Skip to main content
mySites.guru
J!Awards 2026mySites.guru is shortlisted for Your Favourite Tool in Your Joomla WorkflowVote by 11 OctoberHow to vote

Joomla 3

26 articles tagged Joomla 3, newest first.

1,000+ Days After Joomla 3's End of Life, Everything You Need Is on One Site

1,000+ Days After Joomla 3's End of Life, Everything You Need Is on One Site

joomla3security.com puts the Joomla 3 end-of-life dates, 46 vendors' positions, 39 unpatched core advisories and your options to stay or migrate in one place.

14 More Joomla 3 Security Fixes, Each Tested on a Real 3.10.12 Site

14 More Joomla 3 Security Fixes, Each Tested on a Real 3.10.12 Site

Joomla 5.4.9 fixed 16 core issues. We backported every one reaching Joomla 3 to the mySites.guru one-click patch tool, each proved on a real 3.10.12 site.

SP Page Builder's Joomla 3 Security Patch Was Incomplete. Version 1.0.3 Fixes It.

SP Page Builder's Joomla 3 Security Patch Was Incomplete. Version 1.0.3 Fixes It.

JoomShaper's first Joomla 3 security patch for SP Page Builder left the captcha bypass live and the XSS fix incomplete. Version 1.0.3 closes both.

Joomla 5.4.9 and 6.1.4 Fix 16 Security Issues, Two Rated High

Joomla 5.4.9 and 6.1.4 Fix 16 Security Issues, Two Rated High

Joomla 5.4.9 and 6.1.4 fix 16 core security issues, including cache directory deletion, SSRF, an MFA bypass and account creation with registration switched off.

Six more J2Store flaws fixed in 3.3.23, 4.0.23 and 4.1.8

Six more J2Store flaws fixed in 3.3.23, 4.0.23 and 4.1.8

J2Store 3.3.23, 4.0.23 and 4.1.8 fix six flaws mySites.guru reported, including an anonymous blind SQL injection that reads a Joomla shop's whole database.

SQL Injection and a Captcha Bypass in the SP Page Builder Joomla Extension, found by mySites.guru

SQL Injection and a Captcha Bypass in the SP Page Builder Joomla Extension, found by mySites.guru

mySites.guru found an Author-level SQL injection and an unauthenticated captcha bypass in the SP Page Builder Joomla extension, both fixed in 6.9.1.

Regular Labs Publishes 24 Joomla Extension Updates Including 10 Security Fixes

Regular Labs Publishes 24 Joomla Extension Updates Including 10 Security Fixes

Regular Labs shipped 24 Joomla extension updates on 13 September 2026. Ten fix security issues across nine CVEs, and four change behaviour on update.

Digital Peak patches four Joomla extensions after a Claude audit

Digital Peak patches four Joomla extensions after a Claude audit

Digital Peak shipped out-of-band fixes for DPCalendar, DPMedia, DPAttachments and DPCases on 10 September. DPAttachments is the one to do first.

J2Store 3 Stops Getting Security Fixes on 19 October 2026

J2Store 3 Stops Getting Security Fixes on 19 October 2026

J2Commerce ends J2Store 3 support on 19 October 2026. Six in ten of the J2Store installs we monitor are on that line, and most are three releases behind.

J2Store 3.3.22, 4.0.22 and 4.1.7 fix five flaws we reported

J2Store 3.3.22, 4.0.22 and 4.1.7 fix five flaws we reported

J2Store 3.3.22, 4.0.22 and 4.1.7 fix five flaws mySites.guru reported, including anonymous PayPal order confirmation and a 9.5 backend escalation.

Joomla 3 Didn't Fail. Your Retainer Did.

Joomla 3 Didn't Fail. Your Retainer Did.

We monitor 30,305 live Joomla 3 sites. They are five times more likely to be hacked than Joomla 6, and the agencies who migrated are doing worse.

DPCalendar 10.12.0 fixes an SQL injection and an XSS

DPCalendar 10.12.0 fixes an SQL injection and an XSS

Digital Peak fixed a blind SQL injection and a stored XSS in DPCalendar 10.12.0, backported to 8.19.5 for Joomla 3. Both need a logged-in user.

