The Joomla 5 update package is designed to update existing installations within the 5.x series, which has been released since October 2023. Official support for the series is planned until October 2027. We recommend promptly installing the latest stable updates for Joomla 5 and, if possible, upgrading to the current major Joomla 6 series.
| Security |
[20260801] Fixed response header injection in download views.
|
| Security |
[20260802] Fixed improper CORS origin validation.
|
| Security |
[20260803] Fixed inconsistent ACL checks for mutating web service endpoints.
|
| Security |
[20260804] Fixed improper ACL checks for custom fields web service endpoints.
|
| Security |
[20260805] Fixed improper ACL checks for category web service endpoints.
|
| Security |
[20260806] Fixed an XSS vulnerability in Schema.org output.
|
| Security |
[20260807] Fixed a multi-factor authentication (MFA) bypass vulnerability.
|
| Security |
[20260808] Fixed improper ACL checks for batch copy actions.
|
| Security |
[20260809] Fixed improper ACL checks when injecting Schema.org contact data.
|
| Security |
[20260810] Prevented unrestricted uploads of SHTML files.
|
| Fixed |
#46805 — Added an ACL check when displaying the link to the user edit form.
|
| Fixed |
#47202 — Fixed menu item editing redirecting to the list view without preserving the original filters.
|
| Fixed |
#47626 — Implemented date and time validation when input values are changed.
|
| Fixed |
#47766 — Improved error messages for update server errors.
|
| Fixed |
#47780 — Corrected the data-nested attribute for nested components, including categories, menu items and modules.
|
| Fixed |
#47886 — Fixed Global Check-in treating rows with checked_out=0 as requiring check-in.
|
| Fixed |
#48060 — Fixed article-specific options being ignored in the article view.
|
| Fixed |
#48074 — Prevented a DivisionByZeroError in ListModel when list.limit is set to 0.
|
| Fixed |
#48080 — Updated joomla/filesystem from version 3.2.0 to 3.3.0 and partially backported the update upload fix from the Joomla 6.1 branch.
|
| Fixed |
#48088 — Fixed the duplicate “No results” message in the list of installed languages.
|
| Fixed |
#48091 — The Action Log plugin now creates only one entry when blocking or unblocking a user.
|
| Fixed |
#48116 — Cleaned up FilePatcher remnants left by the Joomla 5.4.7 core update hotfix.
|
| Fixed |
#48163 — Fixed a division-by-zero error in subforms.
|
| Fixed |
#48171 — Added path traversal checks to the Templates component.
|
| Fixed |
#48173 — Standardized the memory_table_limit option in Smart Search.
|
| Fixed |
#48184 — Fixed a typo in the Awesomplete example.
|
| Fixed |
#48185 — Fixed indentation in the tree selection field.
|
| Fixed |
#48212 — Fixed normalization of the days_of_week parameter.
|
| Fixed |
#48216 — Fixed the Site Offline functionality.
|
| Fixed |
#48247 — Reverted an invalid path check change in the Templates component.
|
| Note |
Joomla 5.4.8 is a security and bugfix release.
|
| Note |
Installing Joomla 5.4.8 as soon as possible is strongly recommended.
|
| Note |
Joomla 5.4.8 was released together with Joomla 6.1.3.
|
| Note |
Creating a website backup and checking the compatibility of installed extensions and templates is recommended before updating.
|
| Security |
[20260701] Fixed incorrect access control in com_media web service endpoints.
|
| Security |
[20260702] Fixed incorrect access control when downloading VCF files from com_contact.
|
| Security |
[20260703] Fixed an XSS vulnerability in MFA method management.
|
| Security |
[20260704] Fixed an XSS vulnerability in com_templates.
|
| Security |
[20260705] Fixed XSS vulnerabilities in various modalreturn layouts.
|
| Security |
[20260706] Fixed an XSS vulnerability in com_installer.
|
| Security |
[20260707] Fixed an XSS vulnerability in the generic image output layout.
|
| Security |
[20260708] Fixed an XSS vulnerability involving language overrides.
|
| Security |
[20260709] Fixed incorrect access control in com_workflow.
|
| Security |
[20260710] Fixed incorrect access control in com_modules.
|
| Security |
[20260711] Fixed incorrect access control in com_privacy web service endpoints.
|
| Security |
[20260712] Fixed incorrect access control in com_fields web service endpoints.
|
| Fixed |
#47836 — Updated the phpstan-baseline.neon file.
|
| Fixed |
#47203 — Added support for updating extensions from the command-line interface.
|
| Fixed |
#47603 — Mail templates are now loaded using the language assigned to the template.
|
| Fixed |
#47734 — The installer no longer proceeds to database setup when the password contains leading or trailing spaces.
|
| Fixed |
#47837 — Added a system test for the Media Manager search path traversal issue.
|
| Fixed |
#47748 — Added support for creating a user access level through a POST web service request.
|
| Fixed |
#47752 — Fixed author display when using article-specific settings.
|
| Fixed |
#47771 — Updated NPM dependencies.
|
| Fixed |
#47774 — Front-end filters are now activated only when the filter button is available.
|
| Fixed |
#47800 — Preserved the text of the zero-value option in selection fields.
|
| Fixed |
#47825 — Updated the Typos GitHub Action to version 1.46.3.
|
| Fixed |
#47827 — Updated the actions-setup-mysql GitHub Action to version 1.51.0.
|
| Fixed |
#47852 — Fixed a regression introduced by the security fix in Joomla 5.4.6 and 6.1.1.
|
| Fixed |
#47855 — Fixed modal pagination breaking navigation.
|
| Fixed |
#47751 — Added support for updating a user access level without supplying rules through a PATCH request.
|
| Fixed |
#47847 — Updated symfony/yaml to version 6.4.41 to fix three security vulnerabilities.
|
| Fixed |
#47830 — Updated the github-script GitHub Action to version 9.0.0.
|
| Fixed |
#47826 — Updated the setup-php GitHub Action to version 2.37.1.
|
| Fixed |
#47882 — FIDO metadata is now cached in the build directory and preserved during builds.
|
| Fixed |
#47865 — Fixed the Joomla success alert.
|
| Fixed |
#47637 — The manifest path is now compiled from the extension root directory.
|
| Fixed |
#47895 — Added FIDO, Composer and NPM caching to the Drone configuration.
|
| Fixed |
#47548 — Fixed CodeMirror editor duplication.
|
| Fixed |
#47483 — Fixed the aria-expanded attribute check.
|
| Fixed |
#47869 — Added an email-sending test for the contact form.
|
| Fixed |
#47896 — Reordered and updated Text::script() calls for media field labels.
|
| Fixed |
#47917 — Reordered and updated Text::script() calls in the Joomla Update component.
|
| Fixed |
#47931 — Fixed the documentation block for the input type.
|
| Fixed |
#47819 — Fixed submitting the com_contact form through web services when custom reply is enabled.
|
| Fixed |
#47964 — A new installer instance is now always used when installing discovered extensions.
|
| Fixed |
#47978 — Fixed a potential issue when updating multiple extensions.
|
| Fixed |
#47985 — Cookie authentication now loads the language file so that log messages can be translated.
|
| Fixed |
#47986 — Fixed the username placeholder in failed cookie-login log messages.
|
| Fixed |
#47972 — The correct function is now used to retrieve a message from an exception.
|
| Fixed |
#47916 — Fixed the Indexer Debugger constructor and added an error message when no ID or an invalid ID is supplied.
|
| Fixed |
#44914 — Fixed the contact and news feed serializers.
|
| Fixed |
#47818 — Added integration tests for the config:get CLI command.
|
| Fixed |
#47993 — Fixed filtering by unactivated user status in com_users.
|
| Fixed |
#47763 — Added a system test for the Scheduled Tasks console command.
|
| Fixed |
#47951 — The “Running Since” tooltip on the Scheduled Tasks page now uses the locked property instead of last_execution.
|
| Fixed |
#48018 — Updated Composer dependencies.
|
| Fixed |
#48024 — Updated NPM dependencies.
|
| Fixed |
#47936 — Added code style fixes and updated the PHPStan configuration.
|
| Note |
Joomla 5.4.7 is a security and bugfix release.
|
| Note |
Installing Joomla 5.4.7 as soon as possible is strongly recommended.
|
| Note |
Joomla 5.4.7 was released together with Joomla 6.1.2.
|
| Note |
Joomla 5.4.7 has a known issue where article-specific parameters may be ignored when an article is displayed through a category layout or a single-article menu item.
|
| Note |
An installable Joomla_5_4_7_and_6_1_2_ArticleModel_Hotfix1.zip package was released as a temporary fix.
|
| Note |
The permanent fix for the known issue was included in Joomla 5.4.8.
|
| Note |
Creating a website backup and checking the compatibility of installed extensions and templates is recommended before updating.
|
| Security |
[20260501] Fixed an XSS vulnerability in feed modules.
|
| Security |
[20260502] Fixed an XSS vulnerability in com_associations.
|
| Security |
[20260503] Fixed an XSS vulnerability in com_contenthistory.
|
| Security |
[20260504] Fixed an XSS vulnerability in Read More links.
|
| Security |
[20260505] Fixed a CSRF vulnerability in the user activation endpoint.
|
| Security |
[20260506] Fixed an authenticated blind SQL injection vulnerability in com_finder.
|
| Security |
[20260507] Fixed an authenticated blind SQL injection vulnerability in com_tags.
|
| Security |
[20260508] Fixed an improper access check in com_config web service endpoints.
|
| Security |
[20260509] Fixed a local file inclusion vulnerability in the HTMLView layout parameter.
|
| Security |
[20260510] Fixed a path traversal vulnerability in a com_media web service endpoint.
|
| Security |
[20260511] Fixed an MFA authentication bypass vulnerability.
|
| Security |
[20260512] Fixed an additional MFA authentication bypass vulnerability.
|
| Security |
[20260513] Fixed privilege escalation through the com_users batch task.
