Skip to main content
Blog

Joomla 5.4.9 security- and bugfix release

29 September 2026

On Tuesday 29 September 2026, the Joomla! Project released Joomla 5.4.9. This is a security- and bugfix release for the Joomla 5.x series, with more than 50 improvements and fixes.

Known issue with Joomla 5.4.9

After the release, an issue with the Web Services API was discovered: PATCH requests fail. When you try to update an item, for example a banner or user entry, using the Web Services API, the PATCH request fails with a fatal error. A workaround is to use a temporary fix that also will be included in Joomla 5.4.10. Full details: https://manual.joomla.org/updates/53-54/known-issues/5.4.9/

Security fixes for Joomla 5.4.9

Joomla 5.4.9 includes 16 security fixes. These address several vulnerabilities in the Joomla core, including cross-site scripting (XSS), access control issues, server-side request forgery (SSRF) and an MFA authentication bypass.

  • Cross-site scripting (XSS)
    Several XSS vulnerabilities have been fixed in Joomla, including issues in HTML links, media layouts, HTML mail templates, toolbar links and module lists.
  • Access control (ACL) improvements
    Multiple issues with insufficient permission checks have been resolved. These affected webservice endpoints, content history, tagged items, workflow stage changes and several webservice editing tasks.
  • Unauthorized account creation
    A vulnerability in the user profile controller that could allow unauthorized user account creation has been fixed.
  • MFA authentication bypass
    Joomla fixes an issue where remember-me cookies could potentially be used to bypass Multi-factor Authentication (MFA).
  • Server-side request forgery (SSRF)
    Several potential SSRF vectors in Joomla core extensions have been addressed.
  • Input filtering improvements
    Two vulnerabilities that could bypass Joomla's XSS filtering have been fixed, involving HTML5 entity decoding and whitespace characters in HTML data URIs.
  • Cache directory deletion
    A vulnerability in the cache purge functionality that could allow arbitrary directory deletion has been resolved.

Because Joomla 5.4.9 contains multiple security fixes, we recommend updating existing Joomla 5.x websites as soon as possible.

Bug fixes in Joomla 5.4.9

  • Improvements to the Template Manager
    Several issues in the Template Manager have been resolved. This includes errors when working with template files and archives, warnings when source files are unavailable and improvements to the handling of template overrides.
  • Improved tag handling
    Fixes several issues with Joomla tags, including duplicate aliases and incorrect URL parameters in tag menu items. This makes working with tags more reliable.
  • Improved Smart Search with PostgreSQL
    Fixes an issue with the Smart Search indexer when Joomla is running on a PostgreSQL database.
  • Better multilingual category associations
    Category associations are no longer lost when a translated category is unpublished. This makes multilingual websites more reliable when content is temporarily unpublished.
  • Improved Schema.org structured data
    Corrects the output of structured data used by search engines. Logo URLs in Schema.org JSON-LD are now generated as absolute URLs, and invalid values in JobPosting structured data have been corrected.
  • Improved accessibility of the calendar
    The Joomla calendar has improved keyboard navigation, making date selection easier for users who navigate websites without a mouse.
  • Improved two-factor authentication
    TOTP verification now uses a safer comparison method when checking authentication codes.
  • Improved article category filtering
    The filter button in the article category list is now displayed correctly, making it easier to filter articles in the administrator interface.
  • Better handling of custom fields
    Fixes duplicate options appearing in fields and resolves an issue with image list custom fields on servers that use PHP's open_basedir restriction.
  • Improved article modules
    When article intro text is automatically shortened by the Articles module, Joomla now correctly displays the Read More link.
  • Improved alternative layouts
    Joomla now correctly respects the option and title attributes defined in XML files for alternative layouts.
  • More robust server compatibility
    Joomla now handles situations where the PHP php_uname() function is unavailable or disabled, preventing unnecessary errors on restricted hosting environments.
  • Updated translations
    Various language files and translations have been updated, ensuring that text in Joomla is displayed more accurately and consistently.
  • General stability improvements
    Joomla 5.4.9 also includes various smaller bug fixes, tests and technical improvements that make Joomla 5.4 more stable and reliable.

Please note: do not upgrade directly to Joomla 5.x from a version older than 4.4. First upgrade to Joomla 4.4 and only then to Joomla 5.x.

The full list of changes can be found in the 5.4.9 milestone on GitHub.

Upgrading to Joomla 6

The main aim of the Joomla 5.4.x releases is to prepare website owners for a smooth transition from Joomla 5.x to Joomla 6.x. We build all new websites directly on Joomla 6.x. We upgrade existing websites as soon as the hosting environment, including the PHP and database versions, and all installed extensions are fully compatible with Joomla 6.

Need help updating or migrating your website to Joomla 6? Please feel free to contact us!

Peter Martin
Peter Martin
Joomla Specialist

Peter is a Joomla specialist en a Linux admin for fast, secure and scalable websites..

Recent articles

Correspondence

db8 Website Support
Galiciestraat 35
6663 NR Lent
The Netherlands

+31 85 301 48 28
support at db8 dot nl
+31 6 44 214 500 (urgent)

Nijmegen Office

NYMA makersplaats, Unit 69
Winselingseweg 16
6541 AK Nijmegen
Netherlands

By appointment
Monday to Friday
09:00 - 17:00 (5pm)
(Time zone: Central European Time)

Acquisition is
not appreciated

© db8.nl. All rights reserved.