Everything we have written about Joomla 3
31 posts from the mySites.guru blog cover end of life, what each extension vendor decided, the security flaws that reach Joomla 3 branches, and the patches we built for them. Each one is dated and links to the mySites.guru blog.
New to the subject? Read the first three in order. The rest are newest first, so the latest vendor decision or disclosure sits at the top.
Start here
The state of Joomla 3 across a real dataset, the one-click core patch, and the community project behind it.
- Joomla 3 Didn't Fail. Your Retainer Did.
Joomla 3 sites are five times more likely to be hacked than Joomla 6, and the agencies who migrated are doing worse.
- Fix Joomla 3 Security Issues in One Click
Patch every known Joomla 3 security vulnerability across all your sites with a single toggle in mySites.guru - no manual file edits, no eLTS subscription.
- The Joomla 3.10.999 Project
The Joomla 3.10.999 project backported critical security patches to end-of-life Joomla 3 sites. What it was, why it existed, and what to do now.
Find every unpatched Joomla 3 site you look after
Connect one site and mySites.guru audits it free, with no card. You see the core vulnerabilities still open on it, the extensions with known holes, and a one-click fix for the core ones.
Everything else, newest first
Vendor decisions, security disclosures, supported-version releases and migration notes.
- 1,000+ Days After Joomla 3's End of Life, Everything You Need Is on One Site
joomla3security.com puts the Joomla 3 end-of-life dates, 46 vendors' positions, 39 unpatched core advisories and your options to stay or migrate in one place.
- 14 More Joomla 3 Security Fixes, Each Tested on a Real 3.10.12 Site
Joomla 5.4.9 fixed 16 core issues. We backported every one reaching Joomla 3 to the mySites.guru one-click patch tool, each proved on a real 3.10.12 site.
- SP Page Builder's Joomla 3 Security Patch Was Incomplete. Version 1.0.3 Fixes It.
JoomShaper's first Joomla 3 security patch for SP Page Builder left the captcha bypass live and the XSS fix incomplete. Version 1.0.3 closes both.
- Phoca Cart 6.1.9 stops anyone downloading other customers' paid files
Phoca Cart before 6.1.9 let anonymous visitors download the digital products other customers bought. Only the Joomla 6 line is fixed, and 6.1.8 is affected.
- Joomla 5.4.9 and 6.1.4 Fix 16 Security Issues, Two Rated High
Joomla 5.4.9 and 6.1.4 fix 16 core security issues, including cache directory deletion, SSRF, an MFA bypass and account creation with registration switched off.
- Modules Anywhere 10.0.0 and Tabs & Accordions 3.2.0 Close Two Content Author Security Holes
CVE-2026-100750 and CVE-2026-100751: Regular Labs fixed two High severity issues in Modules Anywhere 10.0.0 and Tabs & Accordions 3.2.0 for Joomla.
- Six more J2Store flaws fixed in 3.3.23, 4.0.23 and 4.1.8
J2Store 3.3.23, 4.0.23 and 4.1.8 fix six flaws mySites.guru reported, including an anonymous blind SQL injection that reads a Joomla shop's whole database.
- SQL Injection and a Captcha Bypass in the SP Page Builder Joomla Extension, found by mySites.guru
mySites.guru found an Author-level SQL injection and an unauthenticated captcha bypass in the SP Page Builder Joomla extension, both fixed in 6.9.1.
- Regular Labs Publishes 24 Joomla Extension Updates Including 10 Security Fixes
Regular Labs shipped 24 Joomla extension updates on 13 September 2026. Ten fix security issues across nine CVEs, and four change behaviour on update.
- Digital Peak patches four Joomla extensions after a Claude audit
Digital Peak shipped out-of-band fixes for DPCalendar, DPMedia, DPAttachments and DPCases on 10 September. DPAttachments is the one to do first.
- J2Store 3 Stops Getting Security Fixes on 19 October 2026
J2Commerce ends J2Store 3 support on 19 October 2026. Six in ten of the J2Store installs we monitor are on that line, and most are three releases behind.
- J2Store 3.3.22, 4.0.22 and 4.1.7 fix five flaws we reported
J2Store 3.3.22, 4.0.22 and 4.1.7 fix five flaws mySites.guru reported, including anonymous PayPal order confirmation and a 9.5 backend escalation.
