Joomla Hub


Channel's geo and language: World, English
Category: Technologies


News of Joomla community: latest updates, useful tutorials, new extensions and templates, upcoming events and all that makes #Joomla heart beating ♥️
Group for discussions: @joomlatalks

Related channels  |  Similar channels

Channel's geo and language
World, English
Statistics
Posts filter


Joomla 3 EOL Security Fixes 1.1.5

This release backports the September 2026 Joomla security fixes (Joomla 5.4.9 / 6.1.4, released 29 September 2026) that also affect Joomla 3.10.12. It includes all fixes from previous versions.

View on Github


The Greek Joomla community will be participating in FOSSCOMM 2026 with an official presentation.
They will discuss the software's core principles and comprehensive security measures.
The event will take place on October 31 – November 1, 2026, at the University of West Attica (250 Thivon St., Egaleo).

FOSSCOMM (Free and Open Source Software Communities Meeting) is an annual conference in Greece that brings together developers, communities, and enthusiasts of free and open-source software (FOSS).


Read more


Joomla 6.2 Release Candidate - Test the final package

What is this release for?

There are two main goals for Release Candidate releases:

+ Providing developers with the basis to test their extensions and reporting any issues well before the final release
+ Allowing users to discover the new features introduced to Joomla 6.2.

For a complete list of known backward compatibility issues for version 6.2, please see Potential backward compatibility issues in Joomla 6.2 on the documentation site.

What is this release NOT for?
This release candidate version of Joomla 6.2 is not suitable for production sites. It is for testing only.

Read more


Joomla 6.1.4 & 5.4.9 Security & Bugfix Release

The Joomla! Project is pleased to announce the release of Joomla 6.1.4 and Joomla 5.4.9. These are security & bugfix releases for the Joomla 5.x and 6.x series.

These releases continue Joomla’s high standards in accessible web design, highlighting Joomla's values of inclusiveness, simplicity and security into an even more powerful open-source web platform.

Read more


Joomla Accessibility Project: From Assessment to Action

The Joomla Accessibility Project is moving from planning into implementation. The first milestone, an independent accessibility audit by Axess Lab, has now been completed. The audit provides a detailed baseline of Joomla’s current accessibility, identifies concrete barriers, and establishes repeatable testing procedures for measuring future progress.
The assessment identified 42 WCAG 2.2 AA issues, including challenges with keyboard navigation, the Media Manager, dialogs, focus management and other core interfaces. It also examined Joomla as an authoring tool using ATAG 2.0.
The next step is already underway: Milestone 1b will turn these findings into a prioritised remediation plan and identify quick wins.

Read the full articles:
• Joomla Accessibility Project: From Planning to Action
• Joomla Accessibility: The Results of Milestone 1a


J!Awards 2026 — Voting Now Open

Nominations for the very first J!Awards closed on 13 September 2026, bringing an exciting first chapter of this new community tradition to a close.
Launched on 17 August to mark Joomla's 21st anniversary, the J!Awards: Community Choice Awards set out to celebrate the people, projects, and tools that make our community what it is — and judging by the response, that spirit clearly struck a chord.
Voting opened on 21 September 2026 at 00:01 UTC and runs until 11 October 2026 at 23:59 UTC. Everyone can vote, no special role or membership required, just an interest in Joomla.
Winners will be announced live at the Joomla World Conference, taking place 16-18 October 2026 in Potsdam, near Berlin, Germany.
Cast your vote at https://community.joomla.org/jawards/vote and help decide who takes home the very first J!Awards.


UX Study for OpenSourceMatters.org: Practicum project

We need your input!
We are collaborating with the Rutgers Master of Business and Science (MBS) Program to conduct research on the opensourcematters.org website.
The students, all concentrating in User Experience Design (UXD), are completing this project as part of their practicum course.
Participate in this study and help us create a better opensourcematters.org site: https://community.joomla.org/invitation-to-participate-the-2026-ux-research-study-on-osm-website


The Joomla Community Magazine. September, 2026

In this issue: your monthly dose of tutorials and how-to’s, the latest updates on the Accessibility Project that aims to enhance Joomla’s state of the art accessibility even more, interviews with our re-elected Vice President and Outreach Department Coordinator, awards to vote for, community news and so much more. Don’t read this editor’s intro, start reading the articles by our fabulous authors!

Read more


Forward from: NorrNext
New payment plugin for Phoca Cart: Unzer HPP

A new NorrNext extension is now available for Phoca Cart 6 and Joomla 5/6.

