Joomla Hub
СтатистикаNews of Joomla community: latest updates, useful tutorials, new extensions and templates, upcoming events and all that makes #Joomla heart beating ♥️ Group for discussions: @joomlatalks
- Последний пост
- 11:55
- Последнее чтение
- 23:30
- Постов за неделю
- 6
- Всего постов
- 36
- Тип
- открытый
- Язык
- английский
- Категория
- Новости и СМИ
- В каталоге с
- 13 авг.
- 1/24сутки в ленте
- 132
- 1/48двое суток
- 151
- 1/72трое суток
- 163
Оценка по просмотрам недавних постов: пост набирает почти всё за первые сутки.
Посты
HikaShop 6.5.1 HikaShop 6.5.1 is a big release. It makes the storefront markedly faster with full-text product search and a switch to the InnoDB database engine, adds calendar-based product variants, PayPal express checkout, next-generation AVIF images, smarter product filters and per-product option controls. In total this release brings 20 new features, 17 improvements, and 51 bug fixes. Read more HikaShop 6.5.2 - security release HikaShop 6.5.2 fixes a security issue along with several bugs, and we recommend that all merchants update. The authors fixed a medium severity open redirect vulnerability in the currency switcher. Read more HikaShop is a flexible, feature-rich e-commerce extension (free and paid versions)
Phoca Cart 5.2.4 and 6.1.7 fix a front-end SQL injection A critical SQL injection vulnerability has been discovered in Phoca Cart for Joomla, potentially allowing unauthenticated attackers to access or manipulate database data. 🔴 Affected: Phoca Cart 5.2.3 and earlier, 6.1.6 and earlier ✅ Fixed: 5.2.4 and 6.1.7 ⚠️ Severity: CVSS 9.3 (Critical) Joomla site owners using Phoca Cart should update immediately. 👉 Full technical details
Meet Hanna Znanewitz at Joomla World Conference 2026! As Content Manager at YOOtheme, Hanna has played a key role in helping users get the most from YOOtheme Pro. From documenting features and creating tutorials to presenting new releases, she specialises in turning complex concepts into clear, practical knowledge. At JWC 2026, Hanna will explore: Next generation of YOOtheme Pro, designed AI-first from the ground up! Discover how AI is shaping the future of website building, how YOOtheme Pro is evolving to embrace this new era, and what it means for designers, developers and site builders working with Joomla. Whether you're already using YOOtheme Pro or simply curious about the future of AI-powered web development, this is a session you won't want to miss. 📍 Joomla World Conference 2026 📅 16-18 October 2026 📌 Potsdam/Berlin, Germany
Joomla 6.1.2 and 5.4.7 Silently Ignore Every Article Option You set an Alternative Layout on a Joomla article. The front end ignores it and renders the default. The custom fields that layout was supposed to show have apparently vanished. So you clear the Joomla cache, purge Cloudflare, rebuild the menus, reinstall the template, and check the article again. Nothing has changed. The article is fine. Your template is fine. Joomla 5.4.7 and 6.1.2 both carry a core regression that throws away every Option you set on an individual article and renders the menu item or global value instead. Both versions shipped on 7 July 2026, and both are still the newest stable release on their branch. That is the part that stings: the people who updated promptly are exactly the ones who got hit, and as of 10 August 2026 there is no released Joomla version you can update to that fixes it. Read more
A Joomla 3 component to migrate K2 content into Joomla core content It convert sK2 categories, items, tags, extra groups, and extra fields to Joomla core structures. See on Github
🚀 NorrCompetition User Points Pack is here! Turn your NorrCompetition contests and voting campaigns into a monetization tool. With User Points Pack, you can create rules that credit or debit points for user actions. For example, require 2 points for a vote and let users purchase points through your connected e-commerce store. 🗳️ Set a cost for voting 💳 Sell points through your online store ➕ Connect products with points 💰 Monetize contests and voting campaigns ⚙️ Create flexible point rules for NorrCompetition 💳 Use popular or local Payment Service Provider to accept payments through your store Give users a reason to purchase points — and turn participation into revenue. AltaUserPoints or any 3rd party extension is no longer needed for points system. Use native addon instead Links: — Product page — Read the announcement
Joomla 6.1: the Native Feature Behind a Clean Frontend-Only Author Split A foundational tutorial on running a multi-author Joomla blog when one of your writers is frontend-only. Joomla 6.1 added a small but genuinely useful piece for this: a Current User filter on an author's own content list. This video builds the full access boundary around it, native Joomla only, no extensions. - Denying backend login for one group without touching its parent group's rights - Edit Own, checked per article rather than per person - Why a saved article can vanish from its own author's list (and why that's correct) - A lightweight content workflow built for a small editorial team - Zero extra extensions Watch video
🛒 Phoca Cart 6.1.6 Released A new maintenance update for Phoca Cart, the Joomla eCommerce extension, is now available. Version 6.1.6 focuses on bug fixes, stability improvements, and updated core extensions to ensure better compatibility and reliability for Joomla 6 websites. As always, keeping your store up to date is recommended. 📥 Read more and view the changelog
