5.3.4
| Security |
Fixed the CVE-2025-54476 XSS vulnerability caused by inadequate content filtering in the checkAttribute methods.
|
| Security |
Fixed the CVE-2025-54477 vulnerability that allowed user enumeration through the passkey authentication method.
|
| Addition |
Added aria-label support to Joomla dialog windows.
|
| Addition |
Added a check for required fields before using them in content versioning.
|
| Addition |
Transport classes now support arrays of HTTP header values.
|
| Change |
Updated a frontend language string.
|
| Change |
Updated the Joomla contribution documentation.
|
| Change |
Updated Composer and NPM dependencies to resolve reported security vulnerabilities.
|
| Change |
Updated TinyMCE from version 6.8.5 to version 6.8.6.
|
| Change |
Updated the joomla/filesystem package.
|
| Change |
Updated the Miscellaneous Information icon in the Contacts component.
|
| Change |
Cleaned up PHPDoc documentation.
|
| Change |
Updated joomla/oauth2 to version 3.0.2.
|
| Fixed |
Fixed the display of the database prefix.
|
| Fixed |
Fixed the calendar picker when week numbers are hidden and the 24-hour time format is used.
|
| Fixed |
Updated the tag router to restrict lossy matches to menu items configured for all tags.
|
| Fixed |
Fixed the Cassiopeia mobile menu collapse behaviour.
|
| Fixed |
Prevented an explicit session identifier from being set through GET request parameters.
|
| Fixed |
A restored article version is now correctly checked out to the current user.
|
| Fixed |
Fixed an undefined array key warning in table/nested.php.
|
| Fixed |
Unique banner aliases are now enforced during both creation and updating.
|
| Fixed |
A DELETE request for a non-existing item now returns HTTP status code 204.
|
| Fixed |
Fixed an infinite API loop when an unknown resource is requested while the website is offline.
|
| Fixed |
The correct HTTP status header is now set for XML and feed responses.
|
| Fixed |
Simplified the No Media Found code in the Media Manager.
|
| Fixed |
Fixed a copy-and-paste error in form field definitions.
|
| Fixed |
The TinyMCE update fixes incorrect cursor placement in the editor.
|
| Fixed |
The joomla/filesystem update fixes extension uploads when post_max_size is set to zero.
|
| Fixed |
Fixed caching in the Predefinedlist field getOptions method.
|
| Fixed |
Fixed a deploy_version typographical error in the Scheduled Tasks component.
|
| Fixed |
Test news feeds and their categories are now correctly cleaned after the first test-suite run.
|
| Fixed |
Added missing periods to interface sentences.
|
| Fixed |
Fixed the author of a tagged item not being updated when an article is saved.
|
| Fixed |
SchemaorgPrepareDateTrait now uses the correct ISO 8601 date format.
|
| Fixed |
The joomla/oauth2 update fixes case-insensitive OAuth2Client authentication.
|
| Fixed |
Fixed copyright notices being incorrectly removed from media assets during the Joomla build process.
|
| Remove |
Removed the obsolete .github/ISSUE_TEMPLATE.md file.
|
| Note |
Joomla 5.3.4 is a security and bug-fix release.
|
| Note |
Joomla 5.3.4 was released on 30 September 2025.
|
| Note |
CVE-2025-54476 has moderate severity and a moderate probability of exploitation.
|
| Note |
CVE-2025-54477 has low severity and a low probability of exploitation.
|
| Note |
Corresponding security fixes were also released in Joomla 4.4.14.
|
| Note |
A complete backup of the website files and database is recommended before updating.
|
| Note |
The update should be tested on a copy of the production website before deployment.
|
| Note |
When updating from a Joomla version earlier than 4.4, upgrade to Joomla 4.4 before updating to Joomla 5.
|