| Security |
[20260501] Fixed an XSS vulnerability in feed modules.
|
| Security |
[20260502] Fixed an XSS vulnerability in com_associations.
|
| Security |
[20260503] Fixed an XSS vulnerability in com_contenthistory.
|
| Security |
[20260504] Fixed an XSS vulnerability in Read More links.
|
| Security |
[20260505] Fixed a CSRF vulnerability in the user activation endpoint.
|
| Security |
[20260506] Fixed an authenticated blind SQL injection vulnerability in com_finder.
|
| Security |
[20260507] Fixed an authenticated blind SQL injection vulnerability in com_tags.
|
| Security |
[20260508] Fixed an improper access check in com_config web service endpoints.
|
| Security |
[20260509] Fixed a local file inclusion vulnerability in the HTMLView layout parameter.
|
| Security |
[20260510] Fixed a path traversal vulnerability in a com_media web service endpoint.
|
| Security |
[20260511] Fixed an MFA authentication bypass vulnerability.
|
| Security |
[20260512] Fixed an additional MFA authentication bypass vulnerability.
|
| Security |
[20260513] Fixed privilege escalation through the com_users batch task.
|
| Security |
[20260514] Fixed privilege escalation through com_users web service endpoints.
|
| Security |
[20260515] Fixed incorrect access control in sample data plugins.
|
| Security |
[20260516] Fixed incorrect access control in com_scheduler.
|
| Security |
[20260517] Fixed incorrect cache key construction for InputFilter objects.
|
| Security |
[20260518] Prevented transport encryption downgrade for username and password reset links.
|
| Security |
[20260519] Improved content filtering in the Joomla Framework checkAttribute filter code.
|
| Security |
[20260520] Improved content filtering in the Joomla Framework cleanAttributes filter code.
|
| Fixed |
#45145 — Fixed an incorrect error being displayed when renaming a file.
|
| Fixed |
#47307 — Fixed an accessibility issue with the Back-to-Top link.
|
| Fixed |
#47413 — Prevented a misleading save failure message when a mail notification fails.
|
| Fixed |
#47423 — Improved substring searching in Fancy Select fields.
|
| Fixed |
#47476 — Added the missing page parameter to the content event arguments in the Articles module.
|
| Fixed |
#47480 — Fixed an incorrect bind parameter key in the Category HTML helper.
|
| Fixed |
#47533 — Fixed an ECB mode validation typo in the OpenSSL AES adapter and updated the related documentation.
|
| Fixed |
#47546 — Preselected values are now displayed in Fancy Select fields.
|
| Fixed |
#47557 — Added handling for Punycode conversion exceptions to prevent crashes.
|
| Fixed |
#47565 — Fixed the handling of attachments supplied as a list of objects.
|
| Fixed |
#47574 — Corrected the background colour of elements with the is-selected class in dark mode.
|
| Fixed |
#47586 — Fixed category custom fields loading.
|
| Fixed |
#47590 — Fixed deletion of the update archive after an automatic Joomla core update.
|
| Fixed |
#47599 — Made the default collapsible menu overridable.
|
| Fixed |
#47601 — Fixed the Debug plugin crashing when Query Explain is used during AJAX requests.
|
| Fixed |
#47602 — Added AJAX error message scripts to improve feedback when editing menu items.
|
| Fixed |
#47604 — Fixed HTML tag replacement when converting an HTML email body to plain text.
|
| Fixed |
#47616 — Added a translation format so that the last automatic update check time is displayed correctly.
|
| Fixed |
#47617 — Added the missing closing angle bracket for a fieldset in the repeatable layout.
|
| Fixed |
#47640 — Fixed publishing fields not being displayed in the article creation form.
|
| Fixed |
#47642 — Corrected aria-posinset values so that they start from 1.
|
| Fixed |
#47644 — Added a missing table column header to improve accessibility.
|
| Fixed |
#47646 — Prevented a fatal error when the getTemplate method is called in an API application.
|
| Fixed |
#47650 — Fixed RTL toolbar dropdown alignment in the administrator interface.
|
| Fixed |
#47653 — Improved the accessibility of language installation information.
|
| Fixed |
#47659 — Fixed the default value of the save_history parameter in com_modules.
|
| Fixed |
#47661 — Fixed TinyMCE menu bar visibility in fullscreen mode.
|
| Fixed |
#47686 — The clear button now correctly resets calendar filters.
|
| Fixed |
#47694 — Version history is now displayed in FormView only when version history is supported.
|
| Fixed |
#47697 — Moved mod_menu language loading until after client_id resolution in ItemsModel.
|
| Fixed |
#47715 — Corrected the z-index of selection fields in the Cassiopeia template.
|
| Fixed |
#47729 — Fixed the notification dismiss button in light mode.
|
| Fixed |
#47731 — Child template name validation now checks only templates of the appropriate type.
|
| Fixed |
#47735 — Fixed article version preview for users with Author permissions.
|
| Fixed |
#47775 — Added a colour variable for disabled Choices.js fields.
|
| Note |
Joomla 6.1.1 is a security release. Installing the update as soon as possible is strongly recommended.
|
| Note |
All bug fixes included in Joomla 5.4.6 have also been merged into Joomla 6.1.1.
|