Updated for 2026

Still running Joomla 3?

Joomla! 3
Security
Patch.

+ PHP 8 Compatibility

Closes 50 known security vulnerabilities in the Joomla! 3 core and fixes 7 PHP 8 deprecation issues in the code every request loads. Every fix is individually verified, backed up automatically, with one click to apply and one click to undo.

Get the patch · $19.90 Instant download after purchase, via Gumroad
Independent third-party patch for Joomla! 3
  • Joomla! 3.10.x · verified on 3.10.12
  • Tested on real PHP 7.4 & 8.1
  • Automatic backup before every change
  • One-click restore per fix

50

verified security fixes

7

PHP 8 compatibility fixes

1 click

apply & undo anytime

Why this matters

Joomla! 3 reached official end-of-life on August 17, 2023. No more official security updates are released, yet a large share of the web still runs on it.

What end-of-life actually means for your site →

No official fixes

New vulnerabilities keep being found in code shared with newer Joomla! versions, but Joomla! 3 itself no longer gets a patch.

Hosts are dropping PHP 7.4

Forced upgrades to PHP 8.x break the unpatched Joomla! 3 core outright in places, including the admin panel.

Migration isn’t always an option

Moving to Joomla! 4/5 takes budget and time many operators don’t have right now, but running unpatched isn’t acceptable either. Patch or migrate, compared →

What’s included

Two independent tracks in one package: apply them separately, on your own schedule.

Security

50 verified fixes

41 tied to an official CVE, 9 independently identified hardening measures. Every fix is individually researched, verified against the real 3.10.12 core, and rated for confidence. Low-confidence candidates are never shipped.

Fixes by vulnerability class
ClassCount
XSS / Cross-Site-Scripting24
Access control / authentication9
Other hardening4
SQL injection2
Cache poisoning2
Timing attacks2
File upload / RCE2
Open redirect2
Path traversal / LFI1
PHP object injection1
Information disclosure1

Each fix is compared against the corresponding upstream Joomla! or community-fork change, adapted to the 3.10.x line, and re-verified by reading the affected code, not copied blindly. All 57 fixes carry a passing smoke test against a real 3.10.12 core; 45 are rated high confidence and 12 medium. Nothing rated low confidence ships.