Kunena 6.4.13 - Security Fix Release The Kunena team is thrilled to announce the thirteenth release (security release) of Kunena 6.4. It needs the compatbility plugin to be enabled to be installed on Joomla! 6.0.x, this release (K6.4.13) is offered for people already on Joomla! 6.0 to be able to update to K7.0.x. The work done in Kunena 6.4 is the following: ✔️ Some security issues fixed - thanks to ruud to have reported them ✔️ Some security issues fixed - thanks to pbugbounty to have reported them ✔️ And more changes Read more
Joomla! 6.2 is on the way! Want to help squash bugs, test new features, and hang out with the community? Join our Joomla! Hands-On Day — online or in person. No experience needed, just enthusiasm. August 21-22 2026. https://www.pizza-bugs-fun.com/
Convert Forms. A Security Update: Unauthorized Access to Form Submissions Convert Forms can display a form's submissions on the front end through the Submissions menu item type, so that people can review what they have sent you. The issue is tracked as CVE-2026-65758. The author reviewed the code, enforced proper access control on that view, and shipped a patched version. The issue is fully resolved in Convert Forms 5.2.4. Read more
Another 23 Critical Security Vulnerabilities in Gridbox for Joomla Gridbox is a widely used drag-and-drop page builder for Joomla, built by Balbooa. On the sites we can see it running, it is usually the thing the whole front end depends on. mySites.guru: We disclosed a critical authentication bypass in Gridbox, CVE-2026-61425, fixed in 2.20.1. Balbooa’s response to that was to ask us to look harder: they invited a full security review of the component. We did it. This is what we found, and it is worse than any of us expected. Twenty-three distinct vulnerabilities in one Joomla extension, including a pre-authentication remote code execution reachable in a single HTTP request. It took Balbooa three attempts to close them all, and the complete fix is now out as Gridbox 2.20.2. Read more
без подписи
Action required: Important Security Update for SP Page Builder 🚨 The developers just released an important security update, SP Page Builder v6.7.1, that patches several vulnerabilities. It is recommended updatinf to the latest version immediately. ✅ Applies to both Pro and Free users. What’s been fixed: 🛠️ Dynamic Content: tighter access control on the Tags sorting feature 🛠️ Media Manager (search/filters): stronger validation on search/date filters 🛠️ Media Manager( file deletion): file deletion now restricted to the intended media folder 🛠️ Contact Form/Form Builder: submission verification now uses unique, site-specific keys 🛠️ Anti-spam: fixed a bypass in the built-in security question check ⚡ Update now via System → Update → Extensions in your Joomla admin panel, or download the latest package from authors’ site.
More Joomla events are just around the corner Join us and be part of what’s ahead. Find the next events: https://community.joomla.org/events.html
Pre-Authentication SQL Injection and Mail Relay in SP Page Builder SP Page Builder is JoomShaper’s drag-and-drop page builder for Joomla, one of the most widely installed page builders in the ecosystem. During a later audit of SP Page Builder 6.7.0, mySites.guru found four further vulnerabilities, and reported them to JoomShaper before disclosing anything publicly. JoomShaper closed all four in SP Page Builder 6.7.1. Read more
Joomla! is looking for application for the "Milestone 1b - Remediation Plan, Quick Wins and Community Publication" as part off the 20-month accessibility improvement programme supported by the Sovereign Tech Fund. Read more
Phoca Commander Version 6.1.2 Released - Security Release What’s inside? ☑️ Fixed possible XSS issue ☑️ Fixed possible Write/RCE and Read/disclosure issue (further details will be provided in an external advisory) Phoca Commander is Joomla! CMS component - it is dual panel file manager (like Total Commander, Midnight Commander, Krusader, ...) working in Joomla! administration. Read more
Meet Adam Melcher at Joomla World Conference 2026! Over more than 15 years, he has helped businesses transform Joomla's flexibility into high-performing online stores, membership platforms and booking systems that deliver results under real business pressure. As co-founder and lead developer of J2Commerce alongside Olivier Buisard, Adam has helped create one of Joomla's leading ecommerce extensions. At JWC 2026, Adam will present: The Million-Dollar Joomla Site: How J2Commerce Turns Traffic Into Revenue Discover how businesses are using Joomla and J2Commerce to build scalable ecommerce platforms that generate real business growth. Adam will share practical examples of how organisations are opening new revenue streams, simplifying their technology stack and preparing for the future with modern, AI-ready ecommerce solutions built natively on Joomla. 📍 Joomla World Conference 2026 📅 16-18 October 2026 📌 Potsdam/Berlin, Germany
VirtueMart (com_virtuemart) below 4.4.11 - Unauthenticated Reflected XSS and Authenticated SQL Injection VirtueMart e-commerce component. CVE-2025-55757 (unauthenticated reflected XSS, affects 1.0.0-4.4.10) and CVE-2025-25228 (authenticated SQL injection in product management, affects 1.0.0-4.4.7). Fixed in 4.4.11. Rule pinned to component type because the Xmap and OSMap VirtueMart bridge plugins ship under element com_virtuemart at their own low versions. https://nvd.nist.gov/vuln/detail/CVE-2025-55757 https://github.com/AdamWallwork/CVEs/tree/main/2025/CVE-2025-55757