Select your language

Sign up

Joomla 5 Full Package - Version 5.3.4

Category: Core
  • Download type: Free
  • Version: 5.3.4
  • Date:

5.3.4

Security
Fixed the CVE-2025-54476 XSS vulnerability caused by inadequate content filtering in the checkAttribute methods.
Security
Fixed the CVE-2025-54477 vulnerability that allowed user enumeration through the passkey authentication method.
Addition
Added aria-label support to Joomla dialog windows.
Addition
Added a check for required fields before using them in content versioning.
Addition
Transport classes now support arrays of HTTP header values.
Change
Updated a frontend language string.
Change
Updated the Joomla contribution documentation.
Change
Updated Composer and NPM dependencies to resolve reported security vulnerabilities.
Change
Updated TinyMCE from version 6.8.5 to version 6.8.6.
Change
Updated the joomla/filesystem package.
Change
Updated the Miscellaneous Information icon in the Contacts component.
Change
Cleaned up PHPDoc documentation.
Change
Updated joomla/oauth2 to version 3.0.2.
Fixed
Fixed the display of the database prefix.
Fixed
Fixed the calendar picker when week numbers are hidden and the 24-hour time format is used.
Fixed
Updated the tag router to restrict lossy matches to menu items configured for all tags.
Fixed
Fixed the Cassiopeia mobile menu collapse behaviour.
Fixed
Prevented an explicit session identifier from being set through GET request parameters.
Fixed
A restored article version is now correctly checked out to the current user.
Fixed
Fixed an undefined array key warning in table/nested.php.
Fixed
Unique banner aliases are now enforced during both creation and updating.
Fixed
A DELETE request for a non-existing item now returns HTTP status code 204.
Fixed
Fixed an infinite API loop when an unknown resource is requested while the website is offline.
Fixed
The correct HTTP status header is now set for XML and feed responses.
Fixed
Simplified the No Media Found code in the Media Manager.
Fixed
Fixed a copy-and-paste error in form field definitions.
Fixed
The TinyMCE update fixes incorrect cursor placement in the editor.
Fixed
The joomla/filesystem update fixes extension uploads when post_max_size is set to zero.
Fixed
Fixed caching in the Predefinedlist field getOptions method.
Fixed
Fixed a deploy_version typographical error in the Scheduled Tasks component.
Fixed
Test news feeds and their categories are now correctly cleaned after the first test-suite run.
Fixed
Added missing periods to interface sentences.
Fixed
Fixed the author of a tagged item not being updated when an article is saved.
Fixed
SchemaorgPrepareDateTrait now uses the correct ISO 8601 date format.
Fixed
The joomla/oauth2 update fixes case-insensitive OAuth2Client authentication.
Fixed
Fixed copyright notices being incorrectly removed from media assets during the Joomla build process.
Remove
Removed the obsolete .github/ISSUE_TEMPLATE.md file.
Note
Joomla 5.3.4 is a security and bug-fix release.
Note
Joomla 5.3.4 was released on 30 September 2025.
Note
CVE-2025-54476 has moderate severity and a moderate probability of exploitation.
Note
CVE-2025-54477 has low severity and a low probability of exploitation.
Note
Corresponding security fixes were also released in Joomla 4.4.14.
Note
A complete backup of the website files and database is recommended before updating.
Note
The update should be tested on a copy of the production website before deployment.
Note
When updating from a Joomla version earlier than 4.4, upgrade to Joomla 4.4 before updating to Joomla 5.
Newsletter Subscription
Enter your email address and we will keep you updated!

Joomla.center is not affiliated with or endorsed by the Joomla!® Project or Open Source Matters. The Joomla!® name and logo is used under a limited license granted by Open Source Matters, the trademark holder in the United States and other countries.