Helix Ultimate 2.2.10 Fixes Twelve Security Issues, Including a Pre-Login Bypass

Helix Ultimate 2.2.10 Fixes Twelve Security Issues, Including a Pre-Login Bypass

Helix Ultimate 2.2.10 is a security release for the Joomla template framework. Every version below it is affected. Here is what it fixes and how to update.

Helix Ultimate's Third Joomla 3 Patch Since JoomShaper Said There Would Be None

Helix Ultimate's Third Joomla 3 Patch Since JoomShaper Said There Would Be None

JoomShaper said its Joomla 3 products would get no security patches regardless of severity. The Helix Ultimate template framework has now had four.

A CVSS 10.0 Unauthenticated Upload in YOOtheme ZOO, Fixed in 4.1.66

A CVSS 10.0 Unauthenticated Upload in YOOtheme ZOO, Fixed in 4.1.66

YOOtheme ZOO (com_zoo) up to 4.1.63 had an unauthenticated file upload RCE scored CVSS 10.0, plus a SQL injection, fixed in 4.1.64. Install 4.1.66.

Phoca Cart 5.2.4, 6.1.7 and 4.0.13 fix a front-end SQL injection

Phoca Cart 5.2.4, 6.1.7 and 4.0.13 fix a front-end SQL injection

Phoca Cart 5.2.4, 6.1.7 and 4.0.13 patch an unauthenticated SQL injection in the Joomla extension's product filter. Joomla 5 on 6.x isn't offered it.

The Fabrik Fiasco: Announced, Restricted, Relabelled

The Fabrik Fiasco: Announced, Restricted, Relabelled

Two CVSS 10.0 RCEs in the Fabrik Joomla extension, and a chaotic run of security releases since. The vendor has moved past 4.7.0; be on 4.7.2.

Events Booking for Joomla: Anyone Could Upload Files to Your Server

Events Booking for Joomla: Anyone Could Upload Files to Your Server

mySites.guru found two unauthenticated flaws in Events Booking for Joomla: file upload enabled by default, and a leak of every user's name and email.

JoomShaper Patched the Joomla 3 It Said It Never Would

JoomShaper Patched the Joomla 3 It Said It Never Would

Six days after excluding Joomla 3 security patches, JoomShaper shipped them for Helix Ultimate, Helix3 and SP Page Builder. What is in them.

The One-Click Way to Patch JoomShaper Extensions on Joomla 3

The One-Click Way to Patch JoomShaper Extensions on Joomla 3

mySites.guru backports JoomShaper's security fixes into SP Page Builder, Helix3 and Helix Ultimate on Joomla 3, across every site in your account.

Unauthenticated SQL Injection in DPCalendar found by mySites.guru

Unauthenticated SQL Injection in DPCalendar found by mySites.guru

mySites.guru found and reported an unauthenticated SQL injection in the DPCalendar Joomla extension's public events feed. Fixed in 10.11.2 and 8.19.4.

JoomShaper Ends Joomla 3 Security Fixes

JoomShaper Ends Joomla 3 Security Fixes

JoomShaper ended Joomla 3 support with no security fixes regardless of severity, then reversed the security half six days later and shipped patches.

Fix Joomla 3 Security Issues in One Click

Fix Joomla 3 Security Issues in One Click

Patch every known Joomla 3 security vulnerability across all your sites with a single toggle in mySites.guru - no manual file edits, no eLTS subscription.

Manage Your Joomla 4 Sites with mySites.guru

Manage Your Joomla 4 Sites with mySites.guru

mySites.guru fully supports Joomla 4 with the same audit, backup, update, and monitoring toolset available for every Joomla version since 1.5.

Migrating to Modern Joomla When Using mySites.guru

Migrating to Modern Joomla When Using mySites.guru

How to keep your sites connected to mySites.guru when migrating from Joomla 3 to Joomla 4, 5, or 6. Step-by-step connector swap process.

The Joomla 3.10.999 Project

The Joomla 3.10.999 Project

The Joomla 3.10.999 project backported critical security patches to end-of-life Joomla 3 sites. What it was, why it existed, and what to do now.

Browse every article