🏠 Home πŸ–₯️ Hosting 🎨 Themes πŸ”Œ Plugins πŸ› οΈ Dev Tools ⚑ WordPress πŸ”₯ Joomla!
News

Joomla 6.1.2 & 5.4.7 Released: 12 Security Fixes Explained (July 2026)

Joomla 6.1.2 & 5.4.7 Released: 12 Security Fixes Explained (July 2026)

Quick Answer

Joomla released 6.1.2 and 5.4.7 on July 7, 2026 to patch 12 security issues (mostly access-control and XSS flaws). There's also a known bug affecting article layouts on category and menu pages β€” a hotfix patch is available now, with a full fix coming in 5.4.8 / 6.1.3.

Joomla admin panel showing successful update to version 6.1.2
Joomla admin panel showing successful update to version 6.1.2

The Joomla Project shipped Joomla 6.1.2 and Joomla 5.4.7 as security and bugfix releases on July 7, 2026. Both versions carry the same 12 security patches, plus dozens of smaller bug fixes merged up from the 5.4 branch into 6.1.

Known Issue: Article Layout Settings Ignored

⚠️ Affects sites using category or menu-linked articles

When an article is displayed via a category layout or a single-article menu item, Joomla now ignores the article's own layout settings and falls back to the menu item or global settings instead β€” causing the wrong layout to render. This affects any front-end article with custom, article-specific parameters.

Workaround: a permanent fix is scheduled for Joomla 5.4.8 and 6.1.3. Until then, apply the official hotfix patch:

12 Security Fixes in This Release

All fixes are Core-level and cover Joomla 5.x and 6.x. Most are access-control gaps or cross-site scripting (XSS) issues β€” no remote code execution flaws were disclosed.

IDComponentIssue Type
20260701com_media (webservice)Incorrect access control
20260702com_contact (vCard download)Incorrect access control
20260703MFA method managementXSS
20260704com_templatesXSS
20260705Modal-return layoutsXSS
20260706com_installerXSS
20260707Generic image output layoutXSS
20260708Language overridesXSS
20260709com_workflowIncorrect access control
20260710com_modulesIncorrect access control
20260711com_privacy (webservice)Incorrect access control
20260712com_fields (webservice)Incorrect access control

Should You Upgrade Now?

Joomla 5.4.x is still supported with bugfix patches until October 13, 2026 and security patches until October 12, 2027 β€” so there's no immediate risk if you stay on 5.4.7 rather than jumping to 6.1.2. Moving from 5.4.x to 6.x is an in-place upgrade, not a migration: extensions with no deprecated code will keep working, and most others work with the new Behaviour 6 backward-compatibility plugin enabled.

Before upgrading

Test on a staging copy first, and check your installed extensions' Joomla 6 compatibility status in the Joomla Extensions Directory.

Where to Download

βœ… Last verified on Joomla 6.1.2 / 5.4.7 β€” July 2026

Stephen
Stephen
CEO, Founder & Joomla Product Creator

Stephen is the CEO and Founder of Jlvextension, known for creating high-quality Joomla templates and leading the development of innovative web solutions.