|
| Security |
[20260514] Fixed privilege escalation through com_users web service endpoints.
|
| Security |
[20260515] Fixed incorrect access control in sample data plugins.
|
| Security |
[20260516] Fixed incorrect access control in com_scheduler.
|
| Security |
[20260517] Fixed incorrect cache key construction for InputFilter objects.
|
| Security |
[20260518] Prevented transport encryption downgrade for username and password reset links.
|
| Security |
[20260519] Improved content filtering in the Joomla Framework checkAttribute filter code.
|
| Security |
[20260520] Improved content filtering in the Joomla Framework cleanAttributes filter code.
|
| Fixed |
#47565 — Fixed the handling of attachments supplied as a list of objects.
|
| Fixed |
#47413 — Prevented a misleading save failure message when a mail notification fails.
|
| Fixed |
#47423 — Improved substring searching in Fancy Select fields.
|
| Fixed |
#47624 — Updated branch documentation following the stable release of Joomla 6.1.0.
|
| Fixed |
#47590 — Fixed deletion of the update archive after an automatic Joomla core update.
|
| Fixed |
#47644 — Added a missing table column header to improve accessibility.
|
| Fixed |
#47650 — Fixed RTL toolbar dropdown alignment in the administrator interface.
|
| Fixed |
#47604 — Fixed HTML tag replacement when converting an HTML email body to plain text.
|
| Fixed |
#47642 — Corrected aria-posinset values so that they start from 1.
|
| Fixed |
#47616 — Added a translation format so that the last automatic update check time is displayed correctly.
|
| Fixed |
#47653 — Improved the accessibility of language installation information.
|
| Fixed |
#47697 — Moved mod_menu language loading until after client_id resolution in ItemsModel.
|
| Fixed |
#47586 — Fixed category custom fields loading.
|
| Fixed |
#47729 — Fixed the notification dismiss button in light mode.
|
| Fixed |
#47731 — Child template name validation now checks only templates of the appropriate type.
|
| Fixed |
#47533 — Fixed an ECB mode validation typo in the OpenSSL AES adapter and updated the related documentation.
|
| Fixed |
#46886 — Added a system test for filtering published and unpublished articles.
|
| Fixed |
#47555 — Added a system test for the cache cleaning console command.
|
| Fixed |
#47556 — Added a system test for the Scheduled Tasks console command.
|
| Fixed |
#47712 — Added system tests for custom fields in articles.
|
| Fixed |
#47254 — Updated phpMyAdmin in Codespaces to the latest version.
|
| Fixed |
#47476 — Added the missing page parameter to the content event arguments in the Articles module.
|
| Fixed |
#47480 — Fixed an incorrect bind parameter key in the Category HTML helper.
|
| Fixed |
#45145 — Fixed an incorrect error being displayed when renaming a file.
|
| Fixed |
#47307 — Fixed an accessibility issue with the Back-to-Top link.
|
| Fixed |
#47401 — Removed an unused web asset reference.
|
| Fixed |
#47735 — Fixed article version preview for users with Author permissions.
|
| Fixed |
#47610 — Added integration tests for listing extensions by type.
|
| Note |
Joomla 5.4.6 is a security and bugfix release.
|
| Note |
Installing Joomla 5.4.6 as soon as possible is strongly recommended.
|
| Note |
Joomla 5.4.6 was released together with Joomla 6.1.1.
|
| Note |
Creating a website backup and checking the compatibility of installed extensions and templates is recommended before updating.
|
| Note |
When upgrading from a version earlier than Joomla 4.4, update to Joomla 4.4 first and then upgrade to Joomla 5.
|
| Fixed |
#47474 — Fixed the ShowOnRule regular expression pattern for custom fields.
|
| Fixed |
#47520 — Updated the version number in the allowEdit method documentation.
|
| Fixed |
#47523 — The full path for $this is now used in the association template file.
|
| Fixed |
#47433 — Fixed double timezone conversion in Media Manager file dates.
|
| Fixed |
#47448 — Added a logical top corner radius for consistent RTL and LTR display.
|
| Fixed |
#47462 — Fixed the image rotation angle being reset to 0 in Media Manager.
|
| Fixed |
#47467 — Added onContentPrepare event processing to the mod_articles module.
|
| Fixed |
#47478 — TinyMCE now loads the non-minified custom CSS file when a minified version is unavailable.
|
| Fixed |
#47505 — Fixed highlighting of the required modal category field after a validation error.
|
| Fixed |
#47529 — Updated phpseclib/phpseclib to version 3.0.50 to fix one high-severity security vulnerability.
|
| Fixed |
#47530 — Updated indirect NPM dependencies to fix eight security vulnerabilities.
|
| Fixed |
#47511 — Added a warning when duplicate subform fields are removed during saving.
|
| Fixed |
#47540 — Corrected the English possessive form of the word users in a language string.
|
| Fixed |
#47208 — Prevented recursion in the loadposition and loadmodule content plugin.
|
| Fixed |
#47534 — Updated the indirect lodash development dependency to version 4.18.1.
|
| Note |
Joomla 5.4.5 is a bugfix release for the Joomla 5 series.
|
| Note |
No separate Joomla core security fixes were announced for this release.
|
| Note |
The update includes a fix for one high-severity vulnerability in the phpseclib library.
|
| Note |
The update also resolves eight security vulnerabilities in indirect NPM dependencies.
|
| Note |
Creating a website backup and checking the compatibility of installed extensions and templates is recommended before updating.
|
| Note |
When upgrading from a version earlier than Joomla 4.4, update to Joomla 4.4 first and then upgrade to Joomla 5.
|
| Security |
[20260301] Hardened ACL checks in com_ajax.
|
| Security |
[20260302] Fixed an SQL injection vulnerability in the com_content articles web service endpoint.
|
| Security |
[20260303] Fixed an XSS vulnerability in the com_associations comparison view.
|
| Security |
[20260304] Fixed XSS vulnerabilities in various article title outputs.
|
| Security |
[20260305] Fixed an arbitrary file deletion vulnerability in com_joomlaupdate.
|
| Security |
[20260306] Fixed improper access checks in web service endpoints.
|
| Fixed |
#46866 — Updated the deployment version information.
|
| Fixed |
#46857 — Reduced exclusions in phpstan-baseline.neon.
|
| Fixed |
#46811 — Fixed date highlighting in the front-end calendar.
|
| Fixed |
#46905 — Updated the browserlist:update script.
|
| Fixed |
#46889 — Fixed TinyMCE initialization in Firefox Developer Edition.
|
| Fixed |
#46719 — Fixed the content data-transitions attribute being inherited from the first allowed item.
|
| Fixed |
#46835 — Updated the Pull Request template to link related issues automatically.
|
| Fixed |
#46910 — Fixed calendar display for right-to-left languages.
|
| Fixed |
#46917 — Added the artificial intelligence policy to the Pull Request template.
|
| Fixed |
#46906 — Updated Browserlist data.
|
| Fixed |
#46881 — Added publishing status checks when retrieving banner items.
|
| Fixed |
#46929 — Exposed the update filename during the automatic update preparation step.
|
| Fixed |
#47235 — Removed a duplicate empty line from README.md.
|
| Fixed |
#47226 — Fixed the selected checkmark background in Choices.js fields.
|
| Fixed |
#47253 — Added a workflow for automatically marking conflicting Pull Requests.
|
| Fixed |
#47265 — Disabled the blank GitHub issue template.
|
| Fixed |
#47286 — Fixed a comment typo in merge-conflicts.yml.
|
| Fixed |
#47258 — Updated the deleted files and folders list in script.php for the Joomla 5.4.4 release.
|
| Fixed |
#47293 — Added new Joomla versions to CONTRIBUTING.md.
|
| Fixed |
#47268 — Fixed flashing icons in the administrator sidebar.
|
| Fixed |
#47218 — Fixed duplicate article counts caused by many-to-many relationships in mod_tags_popular.
|
| Fixed |
#47263 — Fixed conditional Read More link output in mod_articles.
|
| Fixed |
#47244 — Fixed padding in Choices.js selection fields.
|
| Fixed |
#47321 — Updated NPM development dependencies to fix nine security vulnerabilities.
|
| Fixed |
#47217 — Fixed Scheduled Tasks stopping when one task becomes stuck.
|
| Fixed |
#47336 — Added a check to verify that the schema path specified in the manifest exists.
|
| Fixed |
#47352 — Selector filters are now reset when SearchTools filters are cleared.
|
| Fixed |
#46933 — Fixed undefined array key warnings in workflow permissions.
|
| Fixed |
#47274 — Fixed the Joomla version being omitted from nightly build notifications.
|
| Fixed |
#47390 — Nightly build commands now use the DRONE_BRANCH variable instead of MINORVERSION.
|
| Fixed |
#47397 — Corrected quotation mark escaping in nightly build notifications.
|
| Fixed |
#47399 — Fixed nightly build notifications by using single quotes and string concatenation.
|
| Fixed |
#47376 — Fixed MailHelper::isEmailAddress() throwing an exception for forbidden characters.
|
| Fixed |
#47388 — The Versions button is now hidden when com_contenthistory is disabled.
|
| Fixed |
#47406 — Updated the indirect flatted NPM dependency to fix a high-severity security vulnerability.
|
| Fixed |
#47251 — Fixed relative asset paths on the Cassiopeia error page.
|
| Fixed |
#47411 — Updated the GitHub feature request issue template.
|
| Fixed |
#47422 — Updated GitHub Actions and dropped Node.js 20.
|
| Fixed |
#47427 — The media edit button is now disabled when no media action plugins are enabled.
|
| Note |
Joomla 5.4.4 is a security and bugfix release.
|
| Note |
Installing Joomla 5.4.4 as soon as possible is strongly recommended.
|
| Note |
Joomla 5.4.4 was released together with Joomla 6.0.4.
|
| Note |
Creating a website backup and checking the compatibility of installed extensions and templates is recommended before updating.