Unzer HPP for Phoca Cart integrates the Unzer Hosted Payment Page into your Joomla store. Customers are redirected to Unzer to complete their payment and then returned to the store.

What's included:
✅ Joomla 5 & Joomla 6 native support
✅ Phoca Cart 6 compatibility
✅ Hosted Payment Page integration
✅ Multiple Unzer payment methods
✅ Joomla Update System support

Unzer’s payment solutions are particularly popular in countries such as Germany, Austria, Denmark, Luxembourg, Switzerland, and the Nordics.


👉 Product page


Kunena 6.4.14 security release

The Kunena team is thrilled to announce the fourteenth release (security release) of Kunena 6.4, a native Joomla extension for Joomla! 5 and 6.

https://www.kunena.org/blog


Joomla! 6.2 Beta 3 - Preparing for the stable!

The Joomla! Project is pleased to announce the availability of Joomla 6.2 Beta 3 for testing.

What is this release for?

There are two main goals for Beta releases:

✔️Providing developers with the basis to test their extensions and reporting any issues well before the final release
✔️Allowing users to discover the new features introduced to Joomla 6.2.

For a complete list of known backward compatibility issues for version 6.2, please see Potential backward compatibility issues in Joomla 6.2 on the documentation site.

What is this release NOT for?

✔️This beta version of Joomla 6.2 is not suitable for production sites. It is for testing only.

Please help with testing the project


Read more


CRA compliance checklist for Joomla agencies

The EU Cyber Resilience Act is coming. If you run a Joomla agency, building and maintaining sites for clients, the regulation almost certainly does not apply to you directly. But it does change what you should expect from the extension vendors you rely on, and it creates practical responsibilities that are easy to overlook until a client asks an uncomfortable question.

Read more


Security Release VirtueMart 4.8.0

There was a security audit by a Joomla member with Claude and VM did not pass. Some of them were already addressed in VirtueMart5, which is almost ready.

Security Fixes
☑️ Skrill payment plugin: There is a security issue with the Skrill payment plugin. If you use it in your store, please either update to this version or remove the plugin entirely.

Token validation
☑️
Token checks added to backend controllers and frontend forms. Unauthorized form submissions are now rejected.

Enhanced validation for media uploads
☑️ VM allows the unsecure files like php in zips now only for files to sale. Furthermore the mime check was before only done for medias and is now done for any file.

Read more


Joomla 6.2 Beta 2 - Test test test!

The Joomla! Project is pleased to announce the availability of Joomla 6.2 Beta 2 for testing.

What is this release for?

There are two main goals for Beta releases:
☑️ Providing developers with the basis to test their extensions and reporting any issues well before the final release
☑️ Allowing users to discover the new features introduced to Joomla 6.2.

For a complete list of known backward compatibility issues for version 6.2, please see Potential backward compatibility issues in Joomla 6.2 on the documentation site.

What is this release NOT for?
This beta version of Joomla 6.2 is not suitable for production sites. It is for testing only.

🚨 Please help with testing this release

Read more


J2S tore. Security Announcement - Releases 3.3.21, 4.0.21 and 4.1.6

J2Store 3.3.21, 4.0.21 and 4.1.6 are security releases that address six vulnerabilities in the com_j2store component: three authorization/IDOR issues where controller tasks accepted client-supplied identifiers without verifying ownership, one open redirect issue where user-supplied URLs were decoded and used without host validation, one unauthenticated file upload issue compounded by a missing installer manifest entry that left uploaded files web-accessible, and one stored cross-site scripting issue in the administrator order management panel exploitable via the guest checkout flow.

• Release date: 2026-08-20
• Affected versions: All J2Store versions prior to 4.1.6
• Fixed in: J2Store 3.3.21, 4.0.21 and 4.1.6
• Severity: High (CVSS 4.0 scores range from 5.1 to 8.7)

J2Store 4.x was forked and now it is J2Commerce 6.x - a free ecommerce extension for Joomla 6.


Read more


J!Awards: Community Choice Awards

Joomla! Launches Inaugural J!Awards, Celebrating 21 Years of Community-Driven Innovation.

The Joomla! project today announced the launch of the J!Awards: Community Choice Awards, a new awards program created to celebrate the people, projects, and tools that make Joomla what it is. The launch date is no coincidence: 17 August 2026 marks the 21st anniversary of Joomla, and the project chose the occasion to kick off a new tradition celebrating the community that has powered two decades of growth. Nominations open today, with this year's winners to be announced live at Joomla World Conference (JWC) in Potsdam, near Berlin, Germany, taking place 16–18 October 2026.

