Joomla! 3
Joomla! 3
The Joomla! 3 reached end of service life on Aug 17, 2023 — Joomla! no longer ships security patches or fixes for it. Our third-party support keeps it safe to run: 24/7 engineers manage issues, remediate vulnerabilities, and help you maintain compliance.
24/7 engineers own your Joomla! 3 incidents end to end.
Mitigation and patch-around guidance when the vendor no longer ships fixes.
Controls evidence and documentation that keep auditors satisfied.
Specifications
- product
- joomla
- release
- 3
- product Label
- Joomla!
- release Label
- 3
- codename
- lts
- latest Version
- 3.10.12
- release Date
- 2012-09-27
- maintained
- source Url
- https://endoflife.date/joomla
Lifecycle Dates
- End of Service Life
- Aug 17, 2023
- Last OEM Support
- Aug 17, 2021
OEM vs. 3rd Party Support
See how third-party support compares to the vendor contract for Joomla! 3 — monitoring, break/fix, vulnerability work, operations and compliance, before and after EOSL.
| Feature | OEM Support | 3rd Party Support |
|---|---|---|
| Post-EOSL Support | ||
| Break/Fix Support | Until EOSL | |
| 24/7 Monitoring | ||
| Vulnerability Scanning & Remediation | ||
| Managed Operations | ||
| Procedure & Configuration Review | ||
| Compliance & Audit Documentation | Limited | |
| Discounted Migration to Other Platforms |
Why Choose 3rd Party Support for Joomla! 3?
Vulnerability Remediation
Scanning, mitigation and patch-around guidance for Joomla! 3 when the vendor no longer ships fixes.
Compliance Maintenance
Procedure review, controls evidence and the documentation auditors ask for — maintained continuously, not scrambled at audit time.
24/7 Expert Support
Engineers who know this release monitor, manage and fix issues around the clock — break/fix to managed operations.
Joomla! 3 Support: Frequently Asked Questions
Is the Joomla! 3 still supported?
Joomla! ended support for the Joomla! 3 on Aug 17, 2023 — no more patches or fixes from the vendor. Third-party support keeps it covered: our engineers manage issues, remediate vulnerabilities, and help you maintain compliance for as long as you run it.
When is the Joomla! 3 end of service life (EOSL) date?
Joomla! lists the end of service life for the Joomla! 3 as Aug 17, 2023.
Can I keep using the Joomla! 3 after its EOSL date?
Yes. EOSL means Joomla! stops issuing patches and support — the software itself keeps running. Third-party support covers it from there: issue management, security vulnerability remediation, and the compliance documentation auditors ask for, for as long as you choose to run it.
How much does third-party support for the Joomla! 3 cost?
Typically 40-70% below the OEM maintenance renewal price. Exact pricing depends on quantity, service level and location — request a quote and we respond within 24 hours.
Known Vulnerabilities Affecting Joomla! 3
171 published CVEs affect the Joomla! 3, including 65 rated critical or high severity. Joomla! no longer ships security patches for this release — our engineers provide mitigation guidance, workarounds and hardening support.
| CVE | Severity | CVSS | Published | Summary |
|---|---|---|---|---|
| CVE-2026-48902 | CRITICAL | 9.8 | May 26, 2026 | The password and username reset features created plain http links for https connections if the "Force SSL" flag wasn't explicitly set. |
| CVE-2025-25226 | CRITICAL | 9.8 | Apr 8, 2025 | Improper handling of identifiers lead to a SQL injection vulnerability in the quoteNameStr method of the database package. Please note: the affected method is a protected method. It has no usages in the original packages in neither the 2.x nor 3.x branch and therefore the vulnerability in question can not be exploited when using the original database class. However, classes extending the affected class might be affected, if the vulnerable method is used. |
| CVE-2022-23797 | CRITICAL | 9.8 | Mar 30, 2022 | An issue was discovered in Joomla! 3.0.0 through 3.10.6 & 4.0.0 through 4.1.0. Inadequate filtering on the selected Ids on an request could resulted into an possible SQL injection. |
| CVE-2022-23795 | CRITICAL | 9.8 | Mar 30, 2022 | An issue was discovered in Joomla! 2.5.0 through 3.10.6 & 4.0.0 through 4.1.0. A user row was not bound to a specific authentication mechanism which could under very special circumstances allow an account takeover. |