|
| Note |
When upgrading from a version earlier than Joomla 4.4, update to Joomla 4.4 first and then upgrade to Joomla 5.
|
| Fixed |
Fixed a typo in a code comment.
|
| Fixed |
Fixed a warning in tag links without an Itemid.
|
| Fixed |
Anchor references are now skipped by the CSS versioning build script.
|
| Fixed |
Fixed the breadcrumbs module duplicating the Home link on multilingual websites.
|
| Fixed |
Hidden the help link in the administrator menu.
|
| Fixed |
Updated the Joomla Framework HTTP package.
|
| Fixed |
The image class now accepts user input.
|
| Fixed |
Fixed the CLI installation exit code when the PHP version requirement is not met.
|
| Fixed |
Added a legacy label to the archived articles module.
|
| Fixed |
Fixed a 500 error in Smart Search with specific search queries.
|
| Fixed |
Tightened the regular expression used to find menu items and prevent duplicate edit link icons.
|
| Fixed |
Changed the XML user group list field type to the lowercase usergrouplist format.
|
| Fixed |
Fixed missing parent menu items when creating a menu item through the Save to Menu feature.
|
| Fixed |
Updated paragonie/sodium_compat to version 1.24.0 to resolve Composer Audit warnings.
|
| Fixed |
Updated development dependencies to resolve security vulnerabilities reported by NPM Audit.
|
| Fixed |
Fixed a typo in a code comment.
|
| Fixed |
Removed the layouts folder and added presets.
|
| Fixed |
Further fixed missing parent menu items when creating a menu item through the Save to Menu feature.
|
| Fixed |
Fixed OptionsRule validation to support groupedlist fields.
|
| Fixed |
Fixed letter casing in the mod_articles manifest.
|
| Fixed |
Reverted previous mailer improvements.
|
| Fixed |
Fixed a Metis Menu error that occurred when clicking outside a dropdown menu.
|
| Fixed |
Updated algo26-matthias/idna-convert to version 3.2.1.
|
| Fixed |
Improved the archive-not-found error message.
|
| Fixed |
The website root URL is now prepended to schema image paths.
|
| Fixed |
Fixed the extension variable type in AssociationExtensionHelper.
|
| Fixed |
Added cache cleaning after a pull request is merged.
|
| Fixed |
Fixed the web services response when requesting a non-existing user access level.
|
| Fixed |
Fixed the PHP 8.5 deprecation warning caused by passing null as the key to array_key_exists().
|
| Fixed |
Selected rows in the debug profile timeline are now outlined.
|
| Fixed |
Fixed image handling in the articles module.
|
| Fixed |
Fixed button styling in alert messages.
|
| Fixed |
Fixed ZIP archive handling in the Templates component.
|
| Fixed |
Updated development dependencies to resolve low- and moderate-severity NPM vulnerabilities.
|
| Fixed |
The web services API now allows users to be updated through PATCH without specifying groups in the payload.
|
| Fixed |
Added an integration test for checking extension updates.
|
| Fixed |
Fixed the fonts URL.
|
| Fixed |
Fixed an undefined language array key warning in the SEF plugin.
|
| Fixed |
WebAssetRegistry now works with a renamed administrator folder.
|
| Fixed |
Improved the MySQL installation error message.
|
| Fixed |
Fixed untranslated text in the command-line interface.
|
| Fixed |
Updated the pull request template.
|
| Fixed |
The web services API now allows a Super User account to be updated through PATCH.
|
| Fixed |
Added missing name quotes and corrected the casing of a column alias in the Nested table class.
|
| Fixed |
Standardised the XML code style for Joomla.form.field definitions.
|
| Fixed |
Excluded Symfony HTTP client test folders from Joomla release packages.
|
| Fixed |
Updated three development dependencies to resolve Composer Audit warnings.
|
| Fixed |
Updated indirect development dependencies and resolved 19 NPM security vulnerabilities.
|
| Fixed |
Added unit tests for form rules.
|
| Fixed |
Fixed removal of the installation folder on Windows.
|
| Fixed |
Updated the list of deleted files and folders in script.php.
|
| Fixed |
Added a default value for check-in tasks.
|
| Fixed |
Fixed duplicate getLayoutData execution in the popular tags module.
|
| Fixed |
Added a missing-user check to the action log plugin to prevent PHP warnings.
|
| Fixed |
The table column script now checks whether the page title element exists.
|
| Fixed |
Fixed a Calendar field crash caused by an invalid date format.
|
| Fixed |
Reverted the change that allowed user access levels to be created through a POST web services request.
|
| Note |
Joomla 5.4.3 is a bug-fix release in the Joomla 5.4 series.
|
| Note |
Joomla 5.4.3 was released together with Joomla 6.0.3.
|
| Note |
No separate Joomla core security fixes were announced for this release.
|
| Note |
Several dependencies were updated to resolve audit warnings and security vulnerabilities.
|
| Note |
Firefox 148 has a known compatibility issue with TinyMCE that may cause flickering and endless content loading.
|
| Note |
An installable hotfix is available for the Firefox 148 and TinyMCE compatibility issue.
|
| Note |
A complete backup of the website files and database is recommended before updating.
|
| Note |
When updating from a Joomla version earlier than 4.4, upgrading to Joomla 4.4 first is recommended.
|
| Security |
Fixed inadequate content filtering for data URLs that could allow XSS attacks through image tags.
|
| Security |
Fixed XSS vulnerabilities in the Page Break and Page Navigation plugins.
|
| Addition |
Added full support for PHP 8.5.
|
| Addition |
Added PHP 8.5 to unit and integration tests.
|
| Addition |
Added a pull request targeting section to the README file.
|
| Fixed |
Fixed the static getTemplate call in mail templates.
|
| Fixed |
Updated the use of the fputcsv function for PHP 8.4 compatibility.
|
| Fixed |
Fixed the PHP 8.5 version check.
|
| Fixed |
Removed the remaining deprecated JText calls.
|
| Fixed |
Fixed a 404 error in the web services component configuration route when a component name contains numbers.
|
| Fixed |
Aligned the Envelope-From and Return-Path headers with the sender address in MailTemplateFactory.
|
| Fixed |
Fixed the request format condition in MenusHelper that caused a deprecation warning.
|
| Fixed |
The success and message types are now correctly mapped to SymfonyStyle in ConsoleApplication.
|
| Fixed |
Removed the sidebar wrapper border and added a box shadow to the autumn dark-mode colour scheme.
|
| Fixed |
Updated indirect development dependencies to resolve security vulnerabilities reported by NPM Audit.
|
| Fixed |
Fixed Smart Search taxonomy filters being overwritten when multiple filters have identical titles.
|
| Fixed |
Articles are no longer loaded in the blog layout when article loading is disabled in the configuration.
|
| Fixed |
Fixed a regular expression in DocumentRenderer.php.
|
| Fixed |
The latest action logs module now loads the language files of the corresponding extensions.
|
| Fixed |
Fixed the snooze function in the Joomla end-of-support notification plugin.
|
| Fixed |
Fixed the MySQL 8 error caused by an illegal argument being passed to a regular expression in the banners model.
|
| Fixed |
Further updated indirect development dependencies to resolve NPM security vulnerabilities.
|
| Fixed |
Fixed scheduled-task notifications for Joomla installations updated from versions earlier than Joomla 5.3.
|
| Fixed |
Automatic update finalisation errors are now exposed in API responses.
|
| Fixed |
Removed an unnecessary setError call with an empty value.
|
| Fixed |
Updated development dependencies to resolve security vulnerabilities reported by NPM Audit.
|
| Fixed |
Removed the obsolete skin creator link from TinyMCE.
|
| Fixed |
Fixed the subform field dropdown incorrectly displaying the current field.
|
| Note |
Joomla 5.4.2 is a security and bug-fix release.
|
| Note |
Joomla 5.4.2 was released together with Joomla 6.0.2.
|
| Note |
CVE-2025-63082 has moderate severity and a low probability of exploitation.
|
| Note |
CVE-2025-63083 has moderate severity and a low probability of exploitation.
|
| Note |
A complete backup of the website files and database is recommended before updating.
|
| Note |
The update should be tested on a copy of the production website before deployment.
|
| Note |
When updating from a Joomla version earlier than 4.4, upgrade to Joomla 4.4 before updating to Joomla 5.
|
| Addition |
Added Mailpit email testing support to Codespaces.
|
| Addition |
Already selected elements in enhanced select lists are now marked with a checkmark.
|
| Addition |
Added MySQL to the test matrix with the appropriate minimum and maximum supported database versions.
|
| Fixed |
Fixed deprecated PHP 8.5 code.
|
| Fixed |
Resolved PHP 8.5 deprecation warnings.
|
| Fixed |
Fixed additional code deprecated in PHP 8.5.
|
| Fixed |
Fixed missing options in pagination.
|
| Fixed |
Fixed saving content history when using PostgreSQL.
|
| Fixed |
Removed the xml_parser_free() call deprecated in PHP 8.5.
|
| Fixed |
Removed the curl_close() call deprecated in PHP 8.5.
|
| Fixed |
Fixed InstallerScript using id instead of extension_id for the extensions table.
|
| Fixed |
Fixed the deprecated use of null as an array offset in PHP 8.5.
|
| Fixed |
Removed the use of deprecated setAccessible() methods on Reflection objects.
|
| Fixed |
Fixed the use of null as an array offset in unit tests.
|
| Fixed |
Updated joomla/http to version 3.1.3 to resolve the deprecated curl_close() call in PHP 8.5.
|
| Fixed |
Updated joomla/test to version 3.0.4 to resolve the deprecated Reflection setAccessible() call in PHP 8.5.
|
| Fixed |
Removed the imagedestroy() call deprecated in PHP 8.5.
|
| Fixed |
Fixed the privacy request message displayed when email delivery is disabled.
|
| Fixed |
Improved command-line error and help messages.
|
| Fixed |
Fixed the administrator colour scheme display.