- DPCalendar 10.12.0 fixes an SQL injection and an XSS
Digital Peak fixed a blind SQL injection and a stored XSS in DPCalendar 10.12.0, backported to 8.19.5 for Joomla 3. Both need a logged-in user.
- Helix Ultimate 2.2.10 Fixes Twelve Security Issues, Including a Pre-Login Bypass
Helix Ultimate 2.2.10 is a security release for the Joomla template framework. Every version below it is affected. Here is what it fixes and how to update.
- Helix Ultimate's Third Joomla 3 Patch Since JoomShaper Said There Would Be None
JoomShaper said its Joomla 3 products would get no security patches regardless of severity. The Helix Ultimate template framework has now had four.
- Fabrik 4.7.2 for Joomla: A Long List of Security Fixes
Fabrik 4.7.2 for the Joomla extension closes a long list of unauthenticated vulnerabilities, most of them found and reported by mySites.guru. Update now.
- A CVSS 10.0 Unauthenticated Upload in YOOtheme ZOO, Fixed in 4.1.66
YOOtheme ZOO (com_zoo) up to 4.1.63 had an unauthenticated file upload RCE scored CVSS 10.0, plus a SQL injection, fixed in 4.1.64. Install 4.1.66.
- Why PHP 8.5.7 Shows Amber When PHP 8.4.24 Shows Green
PHP 8.5.7 shows amber while 8.4.24 shows green because the badge checks whether you are on the newest patch in your branch, not which branch you picked.
- Phoca Cart 5.2.4, 6.1.7 and 4.0.13 fix a front-end SQL injection
Phoca Cart 5.2.4, 6.1.7 and 4.0.13 patch an unauthenticated SQL injection in the Joomla extension's product filter. Joomla 5 on 6.x isn't offered it.
- The Fabrik Fiasco: Announced, Restricted, Relabelled
Two CVSS 10.0 RCEs in the Fabrik Joomla extension, and a chaotic run of security releases since. The vendor has moved past 4.7.0; be on 4.7.2.
- Events Booking for Joomla: Anyone Could Upload Files to Your Server
mySites.guru found two unauthenticated flaws in Events Booking for Joomla: file upload enabled by default, and a leak of every user's name and email.
- JoomShaper Patched the Joomla 3 It Said It Never Would
Six days after excluding Joomla 3 security patches, JoomShaper shipped them for Helix Ultimate, Helix3 and SP Page Builder. What is in them.
- The One-Click Way to Patch JoomShaper Extensions on Joomla 3
mySites.guru backports JoomShaper's security fixes into SP Page Builder, Helix3 and Helix Ultimate on Joomla 3, across every site in your account.
- Unauthenticated SQL Injection in DPCalendar found by mySites.guru
mySites.guru found and reported an unauthenticated SQL injection in the DPCalendar Joomla extension's public events feed. Fixed in 10.11.2 and 8.19.4.
- JoomShaper Ends Joomla 3 Security Fixes
JoomShaper ended Joomla 3 support with no security fixes regardless of severity, then reversed the security half six days later and shipped patches.
- How to Prevent Accidental Joomla Version Jumps with Update Channel Management
One wrong Joomla update channel setting can jump your site from Joomla 4 to 5 or 5 to 6. Here is how mySites.guru detects and prevents this.
- End-of-Life Version Support in mySites.guru
mySites.guru monitors end-of-life Joomla and WordPress versions from 1.5 to 6, alerting you when sites run unsupported software that puts them at risk.
- Migrating to Modern Joomla When Using mySites.guru
How to keep your sites connected to mySites.guru when migrating from Joomla 3 to Joomla 4, 5, or 6. Step-by-step connector swap process.
The full archive, including posts on WordPress and general site management, is on the mySites.guru blog.
Keeping Joomla 3 patched is part of the subscription
The one-click core patch, JoomShaper's Joomla 3 packages, vulnerable extension alerts and malware scanning are all included, alongside everything else mySites.guru does for Joomla and WordPress. No per-site fees, and no price increases since 2012.
Keep your Joomla 3 sites patched while you plan the move
One free audit of one site, no card, no time limit.