Skip to main content
Blog

Joomla 5.4.2 bugfix & security release

06 January 2026

On Tuesday, January 6, 2025, Joomla 5.4.2 was released, together with Joomla 6.0.2. These are bugfix & security releases for the Joomla 5.x and 6.x series.

Security fixes

  • Joomla! Core - [20260101] - Inadequate content filtering for data URLs
    A security issue where images could be abused to inject harmful code;
    it affects older Joomla versions (Joomla 4.0.0-5.4.1, 6.0.0-6.0.1) and is solved by updating to 5.4.2 or 6.0.2.
  • Joomla! Core - [20260102] - XSS vector in the pagebreak plugin
    A security flaw in the pagebreak feature that could allow unwanted code on a website;
    it also affects older Joomla versions (Joomla 3.9.0-5.4.1, 6.0.0-6.0.1) and is fixed by updating to 5.4.2 or 6.0.2.

PHP 8.5

Starting with Joomla! 5.4.2 and Joomla! 6.0.2, PHP 8.5 is fully supported.

Bug fixes in the Joomla 5.4.2 release

Some improvements include:

  • core editor & layout fixes: fixed content editing issues such as article version history and featured article display, making it easier to view, restore and manage content reliably.
  • interface and layout polish: resolved issues with menus and dropdowns behaving incorrectly, resulting in a smoother and more predictable admin interface.
  • correct default settings: fixed several default configuration values so new sites and modules work as expected right from the start.
  • wider platform compatibility: addressed warnings and issues on modern PHP versions, ensuring Joomla runs cleanly and safely on up-to-date hosting environments.
  • cleaner API behaviour: improved how system messages and errors are handled, so integrations and automated processes behave more consistently.
  • usability refinements: applied small interface improvements, including editor and display fixes, to make daily administration more comfortable and less error-prone.

A full list of changes is available in the 5.4.2 milestone on GitHub.

Upgrading to Joomla 6

The main purpose of the Joomla 5.4.x versions is to allow future upgrades from Joomla 5.x to Joomla 6.x. We usually upgrade a couple of our own websites to the newer version. Joomla 6 is already stable. Depending on the compatibility of the extensions used, we upgrade client websites to Joomla 6 when it's even somewhat more mature, so when it reached Joomla 6.1

Need help updating or migrating to Joomla 6? Contact us!

Other articles

Correspondence

db8 Website Support
Galiciestraat 35
6663 NR Lent
The Netherlands

+31 85 301 48 28
support at db8 dot nl
+31 6 44 214 500 (urgent)

Nijmegen Office

NYMA makersplaats, Unit 69
Winselingseweg 16
6541 AK Nijmegen
Netherlands

By appointment
Monday to Friday
09:00 - 17:00 (5pm)
(Time zone: Central European Time)

Acquisition is
not appreciated

© db8.nl. All rights reserved.