|
| Fixed |
Fixed the log entry format.
|
| Fixed |
Underlined links to improve accessibility.
|
| Fixed |
Removed obsolete Joomla 4.4 GitHub Actions workflows and cleaned up contributing.md.
|
| Fixed |
Updated the list of deleted files in script.php.
|
| Fixed |
Fixed the scheduled update notification task.
|
| Fixed |
Fixed a Joomla installation error on Windows.
|
| Fixed |
Added a check to determine whether the state is initialised in the content CategoryModel.
|
| Fixed |
Fixed the return types of the application getDocument and getLanguage methods.
|
| Fixed |
Improved the pre-update check for Joomla 6.0.0 by correcting a confusing message and adding additional notices.
|
| Fixed |
A 401 Unauthorized response is now handled without causing an uncaught critical server error 500.
|
| Fixed |
Improved the PHP temporary folder message.
|
| Fixed |
Fixed article ordering in the articles module.
|
| Fixed |
Updated the mysql2 development dependency from version 2.3.3 to version 3.15.3.
|
| Fixed |
Fixed automatic cache clearing for the articles module.
|
| Fixed |
Replaced critical 404 and 406 errors with notices containing useful diagnostic information.
|
| Fixed |
The captive page and captive.validate task are now available even when a password reset is required.
|
| Fixed |
Updated NULL values in Smart Search links.
|
| Fixed |
Fixed XML SHA checksum verification for update servers.
|
| Fixed |
Fixed the untranslated JLIB_APPLICATION_ERROR language string.
|
| Fixed |
Fixed headers not being sent correctly by the Media component API controller.
|
| Fixed |
The SessionGC task now removes associated metadata from the database.
|
| Fixed |
Prevented modules from being rendered on error pages when the application is not completely initialised.
|
| Fixed |
Fixed issues in the language package installer.
|
| Fixed |
Fixed the Joomla version information.
|
| Fixed |
Profile information is no longer requested when no user is linked to the profile.
|
| Fixed |
Updated the repeatable-table.php layout.
|
| Fixed |
Fixed comment block formatting to comply with the code style.
|
| Fixed |
Updated indirect development dependencies to resolve security vulnerabilities reported by NPM Audit.
|
| Fixed |
Prevented notices from being generated when processing broken images.
|
| Fixed |
Smart Search filters no longer receive a unique title and alias when using Save as Copy.
|
| Note |
Joomla 5.4.1 is a bug-fix release in the Joomla 5.4 series.
|
| Note |
Joomla 5.4.1 was released on 25 November 2025 together with Joomla 6.0.1.
|
| Note |
No separate Joomla core security fixes were announced for this release.
|
| Note |
A significant part of this release improves compatibility with PHP 8.5.
|
| Note |
A complete backup of the website files and database is recommended before updating.
|
| Note |
The update should be tested on a copy of the production website before deployment.
|
| Note |
When updating from a Joomla version earlier than 4.4, upgrade to Joomla 4.4 before updating to Joomla 5.
|
| Addition |
Added automated Joomla core updates.
|
| Addition |
Added the Joomla automated update client.
|
| Addition |
Added automated update notifications and configuration information.
|
| Addition |
Added an automated update status icon to the administrator dashboard.
|
| Addition |
Added an option to disable automated updates during Joomla installation.
|
| Addition |
Added selection of user groups that receive automated update notifications.
|
| Addition |
Automated update notifications can now be sent to all Super Users.
|
| Addition |
Added plugin events for integration with the automated update system.
|
| Addition |
Added pre-update checks for Joomla 6 backward compatibility plugins.
|
| Addition |
Added and enabled the Joomla 6 backward compatibility plugin.
|
| Addition |
Added a link to the System Maintenance Database page from the pre-update check.
|
| Addition |
Added a link to Mail Templates from the update notification.
|
| Addition |
Added support for a custom registration link in the Users component login menu item.
|
| Addition |
Added a None author filter to find articles associated with deleted users.
|
| Addition |
Added a None tag filter to find articles without tags.
|
| Addition |
Added a None tag filter to the Contacts component.
|
| Addition |
Added a None tag filter to the News Feeds component.
|
| Addition |
Added a None tag filter to category lists.
|
| Addition |
Fields without an assigned field group now display None.
|
| Addition |
User notes associated with deleted users now display None.
|
| Addition |
Added a checked-out filter to the Article Manager and API.
|
| Addition |
Added a year sort order parameter for archived articles.
|
| Addition |
Added an H6 article title heading option to the articles module.
|
| Addition |
The Show Article Images option is now available when intro text is truncated.
|
| Addition |
Added start and end dates for featured articles.
|
| Addition |
Added GitHub Codespaces support for Joomla development and testing.
|
| Addition |
Added a settings icon to the debug plugin.
|
| Change |
Prepared Joomla 5.4 as the bridge release for upgrading to Joomla 6.
|
| Change |
Refactored component and Joomla CMS table classes to use the modern architecture.
|
| Change |
Converted the random image, menu, latest articles, users online, logged-in users, privacy dashboard, Smart Search and login modules to service providers.
|
| Change |
Extended the deprecation period for plugin listener registration methods to Joomla 7.
|
| Change |
Extended the deprecation period for plugin events, editors and CAPTCHA integrations to Joomla 7.
|
| Change |
Extended the deprecation period for JLoader::register() from Joomla 6 to Joomla 7.
|
| Change |
Deprecated the app property in FieldsPlugin.
|
| Change |
Deprecated legacy Universal Content Model code.
|
| Change |
Changed administrator views to use exceptions instead of legacy error handling.
|
| Change |
Renamed the table event from onBeforeDelete to onTableBeforeDelete.
|
| Change |
Replaced DatabaseQuery::castAsChar() with castAs().
|
| Change |
Updated Composer and NPM dependencies.
|
| Change |
Updated joomla/filesystem to version 3.2.0.
|
| Change |
Updated GitHub Actions workflow versions to version 5.
|
| Change |
Updated the What's New tour image.
|
| Change |
Updated system information in the administrator interface.
|
| Change |
Updated documentation for Joomla developers.
|
| Fixed |
Fixed the article author filter.
|
| Fixed |
Fixed the display of deleted users in user notes.
|
| Fixed |
Improved the display of fields without an assigned field group.
|
| Fixed |
Improved tag error messages.
|
| Fixed |
Fixed tooltip widths.
|
| Fixed |
Improved the media deletion confirmation message.
|
| Fixed |
Added modern error handling through the shouldUseException() method.
|
| Fixed |
Fixed the handling of responses from the automated update server.
|
| Fixed |
Improved the automated update experience on local websites.
|
| Fixed |
Improved automated update download logging.
|
| Fixed |
Fixed the display of the automated update registration state on new installations.
|
| Fixed |
Corrected Joomla Update API status codes when automated updates are disabled.
|
| Fixed |
Version information for potential downgrades is now skipped by TUF.
|
| Fixed |
Converted the TUF update information URL to the legacy-compatible format.
|
| Fixed |
Database update scripts no longer insert duplicate records when run multiple times.
|
| Fixed |
Fixed the minimum required PHP version shown by the pre-update check.
|
| Fixed |
Fixed the user registration error notification.
|
| Fixed |
Cache subfolders are now included correctly in Clear Cache statistics.
|
| Fixed |
Optimised the Smart Search module.
|
| Fixed |
Fixed TinyMCE filters.
|
| Fixed |
Fixed the default TinyMCE upload folder.
|
| Fixed |
The Model\AfterCleanCacheEvent class is no longer forced for onContentCleanCache events.
|
| Fixed |
Fixed the Schema.org system plugin handling of the content deletion event.
|
| Fixed |
Reverted a backward-incompatible change in AbstractView::get().
|
| Fixed |
Fixed deprecated direct access to model state properties.
|
| Fixed |
Fixed deprecated direct model state access in the Content component ArchiveModel.
|
| Fixed |
Fixed menuType table instantiation by using the database from the dependency container.
|
| Fixed |
Fixed unlocked and potentially uninstalled core plugins on new installations and updates.
|
| Fixed |
Fixed custom field menu items in administrator presets.
|
| Fixed |
Fixed the administrator menu item for the custom fields list.
|
| Fixed |
Fixed the administrator menu item for listing all field groups.
|
| Fixed |
Automated update notification emails now use the correct language.
|
| Fixed |
Improved the update notification code.
|
| Fixed |
Fixed the alphabetical order of automated update language strings in the installer.
|
| Fixed |
Fixed the alphabetical order of language strings in the installation joomla.ini file.
|
| Fixed |
Fixed a deprecated build-script variable to allow Joomla to be built with Node.js 24.
|
| Fixed |
Improved accessibility in the Joomla statistics plugin.
|
| Fixed |
Fixed deprecated cookie setter method calls.
|
| Fixed |
Removed deprecated AbstractView::get() calls from layouts.
|
| Fixed |
Fixed language string naming conventions.
|
| Fixed |
Fixed typographical errors in actions and language strings.
|
| Fixed |
Fixed the custom logging configuration description.
|
| Fixed |
Moved the multilingual associations alert to a more appropriate location.
|
| Fixed |
Removed unused CSS from the articles module.
|
| Fixed |
Improved PHPStan configuration for deprecated database interface errors.
|
| Remove |
Removed deprecated Joomla core constants.
|
| Remove |
Removed LegacyPropertyManagementTrait calls from the User class.
|
| Remove |
Removed the deprecated dispatcher from plugin constructors.
|
| Remove |
Removed legacy HTTP response handling code.
|
| Remove |
Removed duplicate language strings.
|
| Remove |
Removed outdated FOF references from code comments.
|
| Remove |
Removed unnecessary boolean expressions.
|
| Note |
Joomla 5.4.0 is a minor release in the Joomla 5 series.
|
| Note |
Joomla 5.4.0 was released on 14 October 2025 together with Joomla 6.0.0.
|
| Note |
Joomla 5.4 is the bridge release for upgrading existing Joomla 5 websites to Joomla 6.
