Skip to main content
Blog

Joomla 5.2.6 security release

On Tuesday, April 8, 2025, Joomla 5.2.6 was released. This is a security release that fixes a security issue in Joomla 5.x related to the Multi-Factor Authentication (MFA).

Fixed security issue

This security update fixes two security issues in Joomla:

  • [20250401] - Framework - SQL injection vulnerability in quoteNameStr method of Database package
  • [20250402] - Core - MFA Authentication Bypass

The update fixes a security problem with missing checks that could lead to a way to skip the two-step verification. It also fixes an issue with the quoteNameStr database package.

This is really the last release in the Joomla 5.2 series. The release of Joomla 5.3 is planned for Tuesday, April 15, 2025. Upgrading from Joomla 5.2 to Joomla 5.3 will be a regular update.

Need help updating or migrating to Joomla 5.2? Contact us.

Correspondence

db8 Website Support
Galiciestraat 35
6663 NR Lent
The Netherlands

+31 85 301 48 28
support at db8 dot nl
+31 6 44 214 500 (urgent)

Nijmegen Office

Zes Huizenhof 30
6511 EA Nijmegen
Netherlands

By appointment
Monday to Friday
09:00 - 17:00 (5pm)
(Time zone: Central European Time)

Acquisition is
not appreciated

© db8.nl. All rights reserved.