| CVE-2020-35613 | CRITICAL | 9.8 | Dec 28, 2020 | An issue was discovered in Joomla! 3.0.0 through 3.9.22. Improper filter blacklist configuration leads to a SQL injection vulnerability in the backend user list. |
| CVE-2020-10243 | CRITICAL | 9.8 | Mar 16, 2020 | An issue was discovered in Joomla! before 3.9.16. The lack of type casting of a variable in a SQL statement leads to a SQL injection vulnerability in the Featured Articles frontend menutype. |
| CVE-2019-19846 | CRITICAL | 9.8 | Dec 18, 2019 | In Joomla! before 3.9.14, the lack of validation of configuration parameters used in SQL queries caused various SQL injection vectors. |
| CVE-2019-10945 | CRITICAL | 9.8 | Apr 10, 2019 | An issue was discovered in Joomla! before 3.9.5. The Media Manager component does not properly sanitize the folder parameter, allowing attackers to act outside the media manager root directory. |
| CVE-2019-7743 | CRITICAL | 9.8 | Feb 12, 2019 | An issue was discovered in Joomla! before 3.9.3. The phar:// stream wrapper can be used for objection injection attacks because there is no protection mechanism (such as the TYPO3 PHAR stream wrapper) to prevent use of the phar:// handler for non .phar-files. |
| CVE-2018-15882 | CRITICAL | 9.8 | Aug 29, 2018 | An issue was discovered in Joomla! before 3.8.12. Inadequate checks in the InputFilter class could allow specifically prepared phar files to pass the upload filter. |
| CVE-2018-11325 | CRITICAL | 9.8 | May 22, 2018 | An issue was discovered in Joomla! Core before 3.8.8. The web install application would autofill password fields after either a form validation error or navigating to a previous install step, and display the plaintext password for the administrator account at the confirmation screen. |
| CVE-2018-6376 | CRITICAL | 9.8 | Jan 30, 2018 | In Joomla! before 3.8.4, the lack of type casting of a variable in a SQL statement leads to a SQL injection vulnerability in the Hathor postinstall message. |
| CVE-2017-14596 | CRITICAL | 9.8 | Sep 20, 2017 | In Joomla! before 3.8.0, inadequate escaping in the LDAP authentication plugin can result in a disclosure of a username and password. |
| CVE-2017-8917 | CRITICAL | 9.8 | May 17, 2017 | SQL injection vulnerability in Joomla! 3.7.x before 3.7.1 allows attackers to execute arbitrary SQL commands via unspecified vectors. |
| CVE-2016-9081 | CRITICAL | 9.8 | Jan 23, 2017 | Joomla! 3.4.4 through 3.6.3 allows attackers to reset username, password, and user group assignments and possibly perform other user account modifications via unspecified vectors. |
| CVE-2016-10045 | CRITICAL | 9.8 | Dec 30, 2016 | The isMail transport in PHPMailer before 5.2.20 might allow remote attackers to pass extra parameters to the mail command and consequently execute arbitrary code by leveraging improper interaction between the escapeshellarg function and internal escaping performed in the mail function in PHP. NOTE: this vulnerability exists because of an incorrect fix for CVE-2016-10033. |
| CVE-2016-10033 | CRITICAL | 9.8 | Dec 30, 2016 | The mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote attackers to pass extra parameters to the mail command and consequently execute arbitrary code via a \" (backslash double quote) in a crafted Sender property. |
| CVE-2016-9836 | CRITICAL | 9.8 | Dec 5, 2016 | The file scanning mechanism of JFilterInput::isFileSafe() in Joomla! CMS before 3.6.5 does not consider alternative PHP file extensions when checking uploaded files for PHP content, which enables a user to upload and execute files with the `.php6`, `.php7`, `.phtml`, and `.phpt` extensions. Additionally, JHelperMedia::canUpload() did not blacklist these file extensions as uploadable file types. |
| CVE-2016-8869 | CRITICAL | 9.8 | Nov 4, 2016 | The register method in the UsersModelRegistration class in controllers/user.php in the Users component in Joomla! before 3.6.4 allows remote attackers to gain privileges by leveraging incorrect use of unfiltered data when registering on a site. |
| CVE-2024-27185 | CRITICAL | 9.1 | Aug 20, 2024 | The pagination class includes arbitrary parameters in links, leading to cache poisoning attack vectors. |
Showing the 20 most severe of 171 known CVEs.
Get Third Party Support