|
| Note |
Installed extensions and templates should be checked for compatibility before upgrading to Joomla 6.
|
| Note |
A complete backup of the website files and database is recommended before updating.
|
| Note |
The update should be tested on a copy of the production website before deployment.
|
| Note |
Websites running Joomla 4 should be updated from the latest Joomla 4.4 release.
|
| Security |
Fixed the CVE-2025-54476 XSS vulnerability caused by inadequate content filtering in the checkAttribute methods.
|
| Security |
Fixed the CVE-2025-54477 vulnerability that allowed user enumeration through the passkey authentication method.
|
| Addition |
Added aria-label support to Joomla dialog windows.
|
| Addition |
Added a check for required fields before using them in content versioning.
|
| Addition |
Transport classes now support arrays of HTTP header values.
|
| Change |
Updated a frontend language string.
|
| Change |
Updated the Joomla contribution documentation.
|
| Change |
Updated Composer and NPM dependencies to resolve reported security vulnerabilities.
|
| Change |
Updated TinyMCE from version 6.8.5 to version 6.8.6.
|
| Change |
Updated the joomla/filesystem package.
|
| Change |
Updated the Miscellaneous Information icon in the Contacts component.
|
| Change |
Cleaned up PHPDoc documentation.
|
| Change |
Updated joomla/oauth2 to version 3.0.2.
|
| Fixed |
Fixed the display of the database prefix.
|
| Fixed |
Fixed the calendar picker when week numbers are hidden and the 24-hour time format is used.
|
| Fixed |
Updated the tag router to restrict lossy matches to menu items configured for all tags.
|
| Fixed |
Fixed the Cassiopeia mobile menu collapse behaviour.
|
| Fixed |
Prevented an explicit session identifier from being set through GET request parameters.
|
| Fixed |
A restored article version is now correctly checked out to the current user.
|
| Fixed |
Fixed an undefined array key warning in table/nested.php.
|
| Fixed |
Unique banner aliases are now enforced during both creation and updating.
|
| Fixed |
A DELETE request for a non-existing item now returns HTTP status code 204.
|
| Fixed |
Fixed an infinite API loop when an unknown resource is requested while the website is offline.
|
| Fixed |
The correct HTTP status header is now set for XML and feed responses.
|
| Fixed |
Simplified the No Media Found code in the Media Manager.
|
| Fixed |
Fixed a copy-and-paste error in form field definitions.
|
| Fixed |
The TinyMCE update fixes incorrect cursor placement in the editor.
|
| Fixed |
The joomla/filesystem update fixes extension uploads when post_max_size is set to zero.
|
| Fixed |
Fixed caching in the Predefinedlist field getOptions method.
|
| Fixed |
Fixed a deploy_version typographical error in the Scheduled Tasks component.
|
| Fixed |
Test news feeds and their categories are now correctly cleaned after the first test-suite run.
|
| Fixed |
Added missing periods to interface sentences.
|
| Fixed |
Fixed the author of a tagged item not being updated when an article is saved.
|
| Fixed |
SchemaorgPrepareDateTrait now uses the correct ISO 8601 date format.
|
| Fixed |
The joomla/oauth2 update fixes case-insensitive OAuth2Client authentication.
|
| Fixed |
Fixed copyright notices being incorrectly removed from media assets during the Joomla build process.
|
| Remove |
Removed the obsolete .github/ISSUE_TEMPLATE.md file.
|
| Note |
Joomla 5.3.4 is a security and bug-fix release.
|
| Note |
Joomla 5.3.4 was released on 30 September 2025.
|
| Note |
CVE-2025-54476 has moderate severity and a moderate probability of exploitation.
|
| Note |
CVE-2025-54477 has low severity and a low probability of exploitation.
|
| Note |
Corresponding security fixes were also released in Joomla 4.4.14.
|
| Note |
A complete backup of the website files and database is recommended before updating.
|
| Note |
The update should be tested on a copy of the production website before deployment.
|
| Note |
When updating from a Joomla version earlier than 4.4, upgrade to Joomla 4.4 before updating to Joomla 5.
|
| Addition |
Added a system test for multi-factor authentication plugins using passkeys.
|
| Addition |
Added SCSS variables for interface styling.
|
| Addition |
Added an end-of-support notification for the Joomla version.
|
| Change |
Updated the PHPStan baseline configuration for Joomla 5.3.
|
| Change |
Updated terminology related to whitelists.
|
| Change |
Migrated AppVeyor tests to GitHub Actions.
|
| Change |
Cypress tests now use a generated API Bearer token.
|
| Change |
Updated test descriptions.
|
| Change |
Updated the debug plugin collector.
|
| Fixed |
Fixed the .bg-warning text colour in the installer to improve accessibility.
|
| Fixed |
Excluded phpstan-baseline.neon from Joomla distribution packages.
|
| Fixed |
Removed tests from the Drone configuration after their migration to GitHub Actions.
|
| Fixed |
Removed the remaining Phan analyser configuration.
|
| Fixed |
Cleaned up the configuration after moving to GitHub Actions.
|
| Fixed |
Prevented null ordering when restoring an item from version history.
|
| Fixed |
URLs containing an invalid controller name now return the correct HTTP 404 status.
|
| Fixed |
Fixed automatic language-change redirection when SEF URLs are enabled.
|
| Fixed |
Fixed an orphaned ellipsis in the articles module.
|
| Fixed |
Applied a background colour to Choices elements to ensure correct display.
|
| Fixed |
Fixed strict routing for frontend forms.
|
| Fixed |
Fixed invalid Schema.org breadcrumb JSON-LD output.
|
| Fixed |
Further fixed breadcrumb handling in the Schema.org system plugin.
|
| Note |
Joomla 5.3.3 is a bug-fix release in the Joomla 5.3 series.
|
| Note |
Joomla 5.3.3 was released on 19 August 2025.
|
| Note |
No separate Joomla core security fixes were announced for this release.
|
| Note |
A complete backup of the website files and database is recommended before updating.
|
| Note |
The update should be tested on a copy of the production website before deployment.
|
| Note |
When updating from a Joomla version earlier than 4.4, upgrade to Joomla 4.4 before updating to Joomla 5.
|
| Addition |
Added a button for showing and hiding the password in the login module.
|
| Addition |
Added a continuous integration workflow based on GitHub Actions.
|
| Change |
Optimised the loading of Smart Search plugin language files.
|
| Change |
Disabled OPcache in the SEF system test to improve test stability.
|
| Fixed |
Added a missing Joomla installer language string.
|
| Fixed |
Corrected comments in the source code.
|
| Fixed |
Fixed the creation of Zstandard packages by build.php on macOS.
|
| Fixed |
Fixed the display of duplicate queries in the debug plugin's dark mode.
|
| Fixed |
Improved the error page displayed during Joomla installation.
|
| Fixed |
Fixed a copy-and-paste error in a source-code comment.
|
| Fixed |
Fixed errors and improved the stability of the build.php script.
|
| Fixed |
Fixed the type used for custom form validators.
|
| Remove |
Removed the custom fields button from the custom module editing form.
|
| Note |
Joomla 5.3.2 is a bug-fix release in the Joomla 5.3 series.
|
| Note |
Joomla 5.3.2 was released on 8 July 2025.
|
| Note |
No separate Joomla core security fixes were announced for this release.
|
| Note |
A complete backup of the website files and database is recommended before updating.
|
| Note |
The update should be tested on a copy of the production website before deployment.
|
| Note |
When updating from a Joomla version earlier than 4.4, upgrade to Joomla 4.4 before updating to Joomla 5.
|
| Addition |
Added server error log checks to the system tests.
|
| Addition |
Added development mode information to the installer.
|
| Change |
Updated Joomla translations.
|
| Change |
Cleaned up the arguments of the File::upload() method.
|
| Change |
Updated the Danish TinyMCE translation.
|
| Change |
Updated embedded help URLs in the Jooa11y plugin language strings.
|
| Change |
Action log email notifications now use the website time zone.
|
| Change |
Updated joomla/database to version 3.4.2 for PHP 8.4 compatibility.
|
| Fixed |
Fixed hidden option prompts during command-line Joomla installation.
|
| Fixed |
Corrected grammatical errors in interface text.
|
| Fixed |
Fixed a typo in the replacement event name for onUserBeforeDataValidation.
|
| Fixed |
Fixed the positioning of the description in the search bar.
|
| Fixed |
Fixed the skip-to-link tooltip.
|
| Fixed |
Improved the empty-state information in the Media Manager.
|
| Fixed |
Fixed a PHP deprecation warning in the language switcher module.
|
| Fixed |
Fixed the incorrect sequence of the #__action_log_config table on PostgreSQL.
|
| Fixed |
The Media Action Resize plugin now respects individual width and height constraints.
|
| Fixed |
Fixed a mismatch between the default option and its label in the articles filter.
|
| Fixed |
The correct custom fields are now displayed when creating an article after filtering by multiple categories.
|
| Fixed |
Fixed missing values in enhanced select filters.
|
| Fixed |
Fixed the specified deprecation version of an application programming interface.
|
| Fixed |
Fixed the ordering of Content Security Policy directives in the HTTP Headers configuration.
|
| Fixed |
Corrected the deprecation text and added Registry support to StateBehaviorTrait.
|
| Fixed |
Fixed valid JSON handling in PostgreSQL queries.
|
| Fixed |
Fixed logical CSS properties in the installer for right-to-left languages.
|
| Fixed |
Fixed location updates when an update site already exists.
|
| Fixed |
Improved the spacing of long element lists in Smart Search.
|
| Fixed |
Limited the length of logged search terms to prevent a MysqliStatement error.
|
| Fixed |
Modified update site URLs are no longer displayed during update checks.
|
| Fixed |
The joomla/database update resolves PHP 8.4 deprecation warnings.
|
| Fixed |
Saving an article as a copy now correctly applies unpublishing or the configured workflow transition.
