Skip to main content

Joomla 3 core vulnerabilities that Joomla will never patch

The last public Joomla 3 release, 3.10.12, shipped on 8 July 2023. Joomla 3 reached end of life on 17 August 2023, and the paid eLTS programme that kept patching it ended on 17 February 2025. Joomla's security team still publishes core advisories, and many of them describe code that Joomla 3 shares with the supported versions.

39 of those advisories are listed below. Joomla fixed them in the supported versions where they apply and, for part of the period, in paid eLTS builds. No public Joomla 3 release closes any of them. On a Joomla 3 site that stops at 3.10.12, every one is still open.

39
core advisories reach Joomla 3.10.12
published from November 2023 onward
21
of them were published in 2026
the holes keep coming
18%
also affect Joomla 4 and later
as marked in Joomla's advisories
85
core files changed by the one-click patch
84 replaced, 1 added

Advisory figures are from the Joomla Security Centre. File counts are from the mySites.guru patch tool. Site measurements: 79% of the Joomla 3 sites we can check have unpatched core files we could fix, across sites connected to mySites.guru, 28 August 2026.

How the one-click patch closes them

It is part of the mySites.guru subscription, and it works on the files, so there is nothing to migrate first.

mySites.guru backports each Joomla core fix to Joomla 3.10.12, tests it against a stock 3.10.12 install, and ships it with the mySites.guru connector. One toggle in the site's Snapshot changes 85 core files: 84 are replaced with patched copies and 1 is added. Switch the toggle off and every file goes back to stock 3.10.12. The work builds on the community 3.10.999 reference project, and the fixes are reproduced on a real 3.10.12 install before they ship.

The audit compares each of the 85 files with the patched copy and counts the ones that do not match. Zero means the site has every patch we ship today. Any other number is how many files still need patching, and the toggle fixes them all at once. A file you edited by hand counts as unpatched, and switching the toggle on replaces it with the patched copy. Files for parts of Joomla you have uninstalled, such as the Hathor or Beez3 templates, are skipped, so they stay uninstalled.

The one file Joomla 3 never shipped is a form rule behind the language override fix. It is created when you switch the toggle on and deleted when you switch it off. After patching, an audit lists these files under Core File Changes, because they no longer match the 3.10.12 release. That is expected, and you can read every diff there.

When Joomla publishes a new advisory that reaches Joomla 3, it is added to the patch set. Your site then shows as not fully patched until you switch the toggle on again, so watch for the Patches Available badge on your sites list. For a portfolio, a bulk view lists every Joomla 3.10.12 site with its own toggle.

All 39 advisories, newest first

Grouped by the year Joomla published the advisory. Each title links to Joomla's own write-up, and every row is closed by the mySites.guru one-click patch.

2026 (21 advisories)

CVEAdvisoryAlso affects Joomla 4+One-click patch
CVE-2026-92232XSS filter bypass in InputFilter via whitespace in HTML data URIsNoIncluded
CVE-2026-92231XSS filter bypass in InputFilter via HTML5 entity decode mismatchNoIncluded
CVE-2026-92225XSS in module listYesIncluded
CVE-2026-92222SSRF vectors in various core extensionsNoIncluded
CVE-2026-90917Improper ACL checks in outputs for tagged itemsYesIncluded
CVE-2026-90916Improper ACL checks in the content history comparison viewYesIncluded
CVE-2026-90915Arbitrary directory deletion via the cache purge actionYesIncluded
CVE-2026-90907Unauthorized user account creation via the profile.save controllerNoIncluded
CVE-2026-90906XSS in the HTMLHelper::link methodNoIncluded
CVE-2026-73373Unrestricted uploads of SHTML filesNoIncluded
CVE-2026-71572Response header injection in download viewsNoIncluded
CVE-2026-48954XSS through language overridesNoIncluded
CVE-2026-48948Incorrect access control in the com_contact vCard downloadNoIncluded
CVE-2026-48905Inadequate content filtering in the cleanAttributes filter codeNoIncluded
CVE-2026-48903Inadequate content filtering in the checkAttribute filter codeNoIncluded
CVE-2026-48902Transport encryption downgrade for password and username reset linksNoIncluded
CVE-2026-40383LFI in the HtmlView layout parameterNoIncluded
CVE-2026-30894XSS in com_contenthistoryNoIncluded
CVE-2026-25900XSS in feed modulesNoIncluded
CVE-2025-63083XSS vector in the pagebreak pluginNoIncluded
CVE-2025-63082Inadequate content filtering for data URLsYesIncluded

