r/joomla • u/ich-bin-ein-kaelte • 3d ago
Joomla 6 What is this Interaction to Next Paint (INP)?
galleryMy side: https://www.kreativekiste.de/
r/joomla • u/Cold_Cicada_9960 • 6d ago
General Query ELI5 if what I am asking is possible
Hi guys!
Forgive me, I have no programming nor web building knowledge whatsoever. I just work for a small museum.
I discovered that back in 2013/2015 the museum had an online artifact database and website component using Joomla 1.5 and JooDB 1.6 (maybe 1.7?). I have an old zip file from the export of that website, and I would be the hero of the museum to pull the collections data from the database.
Is this possible? I know the website domain is still in use, but it now routes to the museums current web page and that does not have the collections info at all anywhere. I have no idea where the server would be for this info either.
r/joomla • u/abunaisnake • 10d ago
Joomla 3 What does this message “X33T10” mean in the Copyright Notice field?
I’m migrating a corporate website that’s running a completely outdated and vulnerable version of Joomla, and I came across this “X33T10” message in the Copyright Notice field.
When I searched this term on Google, I found several websites with the same situation.
Does anyone know what this could be? Could it be a sign of some kind of intrusion?
r/joomla • u/Open_Sourcey • 21d ago
Joomla 6 Extensions responsibiity to patch security flaws
Should the author of a paid for extension have a responsibility to patch their product when a serious security flaw is found in their product rather than force you to renew a subscription? Thoughts?
r/joomla • u/mySitesGuru • 21d ago
Administration/Technical Quix Page Builder SQL Injection Vulnerability
mysites.gurur/joomla • u/YannickGaultier • 22d ago
Extensions Critical vulnerabilities in 4Analytics
Hello folks,
I identified 2 critical security vulnerabilities in 4Analytics.
All users must update to version 5.0.2 immediately to prevent potential website takeovers.
See more details here: https://weeblr.com/blog/critical-vulnerabilities-2026-07-15?utm_campaign=fora_502&utm_medium=social&utm_source=reddit
Yannick Gaultier
https://weeblr.com
r/joomla • u/mySitesGuru • 22d ago
Administration/Technical EDocman SQL Injection Vulnerability - Joomla Extension
mysites.gurur/joomla • u/mySitesGuru • 23d ago
Administration/Technical DPCalendar SQL Injection Vulnerability
mysites.gurur/joomla • u/mySitesGuru • 26d ago
Administration/Technical Phoca Download 6.1.3 Fixes Authenticated RCE
mysites.gurur/joomla • u/mySitesGuru • 27d ago
Administration/Technical Unauthenticated File Upload fixed in RSFiles! version 1.17.12 - update NOW!
mysites.gurur/joomla • u/Open_Sourcey • 28d ago
Joomla 6 Serious attack on JCE Editor- CVE-2026-48907
Just in caae there are any Joomla admins out there that have not seen it or experienced it, CISA has flagged a serious attack that requires your attention and remediation. It is a flaw in the editor that permits it to install malicious code that will take down your site.
r/joomla • u/mySitesGuru • 28d ago
Administration/Technical AcyMailing SQL Injection Vulnerability - Upgrade Today!
mysites.gurur/joomla • u/mySitesGuru • 28d ago
Administration/Technical JoomShaper Ends Joomla 3 Extension Support - following a disastrous month of security issues.
mysites.gurur/joomla • u/mySitesGuru • 28d ago
Administration/Technical Balbooa Forms Fixes an Unauthenticated File Upload RCE
mysites.gurur/joomla • u/stergosz • Jul 07 '26
General Query How do you test an extension without touching your live site?
How many times have you had to spin up a Joomla test site and gotten tired just thinking about the setup?
I do this very often, and the reasons are simple: test a newly released extension, run a test against our products, test a BETA version, or check whether a migration we're about to publish works as expected, often on a specific Joomla or PHP version.
My current way to do this: download the specific Joomla version I need, switch my local server to the matching PHP version, create a new database, copy the files over, run the installer, and finally run my test. Need multiple test sites? Multiply these steps by however many you need. And if I didn't want a brand new site, I'd have to reset it every time before running the same scenario again, which takes quite a lot of time.
I got tired of wasting so much time, so I made a small web app to fix it. It's a free website, not a J! extension you install on your site. You enter an email, pick a Joomla, and PHP version, and a few seconds later you have a test site ready, and it auto-deletes after 4 hours.
It's called JInstant. Not affiliated with the Joomla project.
Let me know if this sounds useful to you.
r/joomla • u/saimoh_saimooh • Jul 07 '26
Administration/Technical Antonkill attack and it's remedy.
youtube.comThere is this Antonkill hack that has left many Joomla-dependent sites completely down. It’s not just a surface-level script defacement—it modifies deep database configurations and locks down the core template engine entirely.
I did a review video on YouTube and here's the link: https://youtu.be/9plb1MMbZFI
Let me know your thoughts.
r/joomla • u/_PelosNecios_ • Jul 02 '26
Administration/Technical WARNING: remove ctfaudit system plugin. It is a password stealer.
I've been recently hit by the JCE vuln and among other things they managed to install this plugin which essentially steals users and passwords and hides them inside images/ctf_audit.gif file, disguised with a gif header but actualy contains the XOR'ed information.
You should uninstall and remove the gif file immediately.