|
| Fixed |
Fixed Media Manager interface issues and improved accessibility.
|
| Fixed |
The phpass library now uses a timing-safe comparison method.
|
| Fixed |
Fixed calendar day names for right-to-left languages.
|
| Remove |
Removed the unused scss-transform.mjs build tool file.
|
| Note |
Joomla 5.3.1 is a bug-fix release in the Joomla 5.3 series.
|
| Note |
Joomla 5.3.1 was released on 27 May 2025.
|
| Note |
No separate Joomla core security fixes were announced for this release.
|
| Note |
A complete backup of the website files and database is recommended before updating.
|
| Note |
The update should be tested on a copy of the production website before deployment.
|
| Note |
When updating from a Joomla version earlier than 4.4, upgrade to Joomla 4.4 before updating to Joomla 5.
|
| Addition |
The email template view now provides access to template parameters for advanced customisation of outgoing messages.
|
| Addition |
A separate files folder for documents and other non-image files has been added to the Media Manager on new installations.
|
| Addition |
Added a complete execution history to Scheduled Tasks.
|
| Addition |
The Scheduled Tasks execution history records information required for monitoring and troubleshooting automated tasks.
|
| Addition |
Added an option to show or hide the article title in Read More links.
|
| Addition |
Added new methods for managing hidden and control fields in forms.
|
| Addition |
Added the BeforeUpdateSiteDownloadEvent event, which is triggered before an update site URL is downloaded.
|
| Addition |
Installer plugins can now modify an update site URL before it is used.
|
| Addition |
Added support for thumbnails for videos, PDF documents, audio files and other file types.
|
| Addition |
The com_ajax component now supports results implementing StringableInterface.
|
| Addition |
Added support for customised com_ajax responses through StringableInterface objects.
|
| Addition |
Added a guided tour introducing the new features in Joomla 5.3.
|
| Change |
Improved Joomla compatibility with PHP 8.4.
|
| Change |
Core plugins continue their transition to typed event classes.
|
| Change |
The WebAsset API is now recommended for loading scripts and stylesheets.
|
| Change |
The HTMLHelper::script() and HTMLHelper::stylesheet() methods are deprecated.
|
| Change |
Refactored component views to access their models directly.
|
| Change |
Removed the deprecated LegacyPropertyManagementTrait::setProperties() call from the Joomla core.
|
| Change |
The package installer now uses the Joomla Framework Filesystem package instead of the deprecated CMS filesystem.
|
| Change |
Improved the handling of tag aliases and SEF URLs.
|
| Change |
Improved detection of tainted and potentially invalid URLs.
|
| Change |
Updated Composer and NPM dependencies.
|
| Change |
Updated Joomla language files.
|
| Change |
Updated calendar language strings.
|
| Fixed |
Improved the organisation of documents and non-image files in the Media Manager.
|
| Fixed |
Fixed Contact component icons for screen-reader accessibility.
|
| Fixed |
Improved accessibility in the Contacts component interface.
|
| Fixed |
Fixed tag alias handling in the router.
|
| Fixed |
Fixed the handling of SEF URLs in Joomla routing.
|
| Fixed |
Fixed the handling of invalid URLs.
|
| Fixed |
Fixed extension file uploads through the package installer.
|
| Fixed |
Fixed unescaped slashes breaking markup inside script tags.
|
| Fixed |
Fixed PHP 8.4 compatibility issues involving deprecated parameter types.
|
| Fixed |
Fixed PHP 8.4 warnings involving implicitly nullable parameters.
|
| Fixed |
Updated restoration file creation to use the current createUpdateFile() method.
|
| Fixed |
Improved Scheduled Tasks execution logging.
|
| Fixed |
Improved the handling of HTML email templates.
|
| Fixed |
Fixed thumbnail handling for non-image files.
|
| Fixed |
Fixed Read More link behaviour when displaying the article title.
|
| Fixed |
Improved the accessibility of administrator controls and messages.
|
| Note |
Joomla 5.3.0 is a minor release in the Joomla 5 series.
|
| Note |
Joomla 5.3.0 was released on 15 April 2025.
|
| Note |
No separate Joomla core security fixes were announced for this release.
|
| Note |
The files folder is created automatically only on new Joomla 5.3 installations.
|
| Note |
On upgraded websites, the files folder and the corresponding Media Manager path must be configured manually.
|
| Note |
A complete backup of the website files and database is recommended before updating.
|
| Note |
The update should be tested on a copy of the production website before deployment.
|
| Note |
When updating from a Joomla version earlier than 4.4, upgrade to Joomla 4.4 before updating to Joomla 5.
|
| Security |
Fixed the CVE-2025-25226 SQL injection vulnerability in the quoteNameStr method of the Joomla Framework Database package.
|
| Security |
Fixed the CVE-2025-25227 vulnerability that allowed multi-factor authentication checks to be bypassed.
|
| Security |
The user activation token is now removed when the user's email address is changed.
|
| Change |
Updated Joomla translations.
|
| Change |
Updated the joomla/database package from version 3.2.1 to the secure version 3.4.0.
|
| Change |
Further updated the joomla/database package to version 3.4.1.
|
| Change |
Changed the development minor version number to Joomla 5.3.
|
| Note |
Joomla 5.2.6 is a security release in the Joomla 5.2 series.
|
| Note |
Joomla 5.2.6 was released on 8 April 2025 together with Joomla 4.4.13.
|
| Note |
Joomla 5.2.6 is the final release in the Joomla 5.2 series.
|
| Note |
CVE-2025-25226 has high potential impact, low severity and a low probability of exploitation.
|
| Note |
CVE-2025-25227 has high potential impact, moderate severity and a moderate probability of exploitation.
|
| Note |
The multi-factor authentication bypass affects Joomla versions from 5.0.0 through 5.2.5.
|
| Note |
The vulnerable quoteNameStr method is protected and is not directly used by the original database package classes.
|
| Note |
Third-party classes extending the database package may be affected if they use the quoteNameStr method.
|
| Note |
A complete backup of the website files and database is recommended before updating.
|
| Note |
The update should be tested on a copy of the production website before deployment.
|
| Note |
When updating from a Joomla version earlier than 4.4, upgrade to Joomla 4.4 before updating to Joomla 5.
|
| Security |
Fixed the CVE-2025-22213 vulnerability that allowed malicious executable PHP files to be uploaded through the Media Manager.
|
| Security |
Strengthened file upload validation for users with edit permissions in the Media Manager.
|
| Change |
Updated Joomla translations.
|
| Change |
Updated maximebf/debugbar to version 1.23.6.
|
| Change |
Updated the Cypress system test documentation.
|
| Fixed |
Added backup of the $_SERVER array through backupGlobals in unit tests.
|
| Fixed |
System tests no longer delete TUF metadata.
|
| Fixed |
Added a column alias to BannerTable and fixed a warning when saving a banner as a copy.
|
| Fixed |
Fixed a PHP warning caused by passing null to the trim() function.
|
| Fixed |
Added a border to the final Media Manager breadcrumb item.
|
| Fixed |
Disabled the backward compatibility plugin during system tests.
|
| Fixed |
Updated the Cypress menu system test.
|
| Fixed |
Fixed the Send Copy to Submitter feature in the Contacts component.
|
| Fixed |
Redesigned the carousel implementation to match its documentation.
|
| Fixed |
Fixed the frontend editing setting applied through the command-line interface after Joomla installation.
|
| Fixed |
Corrected the sudo command in the documentation.
|
| Fixed |
User sessions are now correctly cleaned after Cypress tests.
|
| Note |
Joomla 5.2.5 is a security and bug-fix release.
|
| Note |
Joomla 5.2.5 was released on 11 March 2025 together with Joomla 4.4.12.
|
| Note |
CVE-2025-22213 has critical potential impact, low severity and a low probability of exploitation.
|
| Note |
The vulnerability affects Joomla versions from 5.0.0 through 5.2.4.
|
| Note |
Exploiting the vulnerability requires a user account with edit permissions in the Media Manager.
|
| Note |
By default, this permission is granted to administrator user groups and frontend users with Editor permissions or higher.
|
| Note |
Successful exploitation could allow arbitrary PHP code to be executed on the server.
|
| Note |
A complete backup of the website files and database is recommended before updating.
|
| Note |
The update should be tested on a copy of the production website before deployment.
|
| Note |
When updating from a Joomla version earlier than 4.4, upgrade to Joomla 4.4 before updating to Joomla 5.
|
| Security |
Fixed an SQL injection vulnerability in the backend task list of the Scheduled Tasks component com_scheduler (CVE-2025-22207).
|
| Fixed |
Fixed namespace map creation when using PHP 8.4 (#44789).
|
| Fixed |
Fixed PHP warnings for the debuguser and debuggroup parameters (#44721).
|
| Fixed |
Fixed the handling of null values when updating a database row (#39607).
|
| Fixed |
Fixed the incorrect counting of files in the cache (#43986).
|
| Fixed |
Fixed permissions for manually running scheduled tasks (#36719).
|
| Fixed |
Restored support for numeric and CSV-formatted identifiers in the Tag Router (#44784).
|
| Fixed |
Updated the enshrined/svg-sanitize library to resolve SVG upload issues (#44746).
|
| Fixed |
Fixed an issue that prevented articles from being saved successfully on the frontend (#44680).
|
| Fixed |
Fixed downloading media files whose names contain spaces (#44745).
|
| Fixed |
Removed unnecessary query elements from Smart Search router URLs (#44055).
|
| Fixed |
Fixed conflicts between the Jooa11y plugin and page caching (#41956).
|
| Fixed |
Fixed an accessibility issue with the accordion role attribute (#40578).
|
| Fixed |
Removed unnecessary alternative text from menu items containing both an image and a title (#40675).
|
| Fixed |
Fixed the breadcrumbs colour in light and dark modes (#44212).
|
| Fixed |
Fixed email alternative text in the Contacts component (#44491).
