Joomla

Joomla! is a free and open-source content management system (CMS) for publishing web content. Over the years Joomla! has won several awards. It is built on a model–view–controller web application framework that can be used independently of the CMS that allows you to build powerful online applications.  Wintercorn have specialised in Joomla! since 2006 and have extensive experience in building, supporting and improving Joomla! websites for a diverse range of industries.  Take a look at our Joomla Consulting services for what we can offer.

  • Joomla Security Announcement on Malicious File Uploads

    Joomla Security Announcement on Malicious File Uploads

    The recent Joomla Security Announcement highlights a critical vulnerability, CVE-2025-22213, that impacts versions 4.0.0-4.4.11 and 5.0.0-5.2.4 of the popular content management system.This vulnerability arises from inadequate checks in the Joomla Media Manager, allowing users with “edit” privileges to maliciously upload executable PHP files.

  • MFA Authentication Bypass: Joomla! Security Advisory

    MFA Authentication Bypass: Joomla! Security Advisory

    MFA Authentication Bypass is a critical security vulnerability impacting Joomla!users, which could potentially leave many installations exposed to malicious attacks.

  • SQL Injection Vulnerability in Joomla’s quoteNameStr Method

    SQL Injection Vulnerability in Joomla’s quoteNameStr Method

    The SQL injection vulnerability discovered in Joomla’s quoteNameStr method poses a significant threat to database security.This flaw highlights a critical oversight in the handling of identifiers within the Database package, potentially exposing sensitive information.

  • Joomla 5.2.6: Latest Security Release and Upgrade Info

    Joomla 5.2.6: Latest Security Release and Upgrade Info

    Joomla 5.2.6 has arrived, marking yet another important milestone in the evolution of this open-source CMS.This latest security release emphasizes Joomla’s ongoing commitment to enhancing web design accessibility, underscoring its values of inclusiveness and security.

  • Joomla 5.2.5: Essential Security and Bugfix Release

    Joomla 5.2.5: Essential Security and Bugfix Release

    The Joomla Project is excited to announce the release of **Joomla 5.2.5**, a significant update that enhances security and fixes various bugs within the Joomla CMS.This release continues the commitment to provide users with a robust platform enriched with the latest features to maintain high standards in web design and development.

  • Joomla 5.3 Release Candidate: What You Need to Know

    Joomla 5.3 Release Candidate: What You Need to Know

    Exciting news for the Joomla community: the Joomla 5.3 Release Candidate has officially arrived!This is a pivotal moment for developers and users alike, as it provides the opportunity to test upcoming features and ensure everything runs smoothly before the final launch.

  • Joomla Security Update: Critical Patch Release on April 8th

    Joomla Security Update: Critical Patch Release on April 8th

    The upcoming Joomla security update, set to be released on April 8th at 16:00 UTC, aims to bolster the security of Joomla versions 4.4.x and 5.2.x.This timely Joomla 4.4 security patch is crucial as it addresses a high-impact vulnerability that poses a moderate risk to users, as classified by the JSST security advisory.

  • Joomla Security Update: Essential Changes for Your Site

    Joomla Security Update: Essential Changes for Your Site

    Joomla security update is set to be released on March 11th at 16:00 UTC, targeting critical vulnerabilities in versions 4.4.x and 5.2.x.This timely Joomla update aims to reinforce your website’s defenses against potential threats, as identified by the JSST security advisory.

  • SQL Injection Joomla: Urgent Security Update Announced

    SQL Injection Joomla: Urgent Security Update Announced

    SQL Injection Joomla vulnerabilities pose a significant threat to website security, particularly within the widely-used Joomla CMS.This high-impact risk, identified as CVE-2025-22207, stems from improperly constructed order clauses in the backend task list of the com_scheduler component, affecting versions 4.1.0-4.4.10 and 5.0.0-5.2.3.

  • ACL Violation in Joomla: Security Update Needed Now

    ACL Violation in Joomla: Security Update Needed Now

    ACL violation in Joomla has recently come under scrutiny due to its potential impact on Joomla security.Specific versions of the Joomla CMS, including 3.9.0-3.10.19-elts and 4.0.0-4.4.9, have been flagged for access control vulnerabilities that could lead to unauthorized access to protected views.