5.4.7
| Security |
[20260701] Fixed incorrect access control in com_media web service endpoints.
|
| Security |
[20260702] Fixed incorrect access control when downloading VCF files from com_contact.
|
| Security |
[20260703] Fixed an XSS vulnerability in MFA method management.
|
| Security |
[20260704] Fixed an XSS vulnerability in com_templates.
|
| Security |
[20260705] Fixed XSS vulnerabilities in various modalreturn layouts.
|
| Security |
[20260706] Fixed an XSS vulnerability in com_installer.
|
| Security |
[20260707] Fixed an XSS vulnerability in the generic image output layout.
|
| Security |
[20260708] Fixed an XSS vulnerability involving language overrides.
|
| Security |
[20260709] Fixed incorrect access control in com_workflow.
|
| Security |
[20260710] Fixed incorrect access control in com_modules.
|
| Security |
[20260711] Fixed incorrect access control in com_privacy web service endpoints.
|
| Security |
[20260712] Fixed incorrect access control in com_fields web service endpoints.
|
| Fixed |
#47836 — Updated the phpstan-baseline.neon file.
|
| Fixed |
#47203 — Added support for updating extensions from the command-line interface.
|
| Fixed |
#47603 — Mail templates are now loaded using the language assigned to the template.
|
| Fixed |
#47734 — The installer no longer proceeds to database setup when the password contains leading or trailing spaces.
|
| Fixed |
#47837 — Added a system test for the Media Manager search path traversal issue.
|
| Fixed |
#47748 — Added support for creating a user access level through a POST web service request.
|
| Fixed |
#47752 — Fixed author display when using article-specific settings.
|
| Fixed |
#47771 — Updated NPM dependencies.
|
| Fixed |
#47774 — Front-end filters are now activated only when the filter button is available.
|
| Fixed |
#47800 — Preserved the text of the zero-value option in selection fields.
|
| Fixed |
#47825 — Updated the Typos GitHub Action to version 1.46.3.
|
| Fixed |
#47827 — Updated the actions-setup-mysql GitHub Action to version 1.51.0.
|
| Fixed |
#47852 — Fixed a regression introduced by the security fix in Joomla 5.4.6 and 6.1.1.
|
| Fixed |
#47855 — Fixed modal pagination breaking navigation.
|
| Fixed |
#47751 — Added support for updating a user access level without supplying rules through a PATCH request.
|
| Fixed |
#47847 — Updated symfony/yaml to version 6.4.41 to fix three security vulnerabilities.
|
| Fixed |
#47830 — Updated the github-script GitHub Action to version 9.0.0.
|
| Fixed |
#47826 — Updated the setup-php GitHub Action to version 2.37.1.
|
| Fixed |
#47882 — FIDO metadata is now cached in the build directory and preserved during builds.
|
| Fixed |
#47865 — Fixed the Joomla success alert.
|
| Fixed |
#47637 — The manifest path is now compiled from the extension root directory.
|
| Fixed |
#47895 — Added FIDO, Composer and NPM caching to the Drone configuration.
|
| Fixed |
#47548 — Fixed CodeMirror editor duplication.
|
| Fixed |
#47483 — Fixed the aria-expanded attribute check.
|
| Fixed |
#47869 — Added an email-sending test for the contact form.
|
| Fixed |
#47896 — Reordered and updated Text::script() calls for media field labels.
|
| Fixed |
#47917 — Reordered and updated Text::script() calls in the Joomla Update component.
|
| Fixed |
#47931 — Fixed the documentation block for the input type.
|
| Fixed |
#47819 — Fixed submitting the com_contact form through web services when custom reply is enabled.
|
| Fixed |
#47964 — A new installer instance is now always used when installing discovered extensions.
|
| Fixed |
#47978 — Fixed a potential issue when updating multiple extensions.
|
| Fixed |
#47985 — Cookie authentication now loads the language file so that log messages can be translated.
|
| Fixed |
#47986 — Fixed the username placeholder in failed cookie-login log messages.
|
| Fixed |
#47972 — The correct function is now used to retrieve a message from an exception.
|
| Fixed |
#47916 — Fixed the Indexer Debugger constructor and added an error message when no ID or an invalid ID is supplied.
|
| Fixed |
#44914 — Fixed the contact and news feed serializers.
|
| Fixed |
#47818 — Added integration tests for the config:get CLI command.
|
| Fixed |
#47993 — Fixed filtering by unactivated user status in com_users.
|
| Fixed |
#47763 — Added a system test for the Scheduled Tasks console command.
|
| Fixed |
#47951 — The “Running Since” tooltip on the Scheduled Tasks page now uses the locked property instead of last_execution.
|
| Fixed |
#48018 — Updated Composer dependencies.
|
| Fixed |
#48024 — Updated NPM dependencies.
|
| Fixed |
#47936 — Added code style fixes and updated the PHPStan configuration.
|
| Note |
Joomla 5.4.7 is a security and bugfix release.
|
| Note |
Installing Joomla 5.4.7 as soon as possible is strongly recommended.
|
| Note |
Joomla 5.4.7 was released together with Joomla 6.1.2.
|
| Note |
Joomla 5.4.7 has a known issue where article-specific parameters may be ignored when an article is displayed through a category layout or a single-article menu item.
|
| Note |
An installable Joomla_5_4_7_and_6_1_2_ArticleModel_Hotfix1.zip package was released as a temporary fix.
|
| Note |
The permanent fix for the known issue was included in Joomla 5.4.8.
|
| Note |
Creating a website backup and checking the compatibility of installed extensions and templates is recommended before updating.
|