
Joomla 5.4.9 security- and bugfix release
On Tuesday 29 September 2026, the Joomla! Project released Joomla 5.4.9. This is a security- and bugfix release for the Joomla 5.x series, with more than 50 improvements and fixes.
Known issue with Joomla 5.4.9
After the release, an issue with the Web Services API was discovered: PATCH requests fail. When you try to update an item, for example a banner or user entry, using the Web Services API, the PATCH request fails with a fatal error. A workaround is to use a temporary fix that also will be included in Joomla 5.4.10. Full details: https://manual.joomla.org/updates/53-54/known-issues/5.4.9/
Security fixes for Joomla 5.4.9
Joomla 5.4.9 includes 16 security fixes. These address several vulnerabilities in the Joomla core, including cross-site scripting (XSS), access control issues, server-side request forgery (SSRF) and an MFA authentication bypass.
- Cross-site scripting (XSS)
Several XSS vulnerabilities have been fixed in Joomla, including issues in HTML links, media layouts, HTML mail templates, toolbar links and module lists. - Access control (ACL) improvements
Multiple issues with insufficient permission checks have been resolved. These affected webservice endpoints, content history, tagged items, workflow stage changes and several webservice editing tasks. - Unauthorized account creation
A vulnerability in the user profile controller that could allow unauthorized user account creation has been fixed. - MFA authentication bypass
Joomla fixes an issue where remember-me cookies could potentially be used to bypass Multi-factor Authentication (MFA). - Server-side request forgery (SSRF)
Several potential SSRF vectors in Joomla core extensions have been addressed. - Input filtering improvements
Two vulnerabilities that could bypass Joomla's XSS filtering have been fixed, involving HTML5 entity decoding and whitespace characters in HTML data URIs. - Cache directory deletion
A vulnerability in the cache purge functionality that could allow arbitrary directory deletion has been resolved.
Because Joomla 5.4.9 contains multiple security fixes, we recommend updating existing Joomla 5.x websites as soon as possible.
Bug fixes in Joomla 5.4.9
- Improvements to the Template Manager
Several issues in the Template Manager have been resolved. This includes errors when working with template files and archives, warnings when source files are unavailable and improvements to the handling of template overrides. - Improved tag handling
Fixes several issues with Joomla tags, including duplicate aliases and incorrect URL parameters in tag menu items. This makes working with tags more reliable. - Improved Smart Search with PostgreSQL
Fixes an issue with the Smart Search indexer when Joomla is running on a PostgreSQL database. - Better multilingual category associations
Category associations are no longer lost when a translated category is unpublished. This makes multilingual websites more reliable when content is temporarily unpublished. - Improved Schema.org structured data
Corrects the output of structured data used by search engines. Logo URLs in Schema.org JSON-LD are now generated as absolute URLs, and invalid values in JobPosting structured data have been corrected. - Improved accessibility of the calendar
The Joomla calendar has improved keyboard navigation, making date selection easier for users who navigate websites without a mouse. - Improved two-factor authentication
TOTP verification now uses a safer comparison method when checking authentication codes. - Improved article category filtering
The filter button in the article category list is now displayed correctly, making it easier to filter articles in the administrator interface. - Better handling of custom fields
Fixes duplicate options appearing in fields and resolves an issue with image list custom fields on servers that use PHP'sopen_basedirrestriction. - Improved article modules
When article intro text is automatically shortened by the Articles module, Joomla now correctly displays the Read More link. - Improved alternative layouts
Joomla now correctly respects theoptionandtitleattributes defined in XML files for alternative layouts. - More robust server compatibility
Joomla now handles situations where the PHPphp_uname()function is unavailable or disabled, preventing unnecessary errors on restricted hosting environments. - Updated translations
Various language files and translations have been updated, ensuring that text in Joomla is displayed more accurately and consistently. - General stability improvements
Joomla 5.4.9 also includes various smaller bug fixes, tests and technical improvements that make Joomla 5.4 more stable and reliable.
Please note: do not upgrade directly to Joomla 5.x from a version older than 4.4. First upgrade to Joomla 4.4 and only then to Joomla 5.x.
The full list of changes can be found in the 5.4.9 milestone on GitHub.
Upgrading to Joomla 6
The main aim of the Joomla 5.4.x releases is to prepare website owners for a smooth transition from Joomla 5.x to Joomla 6.x. We build all new websites directly on Joomla 6.x. We upgrade existing websites as soon as the hosting environment, including the PHP and database versions, and all installed extensions are fully compatible with Joomla 6.
Need help updating or migrating your website to Joomla 6? Please feel free to contact us!

Peter is a Joomla specialist en a Linux admin for fast, secure and scalable websites..









