“October 19, 2026 J2Store 3 end of life. No further releases of any kind.”
Joomla 3 is end of life. Here is what that means for your site today.
The Joomla project stopped patching Joomla 3 on 17 August 2023. Its paid extended support ended on 17 February 2025. Security holes are still being found in the code Joomla 3 shares with Joomla 4, 5 and 6, and no official release fixes them for 3.x any more. This site keeps the dates, every vendor's position and the open holes in one place, and shows how mySites.guru patches them.
One site, one full audit, no card. Or ask us to take a free look if you are not sure where you stand.
1,142
days since Joomla 3 reached end of life
The last free release was 3.10.12 on 8 July 2023. The last paid one was 3.10.20 on 7 January 2025.
Joomla 3 sites are still out there, and they are getting hit
Measured across the Joomla sites connected to mySites.guru, which are some of the best looked-after Joomla sites there are. The real picture across the wider web is unlikely to be kinder.
Figures across sites connected to mySites.guru, 28 August 2026.
A hacked rate five times Joomla 6's is the headline, but the second figure is the useful one. Most of the Joomla 3 sites we can inspect are missing core security fixes that already exist. The fixes are published and could go on today; no one has applied them.
The third figure is the one that should worry agencies most. More than two thirds of Joomla 3 sites have not even reached 3.10.12, the last release Joomla published for free. Those sites miss years of fixes the Joomla project did ship, before you count anything found since.
The support dates
Joomla 3 was supported for almost eleven years, from version 3.0 on 27 September 2012 to its end of life in 17 August 2023, across 106 stable releases. After that a paid programme kept it patched for another eighteen months. Since 17 February 2025 there has been no official way to get a patched Joomla 3 core at any price.
Joomla 3.0 is released
The first of 106 stable Joomla 3 releases.
Joomla 4.0 is released
This starts the two-year clock on Joomla 3.
Joomla 3.10.12, the last public Joomla 3 release
Every later Joomla 3 build was paid-for eLTS.
Joomla 3 reaches end of life
Free security fixes stop. Joomla's announcement
mySites.guru launches the 3.10.999 project and the one-click Joomla 3 core patch
Community security backports for end-of-life Joomla 3 sites, applied from one toggle. The 3.10.999 project
Joomla 3.10.20, the last eLTS release
The final Joomla 3 release of any kind, available only to paying eLTS subscribers.
The paid eLTS programme ends
From here there is no official patch for the Joomla 3 core at any price.
mySites.guru adds a one-click patch for unpatched JoomShaper extensions on Joomla 3
Helix Ultimate, Helix3 and SP Page Builder, across every site in an account. How it works
The one-click Joomla 3 core patch reaches 85 files
Fourteen more core fixes, each reproduced on a real Joomla 3.10.12 install first: 84 files replaced and 1 added. Read the update
39 core security holes Joomla will never patch for 3.x
Since 3.10.12, the Joomla project has published 39 security advisories whose flawed code is also in Joomla 3. Each was fixed in a Joomla release that was still supported at the time. None has an official fix for Joomla 3, because Joomla 3 is no longer released.
- CVE-2026-92232XSS filter bypass in InputFilter via whitespace in HTML data URIs
- CVE-2026-92231XSS filter bypass in InputFilter via HTML5 entity decode mismatch
- CVE-2026-92225XSS in module list
- CVE-2026-92222SSRF vectors in various core extensions
- CVE-2026-90917Improper ACL checks in outputs for tagged items
mySites.guru backports every one of these fixes to Joomla 3.10.12 itself, tests them against a stock 3.10.12 install, and applies them to your site with one toggle. One click changes 85 core files. Switch it off and the stock files go back.
Your extensions are a separate question, and the vendors disagree
The core is rarely what gets a Joomla 3 site hacked. The extensions are. Whether a given extension still gets security fixes for Joomla 3 depends on its vendor, and the vendors have said very different things, at very different times, and often done something else.
- Said stopped, kept shipping7vendors: Said stopped, kept shipping
- Still shipping for Joomla 39vendors: Still shipping for Joomla 3
- Stopped13vendors: Stopped
- No public statement13vendors: No public statement
- Vendor gone4vendors: Vendor gone
“This is a reminder that Joomla 3.x support has come to an end.”
“Because F4 and F5 are complete rewrites of F3, none of this work will be backported to the F3 codebase.”
“upgrading Joomla remains the only meaningful long-term security solution”
“No security patches, regardless of severity”
“We're continuing the development of an open distribution of Joomla 3.x (we call it Joomla 3.x UTD for now) to ensure code security and support modern PHP versions.”
The vendors who made the loudest statements were often the ones who broke them. Several said Joomla 3 was finished and then shipped Joomla 3 security fixes anyway. Others never said anything at all, which is the common case. There is no date you can look up once and write down. mySites.guru also tracks 52 published Joomla extension vulnerabilities that apply to Joomla 3 builds, and flags every site running one.
