six flaws mySites.guru reported, including an anonymous blind SQL injection that reads a Joomla shop's whole database.

SQL Injection and a Captcha Bypass in the SP Page Builder Joomla Extension, found by mySites.guru
mySites.guru found an Author-level SQL injection and an unauthenticated captcha bypass in the SP Page Builder Joomla extension, both fixed in 6.9.1.

Regular Labs Publishes 24 Joomla Extension Updates Including 10 Security Fixes
Regular Labs shipped 24 Joomla extension updates on 13 September 2026. Ten fix security issues across nine CVEs, and four change behaviour on update.

Digital Peak patches four Joomla extensions after a Claude audit
Digital Peak shipped out-of-band fixes for DPCalendar, DPMedia, DPAttachments and DPCases on 10 September. DPAttachments is the one to do first.

J2Store 3 Stops Getting Security Fixes on 19 October 2026
J2Commerce ends J2Store 3 support on 19 October 2026. Six in ten of the J2Store installs we monitor are on that line, and most are three releases behind.

J2Store 3.3.22, 4.0.22 and 4.1.7 fix five flaws we reported
J2Store 3.3.22, 4.0.22 and 4.1.7 fix five flaws mySites.guru reported, including anonymous PayPal order confirmation and a 9.5 backend escalation.

Joomla 3 Didn't Fail. Your Retainer Did.
We monitor 30,305 live Joomla 3 sites. They are five times more likely to be hacked than Joomla 6, and the agencies who migrated are doing worse.

DPCalendar 10.12.0 fixes an SQL injection and an XSS
Digital Peak fixed a blind SQL injection and a stored XSS in DPCalendar 10.12.0, backported to 8.19.5 for Joomla 3. Both need a logged-in user.

Helix Ultimate 2.2.10 Fixes Twelve Security Issues, Including a Pre-Login Bypass
Helix Ultimate 2.2.10 is a security release for the Joomla template framework. Every version below it is affected. Here is what it fixes and how to update.

Helix Ultimate's Third Joomla 3 Patch Since JoomShaper Said There Would Be None
JoomShaper said its Joomla 3 products would get no security patches regardless of severity. The Helix Ultimate template framework has now had four.

A CVSS 10.0 Unauthenticated Upload in YOOtheme ZOO, Fixed in 4.1.66
YOOtheme ZOO (com_zoo) up to 4.1.63 had an unauthenticated file upload RCE scored CVSS 10.0, plus a SQL injection, fixed in 4.1.64. Install 4.1.66.

Phoca Cart 5.2.4, 6.1.7 and 4.0.13 fix a front-end SQL injection
Phoca Cart 5.2.4, 6.1.7 and 4.0.13 patch an unauthenticated SQL injection in the Joomla extension's product filter. Joomla 5 on 6.x isn't offered it.

The Fabrik Fiasco: Announced, Restricted, Relabelled
Two CVSS 10.0 RCEs in the Fabrik Joomla extension, and a chaotic run of security releases since. The vendor has moved past 4.7.0; be on 4.7.2.

Events Booking for Joomla: Anyone Could Upload Files to Your Server
mySites.guru found two unauthenticated flaws in Events Booking for Joomla: file upload enabled by default, and a leak of every user's name and email.

JoomShaper Patched the Joomla 3 It Said It Never Would
Six days after excluding Joomla 3 security patches, JoomShaper shipped them for Helix Ultimate, Helix3 and SP Page Builder. What is in them.

The One-Click Way to Patch JoomShaper Extensions on Joomla 3
mySites.guru backports JoomShaper's security fixes into SP Page Builder, Helix3 and Helix Ultimate on Joomla 3, across every site in your account.

Unauthenticated SQL Injection in DPCalendar found by mySites.guru
mySites.guru found and reported an unauthenticated SQL injection in the DPCalendar Joomla extension's public events feed. Fixed in 10.11.2 and 8.19.4.

JoomShaper Ends Joomla 3 Security Fixes
JoomShaper ended Joomla 3 support with no security fixes regardless of severity, then reversed the security half six days later and shipped patches.

Fix Joomla 3 Security Issues in One Click
Patch every known Joomla 3 security vulnerability across all your sites with a single toggle in mySites.guru - no manual file edits, no eLTS subscription.

Manage Your Joomla 4 Sites with mySites.guru
mySites.guru fully supports Joomla 4 with the same audit, backup, update, and monitoring toolset available for every Joomla version since 1.5.

Migrating to Modern Joomla When Using mySites.guru
How to keep your sites connected to mySites.guru when migrating from Joomla 3 to Joomla 4, 5, or 6. Step-by-step connector swap process.

The Joomla 3.10.999 Project
The Joomla 3.10.999 project backported critical security patches to end-of-life Joomla 3 sites. What it was, why it existed, and what to do now.