|
| Fixed |
Fixed incorrect loading of external resources ending with a slash in the Web Asset Manager (#44774).
|
| Fixed |
Fixed multi-select behaviour in the Media Manager (#44747).
|
| Fixed |
Improved error handling when creating folders in the Media Manager (#39878).
|
| Fixed |
Fixed assets for the com_scheduler component on new Joomla installations (#44684).
|
| Fixed |
Fixed password reset functionality in the administrator interface (#44723).
|
| Fixed |
Fixed the Email Cloaking plugin for email addresses containing internationalised domain names (#39888).
|
| Fixed |
Changed root-path removal so that the path is removed only when it appears at the beginning of the string (#36685).
|
| Fixed |
Reverted the change that loaded the namespace from the cached manifest (#44755).
|
| Fixed |
Fixed duplicated CodeMirror asset entries (#44674).
|
| Security |
Fixed cross-site scripting vectors caused by improper input processing in module chrome layouts (CVE-2024-40747).
|
| Security |
Fixed an XSS vulnerability in the id attribute of menu lists caused by missing output escaping (CVE-2024-40748).
|
| Security |
Fixed an ACL access-control issue that allowed access to protected Joomla component views (CVE-2024-40749).
|
| Fixed |
Fixed button validation in the joomlaExtButtons TinyMCE plugin (#44507).
|
| Fixed |
Fixed validation of email addresses containing an apostrophe (#44527).
|
| Fixed |
Fixed the assignment of AssetTitle and AssetParentId values (#42493).
|
| Fixed |
Removed empty images and anchors from the Articles News, Articles Category and Articles modules (#42493, #44478, #44475).
|
| Fixed |
Removed an incorrect CSS class from the cancel link on the frontend verification-code page (#44473).
|
| Fixed |
Added multi-select support for checkbox fields (#44500).
|
| Fixed |
Fixed Smart Search suggestions when using a PostgreSQL database (#44384).
|
| Fixed |
Added an AllowDynamicProperties extension check to the pre-update checker (#44307).
|
| Fixed |
Fixed the handling of a nullable parameter in PHPCS (#44543).
|
| Fixed |
Fixed an extra closing curly brace in inline styles (#44532).
|
| Fixed |
Fixed a JavaScript error occurring when the toggleButton element is unavailable (#44555).
|
| Fixed |
Fixed case-insensitive plugin searches for languages using Unicode characters (#44525).
|
| Fixed |
Fixed a deprecation warning caused by incrementing a non-alphanumeric string (#44173).
|
| Fixed |
Prevented a newly assigned user password-reset requirement from being incorrectly cleared (#44519).
|
| Fixed |
Fixed incorrect button text generated by the back() method in CoreButtonsTrait (#44509).
|
| Fixed |
Updated the Tags Router to correctly detect pages that should return a 404 error (#44540).
|
| Fixed |
Added exception handling when retrieving a user in the Action Log model (#44358).
|
| Fixed |
Fixed the return type declaration in the IdentityAware trait (#44567).
|
| Fixed |
Updated the joomla/application library to version 3.0.3 to fix PHP deprecation warnings in the Web Client (#44585).
|
| Fixed |
Allowed multi-factor authentication to be completed before a required password reset (#44521).
|
| Fixed |
Fixed duplicate Action Log entries after a Joomla update (#44629).
|
| Fixed |
Fixed the “Invalid Response” error in the CLI extension:remove command when using the -n option (#44546).
|
| Fixed |
Fixed multi-factor authentication handling when a privacy consent is invalid (#44522).
|
| Fixed |
Added changelog URL refreshing when rebuilding the extension manifest cache (#44565).
|
| Security |
Fixed insecure 777 permissions assigned to core files and folders in new Joomla 5.2.0 installations; permissions were restored to 755 for folders and 644 for files (#44379).
|
| Fixed |
Fixed broken URLs in emails using mail template layouts (#44378).
|
| Fixed |
Added wrapping for long text to prevent content from extending beyond the viewport (#44441).
|
| Fixed |
Fixed dark-mode display issues in the default Atum administrator template (#44211).
|
| Fixed |
Fixed an error occurring when checked-out items were moved to the trash (#44392).
|
| Fixed |
Fixed the filter_category_id parameter when creating an administrator menu item (#44305).
|
| Fixed |
Fixed a blank screen on the Guided Tours steps page after a user session timeout (#44375).
|
| Fixed |
Fixed an infinite loop in multilingual content associations (#44360).
|
| Fixed |
Improved error handling during extension updates (#43321).
|
| Security |
Fixed insecure file and folder permissions in new installation packages: the incorrect 777 permissions were replaced with 755 for folders and 644 for files.
|
| Addition |
Added an automatically launched “What’s New” Guided Tour to introduce users to the features of the new Joomla version (#43966).
|
| Addition |
Added support for multiple language-specific home pages within a single menu (#43862).
|
| Addition |
Added a new universal Articles module with flexible content filtering and display options (#43738).
|
| Addition |
Added support for customisable HTML layouts for Joomla system emails (#43829).
|
| Addition |
Added the ability to create and save categories directly while working with menu items (#43840).
|
| Addition |
Added conditional display of form fields based on global configuration values (#43842).
|
| Addition |
Added a CSS class selector for styling links in the TinyMCE editor (#43260).
|
| Addition |
Expanded the range of special characters allowed in passwords (#43484).
|
| Addition |
Added event classes for more convenient and modern plugin development (#43639).
|
| Change |
Improved strict routing and SEF URL handling to reduce duplicate content and unnecessary redirects (#43432).
|
| Change |
Changed the Media Manager to automatically select the most recently uploaded file (#43823).
|
| Change |
Improved image thumbnail compression to reduce file sizes and improve page-loading performance (#43282).
|
| Change |
Added compatibility with PHP 8.4 (#43323).
|
| Change |
Added a warning to the Scheduled Tasks screen when a task fails to execute (#43491).
|
| Fixed |
Fixed paginated page links in Smart Search and the Articles Archive following security-related changes introduced in Joomla 5.1.3 (#43953, #43967).
|
| Fixed |
Fixed filtering of the option, format, view and layout parameters in caching and pagination (#43983).
|
| Fixed |
Updated the support dates for PHP versions (#43984).
|
| Fixed |
Added escaping of unsafe tags in mail copies sent to users and administrator notifications while preserving custom email fields (#43981).
|
| Fixed |
Updated Joomla language files (#43923, #43980).
|
| Security |
Fixed XSS vectors in the OutputFilter::strip* methods caused by improper input handling (CVE-2024-40743).
|
| Security |
Fixed improper ACL checks in the administrator profile view that allowed backend users to overwrite their usernames when this action was prohibited (CVE-2024-27187).
|
| Security |
Fixed XSS vulnerabilities in HTML mail templates caused by missing data escaping (CVE-2024-27186).
|
| Security |
Fixed cache-poisoning vectors caused by arbitrary parameters being included in pagination links (CVE-2024-27185).
|
| Security |
Improved internal URL validation to prevent redirects to external resources (CVE-2024-27184).
|
| Fixed |
Updated the TinyMCE editor to version 6.8.4 (#43808).
|
| Fixed |
Fixed attachment handling in the Mail class (#43828).
|
| Fixed |
Added removal of Schema.org data after the associated item is deleted (#43839).
|
| Fixed |
Removed the testing update channel from the command-line interface (#43764).
|
| Fixed |
Fixed frontend language handling on multilingual sites without the Backward Compatibility plugin enabled (#43791).
|
| Fixed |
Removed unused variables (#43763).
|
| Fixed |
Added the missing security token to the ModalSelect field (#43745).
|
| Fixed |
Fixed the Secure attribute for user session cookies (#43882).
|
| Fixed |
Fixed data encoding in popup links (#43874).
|
| Fixed |
Fixed header translation for modal selection fields (#43878).
|
| Fixed |
Fixed a JavaScript error affecting radio buttons rendered in a sublayout (#43804).
|
| Fixed |
Fixed the handling of relative URLs in private messages (#43897).
|
| Security |
Fixed an XSS vulnerability in the accessible media selection field caused by inadequate input validation (CVE-2024-21729).
|
| Security |
Fixed a Self-XSS vulnerability in the Fancy Select list field layout caused by improper input escaping (CVE-2024-21730).
|
| Security |
Fixed an XSS vulnerability in the StringHelper::truncate method caused by improper input handling (CVE-2024-21731).
|
| Security |
Fixed XSS vulnerabilities in the Wrapper component and module caused by inadequate input validation (CVE-2024-26279).
|
| Security |
Fixed an XSS vulnerability in the default custom-field value handled by the com_fields component (CVE-2024-26278).
|
| Fixed |
Added an update-channel reset to the Joomla Update component (#43717).
|
| Fixed |
Changed Schema.org data to load only in supported forms (#42825).
|
| Fixed |
Changed the created_by field to use a value of 0 when no author is specified (#43752).
|
| Fixed |
Restored support for embedding PDF documents (#43716).
|
| Fixed |
Changed the redirect URL from the Location header to be correctly handled as a string instead of an array (#43734).
|
| Fixed |
Fixed radio buttons and checkboxes in nested Subform fields (#43660).
|
| Fixed |
Added support for the onchange attribute to the Modal Select form field (#43618).
|
| Fixed |
Added resetting of cached layout data when running the form field setup() method (#43562).
|
| Fixed |
Fixed comment syntax in the update SQL script that adds TUF support (#43306).
|
| Fixed |
Fixed the dark-mode selector in the administrator template (#43310).
|
| Fixed |
Fixed the light and dark mode switch in the administrator interface (#43454).
|
| Fixed |
Corrected the link to the official Joomla forum (#43414).
|
| Fixed |
Corrected the message type used for the Redirect plugin state (#43402).
|
| Fixed |
Fixed the TinyMCE media button when editing articles on the frontend (#43376).
|
| Fixed |
Fixed link insertion using the TinyMCE media button (#43374).
|
| Fixed |
Fixed documentation links in empty-state views (#43371).
