Select your language

Sign up

Joomla 6 Update Package 6.1.1

  • Category: Core
  • Version: 6.1.1
  • Date:
  • Download type: Free
  • Compatibility: J6
Security
[20260501] Fixed an XSS vulnerability in feed modules.
Security
[20260502] Fixed an XSS vulnerability in com_associations.
Security
[20260503] Fixed an XSS vulnerability in com_contenthistory.
Security
[20260504] Fixed an XSS vulnerability in Read More links.
Security
[20260505] Fixed a CSRF vulnerability in the user activation endpoint.
Security
[20260506] Fixed an authenticated blind SQL injection vulnerability in com_finder.
Security
[20260507] Fixed an authenticated blind SQL injection vulnerability in com_tags.
Security
[20260508] Fixed an improper access check in com_config web service endpoints.
Security
[20260509] Fixed a local file inclusion vulnerability in the HTMLView layout parameter.
Security
[20260510] Fixed a path traversal vulnerability in a com_media web service endpoint.
Security
[20260511] Fixed an MFA authentication bypass vulnerability.
Security
[20260512] Fixed an additional MFA authentication bypass vulnerability.
Security
[20260513] Fixed privilege escalation through the com_users batch task.
Security
[20260514] Fixed privilege escalation through com_users web service endpoints.
Security
[20260515] Fixed incorrect access control in sample data plugins.
Security
[20260516] Fixed incorrect access control in com_scheduler.
Security
[20260517] Fixed incorrect cache key construction for InputFilter objects.
Security
[20260518] Prevented transport encryption downgrade for username and password reset links.
Security
[20260519] Improved content filtering in the Joomla Framework checkAttribute filter code.
Security
[20260520] Improved content filtering in the Joomla Framework cleanAttributes filter code.
Fixed
#45145 — Fixed an incorrect error being displayed when renaming a file.
Fixed
#47307 — Fixed an accessibility issue with the Back-to-Top link.
Fixed
#47413 — Prevented a misleading save failure message when a mail notification fails.
Fixed
#47423 — Improved substring searching in Fancy Select fields.
Fixed
#47476 — Added the missing page parameter to the content event arguments in the Articles module.
Fixed
#47480 — Fixed an incorrect bind parameter key in the Category HTML helper.
Fixed
#47533 — Fixed an ECB mode validation typo in the OpenSSL AES adapter and updated the related documentation.
Fixed
#47546 — Preselected values are now displayed in Fancy Select fields.
Fixed
#47557 — Added handling for Punycode conversion exceptions to prevent crashes.
Fixed
#47565 — Fixed the handling of attachments supplied as a list of objects.
Fixed
#47574 — Corrected the background colour of elements with the is-selected class in dark mode.
Fixed
#47586 — Fixed category custom fields loading.
Fixed
#47590 — Fixed deletion of the update archive after an automatic Joomla core update.
Fixed
#47599 — Made the default collapsible menu overridable.
Fixed
#47601 — Fixed the Debug plugin crashing when Query Explain is used during AJAX requests.
Fixed
#47602 — Added AJAX error message scripts to improve feedback when editing menu items.
Fixed
#47604 — Fixed HTML tag replacement when converting an HTML email body to plain text.
Fixed
#47616 — Added a translation format so that the last automatic update check time is displayed correctly.
Fixed
#47617 — Added the missing closing angle bracket for a fieldset in the repeatable layout.
Fixed
#47640 — Fixed publishing fields not being displayed in the article creation form.
Fixed
#47642 — Corrected aria-posinset values so that they start from 1.
Fixed
#47644 — Added a missing table column header to improve accessibility.
Fixed
#47646 — Prevented a fatal error when the getTemplate method is called in an API application.
Fixed
#47650 — Fixed RTL toolbar dropdown alignment in the administrator interface.
Fixed
#47653 — Improved the accessibility of language installation information.
Fixed
#47659 — Fixed the default value of the save_history parameter in com_modules.
Fixed
#47661 — Fixed TinyMCE menu bar visibility in fullscreen mode.
Fixed
#47686 — The clear button now correctly resets calendar filters.
Fixed
#47694 — Version history is now displayed in FormView only when version history is supported.
Fixed
#47697 — Moved mod_menu language loading until after client_id resolution in ItemsModel.
Fixed
#47715 — Corrected the z-index of selection fields in the Cassiopeia template.
Fixed
#47729 — Fixed the notification dismiss button in light mode.
Fixed
#47731 — Child template name validation now checks only templates of the appropriate type.
Fixed
#47735 — Fixed article version preview for users with Author permissions.
Fixed
#47775 — Added a colour variable for disabled Choices.js fields.
Note
Joomla 6.1.1 is a security release. Installing the update as soon as possible is strongly recommended.
Note
All bug fixes included in Joomla 5.4.6 have also been merged into Joomla 6.1.1.
Newsletter Subscription
Enter your email address and we will keep you updated!

Joomla.center is not affiliated with or endorsed by the Joomla!® Project or Open Source Matters. The Joomla!® name and logo is used under a limited license granted by Open Source Matters, the trademark holder in the United States and other countries.