2025 (6 advisories)

CVEAdvisoryAlso affects Joomla 4+One-click patch
CVE-2025-54476Inadequate content filtering in the checkAttribute filter codeNoIncluded
CVE-2025-25226SQL injection in the quoteNameStr method of the database packageNoIncluded
CVE-2025-22213Malicious file uploads via the Media ManagerYesIncluded
CVE-2024-40749Read ACL violation in multiple core viewsNoIncluded
CVE-2024-40748XSS vector in the id attribute of menu listsNoIncluded
CVE-2024-40747XSS vectors in module chromesYesIncluded

2024 (11 advisories)

CVEAdvisoryAlso affects Joomla 4+One-click patch
CVE-2024-40743XSS vectors in the Outputfilter::strip* methodsNoIncluded
CVE-2024-27185Cache poisoning in paginationNoIncluded
CVE-2024-27184Inadequate validation of internal URLsNoIncluded
CVE-2024-26278XSS in the com_fields default field valueNoIncluded
CVE-2024-26279XSS in Wrapper extensionsNoIncluded
CVE-2024-21731XSS in the StringHelper::truncate methodNoIncluded
CVE-2024-21726Inadequate content filtering in the filter codeNoIncluded
CVE-2024-21725XSS in mail address outputsNoIncluded
CVE-2024-21724XSS in media selection fieldsNoIncluded
CVE-2024-21723Open redirect in the installation applicationNoIncluded
CVE-2024-21722Insufficient session expiration in MFA management viewsNoIncluded

2023 (1 advisory)

CVEAdvisoryAlso affects Joomla 4+One-click patch
CVE-2023-40626Exposure of environment variablesNoIncluded

See which of these your Joomla 3 sites still have open

Connect one site and the audit counts the patch files that do not match, so you know how many of the 39 advisories apply to it today. The first audit is free, with no card.

What the patch does not do

It closes core holes on a Joomla 3 site and holds the position while you move. Everything else on the server is outside its reach.

  • It does not clean a hacked site. Find and remove the malicious files first with the Hacked tools, then patch.
  • It patches Joomla core only. Extension flaws are tracked on the extension vulnerabilities page, and for Helix and SP Page Builder there is a separate JoomShaper tool.
  • It does not make Joomla 3 a long-term home. PHP, your extensions and your server keep moving on without it.
  • It needs Joomla 3.10.12 or a later 3.x release, and the PHP zip extension on your server. Without zip support the audit says so and the toggle is not offered.

Plan the move as well

The patch buys time to migrate, and it does not replace the migration. The options page sets out what staying, rescuing and moving each involve.

Where to read more

Keeping Joomla 3 patched is part of the subscription

The one-click core patch, JoomShaper's Joomla 3 packages, vulnerable extension alerts and malware scanning are all included, alongside everything else mySites.guru does for Joomla and WordPress. No per-site fees, and no price increases since 2012.

Single site
£5/month
Upgrades itself to Unlimited when you add a second site
Unlimited sites
£19.99/month
Every site you manage, one price
Unlimited, yearly
£199.99/year
£16.66 a month

See the full pricing

Keep your Joomla 3 sites patched while you plan the move

One free audit of one site, no card, no time limit.

Audit a Joomla 3 site free