Joomla 6.1.2 & 5.4.7 Released: 12 Security Fixes Explained (July 2026)
Quick Answer
Joomla released 6.1.2 and 5.4.7 on July 7, 2026 to patch 12 security issues (mostly access-control and XSS flaws). There's also a known bug affecting article layouts on category and menu pages β a hotfix patch is available now, with a full fix coming in 5.4.8 / 6.1.3.

The Joomla Project shipped Joomla 6.1.2 and Joomla 5.4.7 as security and bugfix releases on July 7, 2026. Both versions carry the same 12 security patches, plus dozens of smaller bug fixes merged up from the 5.4 branch into 6.1.
Known Issue: Article Layout Settings Ignored
β οΈ Affects sites using category or menu-linked articles
When an article is displayed via a category layout or a single-article menu item, Joomla now ignores the article's own layout settings and falls back to the menu item or global settings instead β causing the wrong layout to render. This affects any front-end article with custom, article-specific parameters.
Workaround: a permanent fix is scheduled for Joomla 5.4.8 and 6.1.3. Until then, apply the official hotfix patch:
- Hotfix download: Joomla_5_4_7_and_6_1_2_ArticleModel_Hotfix1.zip
- Technical details: manual.joomla.org β Known Issues 6.1.2
12 Security Fixes in This Release
All fixes are Core-level and cover Joomla 5.x and 6.x. Most are access-control gaps or cross-site scripting (XSS) issues β no remote code execution flaws were disclosed.
| ID | Component | Issue Type |
|---|---|---|
| 20260701 | com_media (webservice) | Incorrect access control |
| 20260702 | com_contact (vCard download) | Incorrect access control |
| 20260703 | MFA method management | XSS |
| 20260704 | com_templates | XSS |
| 20260705 | Modal-return layouts | XSS |
| 20260706 | com_installer | XSS |
| 20260707 | Generic image output layout | XSS |
| 20260708 | Language overrides | XSS |
| 20260709 | com_workflow | Incorrect access control |
| 20260710 | com_modules | Incorrect access control |
| 20260711 | com_privacy (webservice) | Incorrect access control |
| 20260712 | com_fields (webservice) | Incorrect access control |
Should You Upgrade Now?
Joomla 5.4.x is still supported with bugfix patches until October 13, 2026 and security patches until October 12, 2027 β so there's no immediate risk if you stay on 5.4.7 rather than jumping to 6.1.2. Moving from 5.4.x to 6.x is an in-place upgrade, not a migration: extensions with no deprecated code will keep working, and most others work with the new Behaviour 6 backward-compatibility plugin enabled.
Before upgrading
Test on a staging copy first, and check your installed extensions' Joomla 6 compatibility status in the Joomla Extensions Directory.
Where to Download
- Joomla 6.1.2: downloads.joomla.org/cms/joomla6/6-1-2
- Joomla 5.4.7: downloads.joomla.org/cms/joomla5/5-4-7
β Last verified on Joomla 6.1.2 / 5.4.7 β July 2026