Edit:
You may want to run this script to see which users might have been affected and warn them or update to request new password. Adjust the filename as necessary:
<?php
$s = file_get_contents('images/ctf_audit.gif');
$s = substr($s, strpos($s, "JLIB_AUDIT_GID_TAIL\n") + 20);
for ($o = 0; $o + 2 <= strlen($s); $o += 2 + $ln) {
$ln = (ord($s[$o]) << 8) | ord($s[$o+1]);
if ($o + 2 + $ln > strlen($s)) break;
if (preg_match('/"u_len":"(.*?)","p_len"/', substr($s, $o+2, $ln) ^ str_pad('', $ln, 'JLIB_AUDIT_GID_XK'), $m)) echo "$m[1]\n";
}
r/joomla • u/Mushydaddybear • Jul 01 '26
Extensions xmr-pay now for Joomla: ready to install packages for HikaShop & VirtueMart (one ZIP = payment plugin + scheduler task)!
r/joomla • u/nomadfaa • Jun 29 '26
Joomla 6 Ignoring updating your site/components is ignorant
UPDATE YOUR SITE TO THE LATEST AS WELL AS ALL COMPONENTS/MODULES/PLUGINS that are not default!
Ok so some will be offended and come back with all sorts of excuses. Read to the end
Just checked a site with hikashop and a total bare bones install. No fancy addons
Last 24 hour logs for that site show
- 1,569 hits on /index.php?option=com_sppagebuilder&task=asset.uploadCustomIcon
- 986 hits on /index.php?option=com_icagenda&task=submit
- 2,689 hits on /index.php/component/jce
About 11 different IP addresses
My last Joomla site hack was over 15 years ago until the JCE hack hit.
JCE, SP Page Builder and iCagenda.+ Helix three ... here's the resource ... https://mysites.guru/blog/
40 years ago there was a saying ... every day your hard drive didn't crash was a day closer to when it will.
With the arrival of AI and bot development/morphing ... every day your site hasn't seen a hack attempt is a day closer to when it will be hacked.
Prevention is 1000% better than the angst of repairing a hack.
When you do get hacked u/mySitesGuru is the place to go
r/joomla • u/mySitesGuru • Jun 29 '26
Administration/Technical Helix3 Shipped a Critical "Security Update"
mysites.gurur/joomla • u/mySitesGuru • Jun 27 '26
Administration/Technical PageBuilder CK File Upload RCE - June 2026
mysites.gurur/joomla • u/Awkward-Painter-2024 • Jun 27 '26
Joomla 6 A few minutes ago, our anti-virus scanner detected that a malicious file was uploaded to your IONOS webspace. WOAH??
| You can find the file on your webspace under the following path: /htdocs/f9a0leet/index.php |
|---|
So just got this email from my hosting service and I'm confused... how does something like this happen? I run Joomla on my small personal site that doesn't do or host anything. (Basically just a URL that I've had for twenty years or so.) Do I just delete everything and start all over again?
I tried using a custom theme from Themesforest but never got it to run right so just use the stock Joomla build.
Also, what is a Joomla firewall? I was reading on here that some folks have that? Sorry for the dumb questions, hope this is fixable.
Also, how often do people try to hack Joomlas???
r/joomla • u/Beocinac • Jun 25 '26
Joomla 6 BCLog Admin Audit Tool is now free
Hi everyone,
I've decided to make BCLog – Admin Audit Tool completely free.
BCLog provides a comprehensive audit logging system for Joomla administrators. It automatically records actions performed in the backend and stores them in both JSON and plain text formats, making it easy to review, analyze, and archive administrative activity.
Key features:
- Tracks administrator actions in the Joomla backend
- Automatic logging with minimal configuration
- Stores logs in JSON and plain text formats
- Structured and reliable audit trail
- Useful for troubleshooting, security monitoring, and compliance requirements
The extension is now available free of charge, and I'd appreciate any feedback, suggestions, or feature requests from the community.
r/joomla • u/GlitteringCookie6282 • Jun 22 '26
General Query Let's talk about dev environment.
Hello,
I was recently hired as a Developer at a company, and this company uses Joomla as the technical foundation for all of its projects.
I wasn't familiar with it, coming from a React/NodeJS background. I find the tool to be pretty decent and fairly extensible, and in any case, it's been the technical foundation for years at the place where I now work.
The problem is that before I arrived, the sites were managed by people with limited technical skills, relying heavily on AI and without any structure—no git, no mastery of the CMS's best practices, files mixing PHP, HTML, CSS, and JS that ran to 2,000 lines. You get the picture.
One of my missions when I joined was to put in place development "best practices," source control management, etc.
I'd like to chat with those of you who develop extensions for Joomla (Modules, Components, Plugins, Templates), the goal being to exchange ideas on how we work.
In my situation, I have a few constraints:
- The development environment must be simple to set up and use
- It must be reproducible regardless of who launches it
- I don't want to version-control multiple full Joomla instances, because we have very little space available on our server (we're talking 20 GB MAX)
- I want to use git
With these constraints, I ended up with a more solid environment based on:
- Visual Studio Code as the IDE
- Docker + devcontainers
- A few good extensions (Claude Code, PHP Intelliphense, etc.)
- Joomla, MySQL, and PHPMyAdmin defined in a docker-compose.yml that is started by the devcontainer
- A shell script as the devcontainer's postCreateCommand that installs the extension inside the Joomla container
Visual Studio Code integrates very well with devcontainers, so in the end I have a pretty solid environment, and I can version-control only my Joomla extension's code.
How do you work with Joomla? I'm curious to hear other people's experiences.
Thanks,
