5.4.6
| Security |
[20260501] Fixed an XSS vulnerability in feed modules.
|
| Security |
[20260502] Fixed an XSS vulnerability in com_associations.
|
| Security |
[20260503] Fixed an XSS vulnerability in com_contenthistory.
|
| Security |
[20260504] Fixed an XSS vulnerability in Read More links.
|
| Security |
[20260505] Fixed a CSRF vulnerability in the user activation endpoint.
|
| Security |
[20260506] Fixed an authenticated blind SQL injection vulnerability in com_finder.
|
| Security |
[20260507] Fixed an authenticated blind SQL injection vulnerability in com_tags.
|
| Security |
[20260508] Fixed an improper access check in com_config web service endpoints.
|
| Security |
[20260509] Fixed a local file inclusion vulnerability in the HTMLView layout parameter.
|
| Security |
[20260510] Fixed a path traversal vulnerability in a com_media web service endpoint.
|
| Security |
[20260511] Fixed an MFA authentication bypass vulnerability.
|
| Security |
[20260512] Fixed an additional MFA authentication bypass vulnerability.
|
| Security |
[20260513] Fixed privilege escalation through the com_users batch task.
|
| Security |
[20260514] Fixed privilege escalation through com_users web service endpoints.
|
| Security |
[20260515] Fixed incorrect access control in sample data plugins.
|
| Security |
[20260516] Fixed incorrect access control in com_scheduler.
|
| Security |
[20260517] Fixed incorrect cache key construction for InputFilter objects.
|
| Security |
[20260518] Prevented transport encryption downgrade for username and password reset links.
|
| Security |
[20260519] Improved content filtering in the Joomla Framework checkAttribute filter code.
|
| Security |
[20260520] Improved content filtering in the Joomla Framework cleanAttributes filter code.
|
| Fixed |
#47565 — Fixed the handling of attachments supplied as a list of objects.
|
| Fixed |
#47413 — Prevented a misleading save failure message when a mail notification fails.
|
| Fixed |
#47423 — Improved substring searching in Fancy Select fields.
|
| Fixed |
#47624 — Updated branch documentation following the stable release of Joomla 6.1.0.
|
| Fixed |
#47590 — Fixed deletion of the update archive after an automatic Joomla core update.
|
| Fixed |
#47644 — Added a missing table column header to improve accessibility.
|
| Fixed |
#47650 — Fixed RTL toolbar dropdown alignment in the administrator interface.
|
| Fixed |
#47604 — Fixed HTML tag replacement when converting an HTML email body to plain text.
|
| Fixed |
#47642 — Corrected aria-posinset values so that they start from 1.
|
| Fixed |
#47616 — Added a translation format so that the last automatic update check time is displayed correctly.
|
| Fixed |
#47653 — Improved the accessibility of language installation information.
|
| Fixed |
#47697 — Moved mod_menu language loading until after client_id resolution in ItemsModel.
|
| Fixed |
#47586 — Fixed category custom fields loading.
|
| Fixed |
#47729 — Fixed the notification dismiss button in light mode.
|
| Fixed |
#47731 — Child template name validation now checks only templates of the appropriate type.
|
| Fixed |
#47533 — Fixed an ECB mode validation typo in the OpenSSL AES adapter and updated the related documentation.
|
| Fixed |
#46886 — Added a system test for filtering published and unpublished articles.
|
| Fixed |
#47555 — Added a system test for the cache cleaning console command.
|
| Fixed |
#47556 — Added a system test for the Scheduled Tasks console command.
|
| Fixed |
#47712 — Added system tests for custom fields in articles.
|
| Fixed |
#47254 — Updated phpMyAdmin in Codespaces to the latest version.
|
| Fixed |
#47476 — Added the missing page parameter to the content event arguments in the Articles module.
|
| Fixed |
#47480 — Fixed an incorrect bind parameter key in the Category HTML helper.
|
| Fixed |
#45145 — Fixed an incorrect error being displayed when renaming a file.
|
| Fixed |
#47307 — Fixed an accessibility issue with the Back-to-Top link.
|
| Fixed |
#47401 — Removed an unused web asset reference.
|
| Fixed |
#47735 — Fixed article version preview for users with Author permissions.
|
| Fixed |
#47610 — Added integration tests for listing extensions by type.
|
| Note |
Joomla 5.4.6 is a security and bugfix release.
|
| Note |
Installing Joomla 5.4.6 as soon as possible is strongly recommended.
|
| Note |
Joomla 5.4.6 was released together with Joomla 6.1.1.
|
| Note |
Creating a website backup and checking the compatibility of installed extensions and templates is recommended before updating.
|
| Note |
When upgrading from a version earlier than Joomla 4.4, update to Joomla 4.4 first and then upgrade to Joomla 5.
|