5.4.8
| Security |
[20260801] Fixed response header injection in download views.
|
| Security |
[20260802] Fixed improper CORS origin validation.
|
| Security |
[20260803] Fixed inconsistent ACL checks for mutating web service endpoints.
|
| Security |
[20260804] Fixed improper ACL checks for custom fields web service endpoints.
|
| Security |
[20260805] Fixed improper ACL checks for category web service endpoints.
|
| Security |
[20260806] Fixed an XSS vulnerability in Schema.org output.
|
| Security |
[20260807] Fixed a multi-factor authentication (MFA) bypass vulnerability.
|
| Security |
[20260808] Fixed improper ACL checks for batch copy actions.
|
| Security |
[20260809] Fixed improper ACL checks when injecting Schema.org contact data.
|
| Security |
[20260810] Prevented unrestricted uploads of SHTML files.
|
| Fixed |
#46805 — Added an ACL check when displaying the link to the user edit form.
|
| Fixed |
#47202 — Fixed menu item editing redirecting to the list view without preserving the original filters.
|
| Fixed |
#47626 — Implemented date and time validation when input values are changed.
|
| Fixed |
#47766 — Improved error messages for update server errors.
|
| Fixed |
#47780 — Corrected the data-nested attribute for nested components, including categories, menu items and modules.
|
| Fixed |
#47886 — Fixed Global Check-in treating rows with checked_out=0 as requiring check-in.
|
| Fixed |
#48060 — Fixed article-specific options being ignored in the article view.
|
| Fixed |
#48074 — Prevented a DivisionByZeroError in ListModel when list.limit is set to 0.
|
| Fixed |
#48080 — Updated joomla/filesystem from version 3.2.0 to 3.3.0 and partially backported the update upload fix from the Joomla 6.1 branch.
|
| Fixed |
#48088 — Fixed the duplicate “No results” message in the list of installed languages.
|
| Fixed |
#48091 — The Action Log plugin now creates only one entry when blocking or unblocking a user.
|
| Fixed |
#48116 — Cleaned up FilePatcher remnants left by the Joomla 5.4.7 core update hotfix.
|
| Fixed |
#48163 — Fixed a division-by-zero error in subforms.
|
| Fixed |
#48171 — Added path traversal checks to the Templates component.
|
| Fixed |
#48173 — Standardized the memory_table_limit option in Smart Search.
|
| Fixed |
#48184 — Fixed a typo in the Awesomplete example.
|
| Fixed |
#48185 — Fixed indentation in the tree selection field.
|
| Fixed |
#48212 — Fixed normalization of the days_of_week parameter.
|
| Fixed |
#48216 — Fixed the Site Offline functionality.
|
| Fixed |
#48247 — Reverted an invalid path check change in the Templates component.
|
| Note |
Joomla 5.4.8 is a security and bugfix release.
|
| Note |
Installing Joomla 5.4.8 as soon as possible is strongly recommended.
|
| Note |
Joomla 5.4.8 was released together with Joomla 6.1.3.
|
| Note |
Creating a website backup and checking the compatibility of installed extensions and templates is recommended before updating.
|