View all 57 fixes and CVEs →
Every fix in the current package
IDTypeCVEClassFileConfidence
JP3-0001SecurityCVE-2025-54476XSS filter bypassInputFilter.phpHigh
JP3-0002SecurityCVE-2025-63083Stored XSStoc.phpHigh
JP3-0003SecurityCVE-2026-21629Missing authentication checkajax.phpHigh
JP3-0004SecurityCVE-2026-48954Stored XSS (attribute-breakout)languageoverridequotes.php +2 moreHigh
JP3-0005SecurityCVE-2026-48950Reflected XSSdefault.phpMedium
JP3-0006SecurityCVE-2026-48953XSS via public layout APIimage.phpMedium
JP3-0007SecurityCVE-2026-48952XSS via untrusted update feed datadefault.phpMedium
JP3-0008SecurityCVE-2026-25901Stored XSSedit.phpMedium
JP3-0009SecurityCVE-2026-30894Stored XSSpreview.phpHigh
JP3-0010SecurityCVE-2026-25900XSS via untrusted RSS feeddefault.php +1 moreHigh
JP3-0011SecurityCVE-2026-30895Stored XSSreadmore.php +1 moreMedium
JP3-0012SecurityCVE-2026-40383Path traversal to local file inclusionHtmlView.phpHigh
JP3-0013SecurityCVE-2026-35222SQL injectiontags.php +1 moreHigh
JP3-0014SecurityCVE-2026-48902Sensitive token sent over cleartext HTTPreset.php +1 moreHigh
JP3-0015SecurityCVE-2026-48901Cache poisoning / incorrect filter reuseInputFilter.phpHigh
JP3-0016SecurityCVE-2026-48948Broken access controlview.vcf.phpHigh
JP3-0017SecurityCVE-2025-63082XSS via data: URIInputFilter.phpHigh
JP3-0018SecurityCVE-2024-40747XSS via module style/attribute parametersModuleHelper.phpHigh
JP3-0019SecurityCVE-2025-25226SQL injection via identifier quoting bypassdriver.phpHigh
JP3-0020SecurityCVE-2026-21631Stored XSSedit.phpHigh
JP3-0021SecurityMissing authorization checkupdate.phpHigh
JP3-0022SecurityTiming side-channeltotp.phpHigh
JP3-0023SecurityMissing request/response authenticationyubikey.php +3 moreHigh
JP3-0024SecurityPHP object injection (defense-in-depth)restore.phpMedium
JP3-0025SecurityXSS via untrusted external feeddefault.phpHigh
JP3-0026SecurityTiming side-channel (limited real-world impact)reset.phpMedium
JP3-0027SecurityCode hygiene (eval removal) -- not found to be exploitableHtmlDocument.phpMedium
JP3-0028SecurityRemote code execution via file upload bypassMediaHelper.phpHigh
JP3-0029SecurityContent-type sniffing bypass (upload XSS)MediaHelper.phpHigh
JP3-0030SecurityCVE-2023-40626Information disclosure (env var / PHP constant exposure)LanguageHelper.php +28 moreHigh
JP3-0031SecurityCVE-2024-21723Open redirectframework.phpHigh
JP3-0032SecurityCVE-2024-27184Improper URL validation (open redirect / SSRF-adjacent)Uri.phpHigh
JP3-0033SecurityCVE-2024-21724XSS via unvalidated media-field valuebanner.xml +28 moreHigh
JP3-0034SecurityCVE-2024-26279XSS via malicious wrapper URL (javascript:/data: schemes)default.xml +1 moreHigh
JP3-0035SecurityCVE-2024-21726XSS filter gap in the URL form-validation ruleUrlRule.php +1 moreHigh
JP3-0036SecurityCVE-2024-21731XSS via entity-encoded tag surviving strip_tags then getting decoded livestring.phpHigh
JP3-0037SecurityCVE-2024-40743XSS via case-mixed or nested tag surviving a single-pass, case-sensitive strip regexOutputFilter.phpHigh
JP3-0038SecurityCVE-2024-27185Cache poisoning via arbitrary parameter injection into cached pagination linksPagination.phpHigh
JP3-0039SecurityCVE-2024-21722Insufficient session expiration after MFA method changeuser.php +1 moreHigh
JP3-0040SecurityCVE-2024-21725XSS via punycode-decoded email/URL containing HTML-special charactersdefault.php +7 moreMedium
JP3-0041SecurityCVE-2024-26278Stored XSS via unsanitized custom-field default valuefield.xmlHigh
JP3-0042SecurityCVE-2024-27187Improper access control (self-service privilege/identity tampering)user.phpMedium
JP3-0043SecurityCVE-2026-48898Missing authorization check (defense-in-depth; does not close a currently-reachable 3.x gap)user.phpMedium
JP3-0044SecurityCVE-2026-73371Improper access control (batch-copy items the user cannot edit)AdminModel.php +4 moreHigh
JP3-0045SecurityCVE-2026-48956Missing authorization check (defense-in-depth for a non-standard entry point)controller.phpMedium
JP3-0046SecurityCVE-2026-71572HTTP header injection via unsanitized filenameview.raw.php +1 moreHigh
JP3-0047SecurityCVE-2026-73373Remote code execution via file upload bypass (SSI-executable extension)template.phpHigh
JP3-0048SecurityCVE-2026-21632Stored XSS via unescaped article titleblog_links.php +6 moreHigh
JP3-0049SecurityCVE-2024-40748XSS via unescaped HTML id attributedefault.phpHigh
JP3-0050SecurityCVE-2024-40749Access control bypass via case-insensitive class resolution vs. case-sensitive ACL checkcontroller.php +1 moreHigh
JP3-0051PHP 8PHP 8.1 compatibility (Serializable interface deprecation notice, not a vulnerability)Input.php +1 moreHigh
JP3-0052PHP 8PHP 8.1 compatibility (SPL interface return-type deprecation, not a vulnerability)Feed.phpHigh
JP3-0053PHP 8PHP 8.4 compatibility (implicit-nullable-parameter deprecation, not a vulnerability)BaseApplication.php +6 moreHigh
JP3-0054PHP 8PHP 8.1 compatibility (SPL interface return-type deprecation, not a vulnerability)iterator.phpHigh
JP3-0055PHP 8PHP 8.1 compatibility (SPL interface return-type deprecation, not a vulnerability)iterator.phpHigh
JP3-0056PHP 8PHP 8.1 compatibility (SPL interface return-type deprecation, not a vulnerability)DataSet.phpHigh
JP3-0057PHP 8PHP 8.1 compatibility (SPL interface return-type deprecation, not a vulnerability)Input.phpHigh

As of August 2026. Prefer a standalone, linkable page? View the full CVE list →

Compatibility

7 PHP 8 fixes

Stops the core from throwing deprecation errors under PHP 8.1+, including the application bootstrap classes that load on every single page request. Purely additive, safe on PHP 7.4 too. See the actual error messages →

  • Input.php (2 fixes): Serializable and Countable interface compliance, the class loaded on every request
  • Application bootstrap (7 files): highest-reachability fix, every front-end and admin request
  • Feed.php: used by mod_feed and com_newsfeeds
  • JDatabaseIterator & FOFDatabaseIterator: optional APIs some extensions call
  • Joomla\Data\DataSet: closes the class fully for any extension that references it

How it works

Installs as a normal, protected Joomla! extension. No SSH or database access required.

