5.2.6
| Security |
Fixed the CVE-2025-25226 SQL injection vulnerability in the quoteNameStr method of the Joomla Framework Database package.
|
| Security |
Fixed the CVE-2025-25227 vulnerability that allowed multi-factor authentication checks to be bypassed.
|
| Security |
The user activation token is now removed when the user's email address is changed.
|
| Change |
Updated Joomla translations.
|
| Change |
Updated the joomla/database package from version 3.2.1 to the secure version 3.4.0.
|
| Change |
Further updated the joomla/database package to version 3.4.1.
|
| Change |
Changed the development minor version number to Joomla 5.3.
|
| Note |
Joomla 5.2.6 is a security release in the Joomla 5.2 series.
|
| Note |
Joomla 5.2.6 was released on 8 April 2025 together with Joomla 4.4.13.
|
| Note |
Joomla 5.2.6 is the final release in the Joomla 5.2 series.
|
| Note |
CVE-2025-25226 has high potential impact, low severity and a low probability of exploitation.
|
| Note |
CVE-2025-25227 has high potential impact, moderate severity and a moderate probability of exploitation.
|
| Note |
The multi-factor authentication bypass affects Joomla versions from 5.0.0 through 5.2.5.
|
| Note |
The vulnerable quoteNameStr method is protected and is not directly used by the original database package classes.
|
| Note |
Third-party classes extending the database package may be affected if they use the quoteNameStr method.
|
| Note |
A complete backup of the website files and database is recommended before updating.
|
| Note |
The update should be tested on a copy of the production website before deployment.
|
| Note |
When updating from a Joomla version earlier than 4.4, upgrade to Joomla 4.4 before updating to Joomla 5.
|