5.4.2
| Security |
Fixed inadequate content filtering for data URLs that could allow XSS attacks through image tags.
|
| Security |
Fixed XSS vulnerabilities in the Page Break and Page Navigation plugins.
|
| Addition |
Added full support for PHP 8.5.
|
| Addition |
Added PHP 8.5 to unit and integration tests.
|
| Addition |
Added a pull request targeting section to the README file.
|
| Fixed |
Fixed the static getTemplate call in mail templates.
|
| Fixed |
Updated the use of the fputcsv function for PHP 8.4 compatibility.
|
| Fixed |
Fixed the PHP 8.5 version check.
|
| Fixed |
Removed the remaining deprecated JText calls.
|
| Fixed |
Fixed a 404 error in the web services component configuration route when a component name contains numbers.
|
| Fixed |
Aligned the Envelope-From and Return-Path headers with the sender address in MailTemplateFactory.
|
| Fixed |
Fixed the request format condition in MenusHelper that caused a deprecation warning.
|
| Fixed |
The success and message types are now correctly mapped to SymfonyStyle in ConsoleApplication.
|
| Fixed |
Removed the sidebar wrapper border and added a box shadow to the autumn dark-mode colour scheme.
|
| Fixed |
Updated indirect development dependencies to resolve security vulnerabilities reported by NPM Audit.
|
| Fixed |
Fixed Smart Search taxonomy filters being overwritten when multiple filters have identical titles.
|
| Fixed |
Articles are no longer loaded in the blog layout when article loading is disabled in the configuration.
|
| Fixed |
Fixed a regular expression in DocumentRenderer.php.
|
| Fixed |
The latest action logs module now loads the language files of the corresponding extensions.
|
| Fixed |
Fixed the snooze function in the Joomla end-of-support notification plugin.
|
| Fixed |
Fixed the MySQL 8 error caused by an illegal argument being passed to a regular expression in the banners model.
|
| Fixed |
Further updated indirect development dependencies to resolve NPM security vulnerabilities.
|
| Fixed |
Fixed scheduled-task notifications for Joomla installations updated from versions earlier than Joomla 5.3.
|
| Fixed |
Automatic update finalisation errors are now exposed in API responses.
|
| Fixed |
Removed an unnecessary setError call with an empty value.
|
| Fixed |
Updated development dependencies to resolve security vulnerabilities reported by NPM Audit.
|
| Fixed |
Removed the obsolete skin creator link from TinyMCE.
|
| Fixed |
Fixed the subform field dropdown incorrectly displaying the current field.
|
| Note |
Joomla 5.4.2 is a security and bug-fix release.
|
| Note |
Joomla 5.4.2 was released together with Joomla 6.0.2.
|
| Note |
CVE-2025-63082 has moderate severity and a low probability of exploitation.
|
| Note |
CVE-2025-63083 has moderate severity and a low probability of exploitation.
|
| Note |
A complete backup of the website files and database is recommended before updating.
|
| Note |
The update should be tested on a copy of the production website before deployment.
|
| Note |
When updating from a Joomla version earlier than 4.4, upgrade to Joomla 4.4 before updating to Joomla 5.
|