  1. Install

    Extensions → Manage → Install → upload the package file.

  2. Scan

    Open Scan & Apply and see live which of the 57 rules are already satisfied and which are missing.

  3. Apply

    Apply the missing security fixes with one click. Every change is backed up automatically first.

  4. Toggle PHP 8

    Turn on PHP 8 compatibility separately, whenever your hosting moves. Also one click, reversible any time.

Safe by design

What actually happens to your files before, during, and after a fix is applied.

Backup before every change

Any file about to be overwritten is copied to a dated backup folder inside the extension first, every time, no exceptions.

Unrecognized files are skipped

Each file is checked against a known pattern before touching it. If the surrounding code no longer matches (e.g. a third-party mod changed it), that fix is skipped for manual review, not force-applied.

Restore any fix, anytime

Every applied fix can be individually reverted from its backup. If a restore can’t fully complete, you’re told explicitly instead of being left guessing.

Two honest limits: when a fix does apply, it replaces the affected file’s full content rather than merging line-by-line, so unrelated custom edits inside that specific file could be lost. Check the file list for a fix against your own changes first if you’re unsure. And fixes aren’t transactional across a batch: if one fix in a multi-fix run fails partway through, files already changed by earlier fixes in that run are not automatically rolled back. The backup is always there to restore manually.

Inside the admin panel

Real screenshots from the Scan & Apply admin screen: this is what you’ll see after install.

Security report: every fix, its CVE, and its live status on your site
PHP 8 compatibility: applied separately from the security fixes, one click

Frequently asked questions

Does this replace migrating to Joomla! 4 or 5?

No. It’s a stopgap that keeps a Joomla! 3 site secure and running on current PHP versions while you plan a migration, not a substitute for one.

Will it work if my Joomla! core files have already been modified?

Each file is checked for the actual vulnerable pattern before it’s touched. If that pattern is still recognizable, the fix applies (after backing the file up). If the surrounding code no longer matches any known pattern, that fix is skipped and flagged for manual review instead of being force-applied. One thing to know: when a fix does apply, it replaces the file’s full content rather than merging line-by-line, so unrelated custom edits inside that specific file could be lost. Check the fix’s file list against your own changes first if you’re unsure.

Does it patch third-party extensions or templates?

No. Every fix only ever touches Joomla! core files.

Which PHP versions are actually supported?

The 7 compatibility fixes close deprecation warnings introduced across PHP 8.1 through 8.4 in code that runs on every request, and they’re verified against real PHP 7.4 and 8.1 interpreters. They stop the Joomla! core itself from throwing those warnings, but they don’t guarantee the rest of your admin area runs error-free on PHP 8.1+ if your templates or third-party extensions aren’t PHP 8-compatible themselves.

Can I undo every change?

Yes. Every applied fix can be individually restored from its automatic backup. If a restore can’t fully complete, you’re told explicitly instead of being left guessing. Check the backup folder manually in that case.

How many websites does one license cover?

One Joomla! installation. Installing on staging and production of the same website is covered by the same license.

Does the extension stay installed permanently?

Yes. It installs as a protected extension and isn’t meant to be removed via the normal Uninstall button. The included installation guide covers the correct way to remove it if you ever need to.

Is this a subscription? Do I get future fixes too?

No. This is a one-time purchase covering the 57 fixes in the current package. New vulnerabilities discovered after your purchase are not automatically included. Check joomla-update.ch for future package updates.

One-time purchase

No subscription. Covers the 57 fixes in the current package.

Joomla! 3 Security Patch + PHP 8 Compatibility

$19.90 one-time

Instant download after purchase, including an installation guide.

Get the patch
  • 50 verified security fixes (41 with CVE, 9 hardening)
  • 7 PHP 8 compatibility fixes
  • Scan & Apply admin interface
  • Automatic backup, reversible any time
  • Works with Joomla! 3.10.12 and 3.10.x forks
  • One license per Joomla! installation, staging and production of the same website included

Deliberately not included

  • Vulnerabilities in third-party extensions or templates: the patch only ever touches Joomla! core files
  • Full PHP 8.1+ compatibility of Joomla! 3’s own admin area: the compatibility fixes stop the core from throwing deprecation warnings, but don’t guarantee every admin screen runs cleanly on PHP 8.1+ without further work
  • A guarantee the entire admin area runs error-free on PHP 8.1 if third-party components aren’t PHP 8-compatible themselves
  • Protection against future, not-yet-disclosed vulnerabilities (zero-days)

Already hacked?

This patch prevents known vulnerabilities. It won’t clean up an active compromise. If your Joomla 3 site is already showing signs of a hack (spam pages, redirects, a defaced homepage, a host warning), get in touch and we’ll help you assess and fix it.

See what to check first →

Get in touch
$19.90 Joomla! 3 Security Patch
Buy now