If you use Joomla, you're already part of the community — and your voice belongs in these awards. The J!Awards are open to everyone: site owners, developers, designers, writers, agencies, hosting customers, and casual users alike. You don't need to be a longtime contributor, hold any official role, or be active on the forums to nominate or vote. Using Joomla is your all-access pass.

"As President of Open Source Matters, I'm genuinely excited about the Joomla! Awards, because they put the wonderful people and projects behind Joomla into the spotlight," said Elisa Foltyn, President of Open Sources Matters.


Read more


Sourcerer 14.0.0 fixes PHP execution from unverified content

On 17 August 2026 Regular Labs released version 14.0.0 of Sourcerer, the Joomla extension that lets you place PHP, JavaScript and CSS inside your content. The changelog carries one entry tagged both [SECURITY FIX] and [BC BREAK]:

Sourcerer 14.0.0 changelog, the security entry in full

[SECURITY FIX] [BC BREAK] Prevents reflected or otherwise unverified rendered Sourcerer code from executing by default while preserving verified article and Custom module code

Read more


Joomla Community Magazine, - The August Issue, 2026

This month, we're celebrating Joomla's 21st birthday. Since we're the Joomla Community Magazine, we do this with content - in this issue, you'll find a number of entertaining 21-themed articles.

☑️ Louise Hawkins - 21 Improvements That Can Make a Difference to a Website

☑️ Nadja Lamisch - 21 Reasons to attend the JWC

☑️ Louise Hawkins - 21 Things Only Joomla Users Understand

☑️ Anja de Crom - 21 Things that were there before Joomla - and that we still love and enjoy

☑️ Viviana Menzel - CSS Shorts: light-dark()

☑️ Dan Atrill - Does AI Make It Easier For Websites To Be Hacked?

☑️ Allon Moritz - Extension developers, it's time to mark your security updates

☑️ Emmanuel Lemor - Funding Open Source in a new era…

☑️ Paul Staub - How a Joomla Component Junkie Fell in love with the Astroid Framework

☑️ Herman Peeren - How to automatically run a task in Joomla?

☑️
Richard Gosler - Joomla at 21: Finding the Golden Ratio in Our History

☑️
Brian Teeman - Joomla is older than...

☑️ Brian Teeman - Standing on the Shoulders of Giants (Stacked So High I Can Almost Touch the Moon)

☑️ Philip Walton - The robots have changed, and your robots.txt hasn't

☑️ Anja de Crom - When AI Turns on Your Code - the impact of AI hacks on extensions developers

☑️ Anja de Crom - Why we don't publish everything

☑️ Serge Billon - You got hacked. So what?

Read more


🚨 YOOtheme Pro 5.0.41 – August 21, 2026 - Security Fix

In YOOtheme Pro 5.0.41, we have fixed critical vulnerabilities that can be exploited by authenticated users who have permission to create articles or drafts. If these users are untrusted, update immediately. Otherwise, no immediate action is required.


☑️ CVE-2026-75115: Fix arbitrary file read exploitable by any contributor-level user
☑️ CVE-2026-76613: Fix SQL injection exploitable by any contributor-level user

YOOtheme Pro:
https://yootheme.com/changelog
——

Critical security update for ZOO 4.1.66

We have fixed critical vulnerabilities in ZOO 4.1.66 that could allow unauthenticated attackers to gain full control of a website. Update all ZOO installations immediately.


4 vulnerabilities:
☑️ CVE-2026-76611: Path traversal
☑️ CVE-2026-76612: Cross-site scripting
☑️ CVE-2026-77028: External redirects
☑️ CVE-2026-77029: CSRF attacks

ZOO Changelog
https://yootheme.com/zoo/changelog

Details about vulnerabilities (mysites.guru)


Joomla 6.1.3 & 5.4.8 Security & Bugfix Release
The Joomla! Project is pleased to announce the release of Joomla 6.1.3 and Joomla 5.4.8. These are security & bugfix releases for the Joomla 5.x and 6.x series.

These releases continue Joomla’s high standards in accessible web design, highlighting Joomla's values of inclusiveness, simplicity and security into an even more powerful open-source web platform.

‼️ 10 security fixes

Read more

20 last posts shown.