Look up any vendor or extensionSee the Joomla 3 extension vulnerabilities
Find every unpatched Joomla 3 site you look after
Connect one site and mySites.guru audits it free, with no card. You see the core vulnerabilities still open on it, the extensions with known holes, and a one-click fix for the core ones.
What you can do about a Joomla 3 site
Which one fits depends on the site, the client and the budget. Most agencies end up using all three across a portfolio.
- Stay and patch
- Apply the backported core fixes, the vendor patches that exist, and watch the extensions. This holds a position while budget and sign-off for a move are found. It has a shelf life, because your host will eventually remove the PHP versions Joomla 3 needs.
- Migrate
- Move to Joomla 5 or 6. From Joomla 3 this is closer to a rebuild than an upgrade, because templates and several extensions usually have no direct successor, so it is a cost conversation with the site owner.
- Both
- Patch every Joomla 3 site now, then migrate them one at a time in the order the risk and the budget allow. This is what most of the agencies we work with do.
Compare the options, including the community rescue projects
How mySites.guru keeps Joomla 3 sites secure
All of this is part of the mySites.guru subscription, for every Joomla 3 site you connect, alongside everything else it does for Joomla and WordPress.
One-click core patches
Every one of the 39 core advisories, backported to 3.10.12, applied with one toggle per site or across every site at once, and reversible. No eLTS licence needed.
How the core patch worksJoomShaper's own Joomla 3 packages
The vendor's security packages for Helix Ultimate, Helix3 and SP Page Builder, installed through Joomla's own installer, checked against a pinned hash, with a backup taken first.
How the JoomShaper packages are deployedEvery unpatched core hole, per site
Each Joomla 3 site shows which published core vulnerabilities apply to its exact version, which are already fixed, and how many can be fixed with one click right now.
What you see for each siteVulnerable extension alerts
Every site is checked against the mySites.guru Joomla extension vulnerability rules on every snapshot, so a newly disclosed hole in an extension you run is flagged without you looking for it.
How extension checks workIs a Joomla 3 site hacked right now?
We clean it for a single fixed fee of £120 per incident, usually the same day. We screen it before you pay, so in the rare case it cannot be fixed you are not charged, and non-subscribers get a free month of mySites.guru with it. Get it fixed
Everything we have written about Joomla 3
The detail behind this site, post by post, on the mySites.guru blog.
- 14 More Joomla 3 Security Fixes, Each Tested on a Real 3.10.12 Site
Joomla 5.4.9 fixed 16 core issues. We backported every one reaching Joomla 3 to the mySites.guru one-click patch tool, each proved on a real 3.10.12 site.
- SP Page Builder's Joomla 3 Security Patch Was Incomplete. Version 1.0.3 Fixes It.
JoomShaper's first Joomla 3 security patch for SP Page Builder left the captcha bypass live and the XSS fix incomplete. Version 1.0.3 closes both.
- Phoca Cart 6.1.9 stops anyone downloading other customers' paid files
Phoca Cart before 6.1.9 let anonymous visitors download the digital products other customers bought. Only the Joomla 6 line is fixed, and 6.1.8 is affected.
- Joomla 5.4.9 and 6.1.4 Fix 16 Security Issues, Two Rated High
Joomla 5.4.9 and 6.1.4 fix 16 core security issues, including cache directory deletion, SSRF, an MFA bypass and account creation with registration switched off.
- Modules Anywhere 10.0.0 and Tabs & Accordions 3.2.0 Close Two Content Author Security Holes
CVE-2026-100750 and CVE-2026-100751: Regular Labs fixed two High severity issues in Modules Anywhere 10.0.0 and Tabs & Accordions 3.2.0 for Joomla.
- Six more J2Store flaws fixed in 3.3.23, 4.0.23 and 4.1.8
J2Store 3.3.23, 4.0.23 and 4.1.8 fix six flaws mySites.guru reported, including an anonymous blind SQL injection that reads a Joomla shop's whole database.
- SQL Injection and a Captcha Bypass in the SP Page Builder Joomla Extension, found by mySites.guru
mySites.guru found an Author-level SQL injection and an unauthenticated captcha bypass in the SP Page Builder Joomla extension, both fixed in 6.9.1.
- Regular Labs Publishes 24 Joomla Extension Updates Including 10 Security Fixes
Regular Labs shipped 24 Joomla extension updates on 13 September 2026. Ten fix security issues across nine CVEs, and four change behaviour on update.
Keeping Joomla 3 patched is part of the subscription
The one-click core patch, JoomShaper's Joomla 3 packages, vulnerable extension alerts and malware scanning are all included, alongside everything else mySites.guru does for Joomla and WordPress. No per-site fees, and no price increases since 2012.
Keep your Joomla 3 sites patched while you plan the move
Connect one Joomla 3 site and see every open core hole and vulnerable extension on it, free, with no card.