Joomla 3 core vulnerabilities that Joomla will never patch
The last public Joomla 3 release, 3.10.12, shipped on 8 July 2023. Joomla 3 reached end of life on 17 August 2023, and the paid eLTS programme that kept patching it ended on 17 February 2025. Joomla's security team still publishes core advisories, and many of them describe code that Joomla 3 shares with the supported versions.
39 of those advisories are listed below. Joomla fixed them in the supported versions where they apply and, for part of the period, in paid eLTS builds. No public Joomla 3 release closes any of them. On a Joomla 3 site that stops at 3.10.12, every one is still open.
Advisory figures are from the Joomla Security Centre. File counts are from the mySites.guru patch tool. Site measurements: 79% of the Joomla 3 sites we can check have unpatched core files we could fix, across sites connected to mySites.guru, 28 August 2026.
How the one-click patch closes them
It is part of the mySites.guru subscription, and it works on the files, so there is nothing to migrate first.
mySites.guru backports each Joomla core fix to Joomla 3.10.12, tests it against a stock 3.10.12 install, and ships it with the mySites.guru connector. One toggle in the site's Snapshot changes 85 core files: 84 are replaced with patched copies and 1 is added. Switch the toggle off and every file goes back to stock 3.10.12. The work builds on the community 3.10.999 reference project, and the fixes are reproduced on a real 3.10.12 install before they ship.
The audit compares each of the 85 files with the patched copy and counts the ones that do not match. Zero means the site has every patch we ship today. Any other number is how many files still need patching, and the toggle fixes them all at once. A file you edited by hand counts as unpatched, and switching the toggle on replaces it with the patched copy. Files for parts of Joomla you have uninstalled, such as the Hathor or Beez3 templates, are skipped, so they stay uninstalled.
The one file Joomla 3 never shipped is a form rule behind the language override fix. It is created when you switch the toggle on and deleted when you switch it off. After patching, an audit lists these files under Core File Changes, because they no longer match the 3.10.12 release. That is expected, and you can read every diff there.
When Joomla publishes a new advisory that reaches Joomla 3, it is added to the patch set. Your site then shows as not fully patched until you switch the toggle on again, so watch for the Patches Available badge on your sites list. For a portfolio, a bulk view lists every Joomla 3.10.12 site with its own toggle.
All 39 advisories, newest first
Grouped by the year Joomla published the advisory. Each title links to Joomla's own write-up, and every row is closed by the mySites.guru one-click patch.
2026 (21 advisories)
2025 (6 advisories)
| CVE | Advisory | Also affects Joomla 4+ | One-click patch |
|---|---|---|---|
| CVE-2025-54476 | Inadequate content filtering in the checkAttribute filter code | No | Included |
| CVE-2025-25226 | SQL injection in the quoteNameStr method of the database package | No | Included |
| CVE-2025-22213 | Malicious file uploads via the Media Manager | Yes | Included |
| CVE-2024-40749 | Read ACL violation in multiple core views | No | Included |
| CVE-2024-40748 | XSS vector in the id attribute of menu lists | No | Included |
| CVE-2024-40747 | XSS vectors in module chromes | Yes | Included |
2024 (11 advisories)
| CVE | Advisory | Also affects Joomla 4+ | One-click patch |
|---|---|---|---|
| CVE-2024-40743 | XSS vectors in the Outputfilter::strip* methods | No | Included |
| CVE-2024-27185 | Cache poisoning in pagination | No | Included |
| CVE-2024-27184 | Inadequate validation of internal URLs | No | Included |
| CVE-2024-26278 | XSS in the com_fields default field value | No | Included |
| CVE-2024-26279 | XSS in Wrapper extensions | No | Included |
| CVE-2024-21731 | XSS in the StringHelper::truncate method | No | Included |
| CVE-2024-21726 | Inadequate content filtering in the filter code | No | Included |
| CVE-2024-21725 | XSS in mail address outputs | No | Included |
| CVE-2024-21724 | XSS in media selection fields | No | Included |
| CVE-2024-21723 | Open redirect in the installation application | No | Included |
| CVE-2024-21722 | Insufficient session expiration in MFA management views | No | Included |
2023 (1 advisory)
| CVE | Advisory | Also affects Joomla 4+ | One-click patch |
|---|---|---|---|
| CVE-2023-40626 | Exposure of environment variables | No | Included |
See which of these your Joomla 3 sites still have open
Connect one site and the audit counts the patch files that do not match, so you know how many of the 39 advisories apply to it today. The first audit is free, with no card.
What the patch does not do
It closes core holes on a Joomla 3 site and holds the position while you move. Everything else on the server is outside its reach.
- It does not clean a hacked site. Find and remove the malicious files first with the Hacked tools, then patch.
- It patches Joomla core only. Extension flaws are tracked on the extension vulnerabilities page, and for Helix and SP Page Builder there is a separate JoomShaper tool.
- It does not make Joomla 3 a long-term home. PHP, your extensions and your server keep moving on without it.
- It needs Joomla 3.10.12 or a later 3.x release, and the PHP zip extension on your server. Without zip support the audit says so and the toggle is not offered.
Plan the move as well
The patch buys time to migrate, and it does not replace the migration. The options page sets out what staying, rescuing and moving each involve.
Where to read more
- Fix Joomla 3 Security Issues in One Click: the full patch guide, the file list and the bulk view.
- 14 More Joomla 3 Security Fixes, Each Tested on a Real 3.10.12 Site: the latest additions to the patch, and how each one is proved on Joomla 3 first.
- The Joomla 3.10.999 Project: the community reference repository behind the backports.
- Joomla 5.4.9 and 6.1.4 Fix 16 Security Issues: the most recent supported-version security release.
- The full reading list, newest first.
Keeping Joomla 3 patched is part of the subscription
The one-click core patch, JoomShaper's Joomla 3 packages, vulnerable extension alerts and malware scanning are all included, alongside everything else mySites.guru does for Joomla and WordPress. No per-site fees, and no price increases since 2012.
Keep your Joomla 3 sites patched while you plan the move
One free audit of one site, no card, no time limit.