JoomDonation and Joomla 3
Announces "Discontinued Joomla 3 Support" for OS Property on a page that also lists it as compatible with Joomla 3.9.0+, and shipped Events Booking 4.9.5 for Joomla 3 in July 2026 with security fixes, available only by updater or support ticket.
Joomla extensions covered: OS Property, Events Booking. JoomDonation website
What they said
“Discontinued Joomla 3 Support: Joomla 3 has reached its official end-of-life”
UndatedRead it on their siteChecked 2 Oct 2026
Known Joomla 3 vulnerabilities
- Medium
Events Booking (com_eventbooking) 5.x below 5.8.2 - Unauthenticated Invoice IDOR (billing data disclosure, fixed 5.8.2, CVE-2026-63047)
Affected: ≥ 5.0.0 and < 5.8.2
- Critical
Events Booking (com_eventbooking) 5.x below 5.8.1 - Unauthenticated File Upload and User Enumeration (CVE-2026-58149, CVE-2026-60024, CVE-2026-60025)
Affected: ≥ 5.0.0 and < 5.8.1
- Critical
Events Booking (com_eventbooking) below 4.9.5 - Unauthenticated File Upload and User Enumeration (CVE-2026-58149, CVE-2026-60024, CVE-2026-60025)
Affected: < 4.9.5
Our coverage
- Events Booking for Joomla: Anyone Could Upload Files to Your Server
mySites.guru found two unauthenticated flaws in Events Booking for Joomla: file upload enabled by default, and a leak of every user's name and email.
See which of your sites run OS Property
Connect one site and mySites.guru audits it free, with no card. You see the core vulnerabilities still open on it, the extensions with known holes, and a one-click fix for the core ones.
Is a Joomla 3 site hacked right now?
We clean it for a single fixed fee of £120 per incident, usually the same day. We screen it before you pay, so in the rare case it cannot be fixed you are not charged, and non-subscribers get a free month of mySites.guru with it. Get it fixed
Keep your Joomla 3 sites patched while you plan the move
One free audit of one site, no card. It shows the core vulnerabilities still open and the extensions with known holes.