|
| Fixed |
Fixed a PHP deprecation warning caused by passing null to PDO::quote() (#43288).
|
| Fixed |
Added backward compatibility for older Bootstrap modals used by plugins and modules (#43291).
|
| Fixed |
Fixed calendar field value handling (#43234).
|
| Fixed |
Restored compatibility with legacy editor-xtd plugins returning an array of buttons (#43129).
|
| Fixed |
Fixed JavaScript syntax highlighting in the CodeMirror 6 editor (#43114).
|
| Fixed |
Fixed an incorrect value for the new trailingslash parameter in the system SEF plugin (#43292).
|
| Fixed |
Added missing entries to the help index (#43251).
|
| Fixed |
Fixed the help index build tool helpTOC.php (#43250).
|
| Fixed |
Fixed switching between duplicate menus in the administrator menu (#43308).
|
| Fixed |
Updated deprecation information in the Joomla changelog (#43219).
|
| Fixed |
Fixed PHP warnings occurring when new custom fields were created (#42956).
|
| Fixed |
Fixed handling of the administrator template brand parameter (#41458).
|
| Fixed |
Updated the documentation link (#43370).
|
| Fixed |
Added proper support for AVIF and WebP images (#43295).
|
| Fixed |
Improved exception handling when generating thumbnails in the Media Manager (#43468).
|
| Fixed |
Fixed an issue that could cause the extension compatibility check before a Joomla update to run indefinitely (#43410).
|
| Fixed |
Changed the redirect URL from the Location header in CurlTransport to be correctly handled as a string instead of an array (#42769).
|
| Fixed |
Updated the documentation to include MariaDB and remove the obsolete Microsoft SQL Server reference (#43368).
|
| Fixed |
Added inline help for the Activate Advanced Mode button in the Redirect component (#43435).
|
| Fixed |
Fixed date and time conversion when no current user is available (#43521).
|
| Addition |
Implemented the secure TUF update mechanism (#42799).
|
| Addition |
Added a light and dark mode switch to the administrator interface (#42221).
|
| Addition |
Added a Welcome Guided Tour for new users (#41659).
|
| Addition |
Added trailing-slash URL behaviour to the system SEF plugin (#42702).
|
| Addition |
Added a notice to the Global Configuration about additional options available in the system SEF plugin (#42832).
|
| Addition |
Added required-field handling and support for checkboxes, radio buttons and selection lists as Guided Tour targets (#40994).
|
| Addition |
Added regular-expression validation for form fields (#42657).
|
| Addition |
Added the Generic type to Schema.org integration (#42699).
|
| Addition |
Added the Article type to Schema.org integration (#42402).
|
| Addition |
Added the ability to manipulate custom-field forms in the same way as category forms (#42510).
|
| Addition |
Added a main region and improved module support on the Cassiopeia error page (#42719).
|
| Addition |
Added a “New Article” button to the blog view (#39506).
|
| Addition |
Added support for subcategory levels in the Contacts category view (#41618).
|
| Addition |
Added a command-line command for managing Joomla core update channels (#42597).
|
| Addition |
Added the update:extension:check command for checking extension updates from the command line (#42844).
|
| Addition |
Added a command-line command for updating the database structure (#42568).
|
| Addition |
Added toolbar buttons on the language installation page for direct access to language management views (#42610).
|
| Addition |
Added buttons for moving Subform rows up and down (#42334).
|
| Addition |
Added a rebuild button to the Tags component (#42586).
|
| Addition |
Added a global Form Layout option for custom fields (#37320).
|
| Addition |
Added SVG image support to the Banners module (#41854).
|
| Change |
Significantly improved the administrator interface in dark mode (#42986).
|
| Change |
Improved SEF URL behaviour for addresses containing index.php (#42704).
|
| Change |
Updated the Jooa11y Accessibility Checker plugin to a newer version of Sa11y (#42780).
|
| Change |
Replaced Bootstrap modals with the new administrator dialog component for scheduled tasks, extension changelogs, batch processing, plugins, modules, media, categories, contacts, news feeds and content history (#42746, #42453, #42355, #42447, #42423, #42288, #42293, #42326, #42327, #42328, #42454).
|
| Change |
Updated Font Awesome to version 6.5.1 (#42721).
|
| Change |
Updated the TinyMCE editor to version 6.8.3 (#42930).
|
| Change |
Changed the value column in the #__fields_values table from TEXT to MEDIUMTEXT (#42606).
|
| Change |
Renamed and improved the core:update:check command (#42594).
|
| Change |
Improved the output of the Joomla core update command (#42601).
|
| Change |
Converted major administrator and system modules to use Joomla service providers (#42214, #42845, #42866, #42853, #42852, #42990, #42838, #42827, #42801, #42781, #42792, #42814, #42886, #42883, #42877, #42735, #42215, #42898, #42899, #42910, #42929, #42987).
|
| Change |
Improved the display of long template descriptions (#42651).
|
| Change |
Improved the removal of child extensions installed as part of a package (#42607).
|
| Change |
Improved data filtering in API web services (#42519).
|
| Change |
Improved API web-service event classes (#42092).
|
| Change |
Changed the Media Manager to use a generic icon for documents (#42527).
|
| Change |
Rewrote the multilingual associations component com_associations in vanilla JavaScript (#42771).
|
| Change |
Added event classes for Page Cache plugin events (#41965).
|
| Change |
Changed batch processing to load the appropriate plugin group when tasks are executed (#39013).
|
| Change |
Added several JavaScript improvements (#42756, #42755, #42776, #42784).
|
| Change |
Updated the automated code-style fixing tool (#42603).
|
| Fixed |
Improved error handling when writing files during a Joomla update (#41096).
|
| Fixed |
Removed potentially unsafe attributes from images in HTML emails (#42448).
|
| Fixed |
Fixed Action Log notification emails containing HTML links (#40033).
|
| Security |
Fixed insufficient termination of existing user sessions after multi-factor authentication methods were changed (CVE-2024-21722).
|
| Security |
Fixed an open redirect caused by inadequate URL parsing in the Joomla installation application (CVE-2024-21723).
|
| Security |
Fixed XSS vulnerabilities in media selection fields caused by inadequate input validation (CVE-2024-21724).
|
| Security |
Fixed XSS vulnerabilities caused by inadequate escaping of email addresses in various Joomla components (CVE-2024-21725).
|
| Security |
Improved content filtering to fix XSS vulnerabilities in various Joomla components (CVE-2024-21726).
|
| Fixed |
Fixed the CodeMirror editor background colour in fullscreen mode (#42683).
|
| Fixed |
Updated Joomla language files (#42669).
|
| Fixed |
Added the display of system messages on the error page (#42652).
|
| Fixed |
Reverted an incorrect minimum environment version change in the Drone CI configuration (#42583).
|
| Fixed |
Fixed the function parameter being lost during a redirect (#42315).
|
| Fixed |
Updated the phpseclib library to version 3.0.34 (#42469).
|
| Fixed |
Improved colour contrast in the Media Manager file list (#42544).
|
| Fixed |
Harmonised the naming of scheduled task types (#42574).
|
| Fixed |
Added a proper error message when installing a package containing no extensions (#42337).
|
| Fixed |
Added missing language strings to improve interface accessibility (#42387).
|
| Fixed |
Fixed a PHP deprecation warning caused by the creation of dynamic properties (#42429).
|
| Fixed |
Fixed PHP 8 deprecation warnings when installing Joomla from the command line (#42451).
|
| Fixed |
Fixed a deprecation warning caused by creating the clientId property during Joomla CLI installation (#42436).
|
| Security |
Fixed the exposure of environment variables through manipulation of the language-file parsing process (CVE-2023-40626).
|
| Fixed |
Fixed SVG file display in the Media Manager list view (#42119).
|
| Fixed |
Added a warning to custom-field settings about possible information disclosure through Smart Search indexing (#42111).
|
| Fixed |
Fixed a PHP notice occurring during tag replacement in mail templates (#41679).
|
| Fixed |
Improved the private-message view in the com_messages component (#42135).
|
| Fixed |
Fixed Joomla installation from the command line (#42116).
|
| Addition |
Added Schema.org integration with automatic structured data generation for the organisation and site name.
|
| Addition |
Added support for AVIF images to the Media Manager.
|
| Addition |
Added JavaScript import-map support to the Web Asset Manager.
|
| Addition |
Added the ability to exclude archived articles from Smart Search indexing.
|
| Addition |
Added the ability to arrange menus using custom sorting.
|
| Addition |
Added a new Joomla modal component for item selection buttons.
|
| Addition |
Added the Backward Compatibility plugin to support Joomla 4 extensions using deprecated APIs.
|
| Change |
Significantly improved dark mode in both the frontend and administrator interfaces.
|
| Change |
Improved caching of CSS and JavaScript web assets.
|
| Change |
Optimised the Joomla source code to improve performance.
|
| Change |
Improved compatibility with PHP 8 and resolved PHP 8.2 deprecation warnings.
|
| Change |
Updated the Bootstrap framework to version 5.3.2.
|
| Change |
Updated the TinyMCE editor to version 6.7 with additional image-alignment features.
|
| Change |
Updated the CodeMirror source-code editor to version 6.
|
| Change |
Updated the Font Awesome icon library to version 6.4.
|
| Change |
Updated the WebAuthn authentication library.
|
| Change |
Moved several system scheduled tasks to dedicated scheduler plugins.
|
| Change |
Migrated Joomla core events to dedicated event classes.
|
| Change |
Refactored internal code to use modern application programming interfaces.
|
| Change |
Raised the minimum system requirements to PHP 8.1, MySQL 8.0.13, MariaDB 10.4 and PostgreSQL 12.
|
| Remove |
Removed non-functional CAPTCHA reCAPTCHA plugins.
|
| Remove |
Removed support for the obsolete ECMAScript 5 JavaScript standard.
|
| Remove |
Removed deprecated APIs and unused code from previous Joomla versions.
|