Joomla! 4
Joomla! 4
The Joomla! 4 reached end of service life on Oct 14, 2025 — Joomla! no longer ships security patches or fixes for it. Our third-party support keeps it safe to run: 24/7 engineers manage issues, remediate vulnerabilities, and help you maintain compliance.
24/7 engineers own your Joomla! 4 incidents end to end.
Mitigation and patch-around guidance when the vendor no longer ships fixes.
Controls evidence and documentation that keep auditors satisfied.
Specifications
- product
- joomla
- release
- 4
- product Label
- Joomla!
- release Label
- 4
- codename
- lts
- latest Version
- 4.4.14
- release Date
- 2021-08-17
- maintained
- source Url
- https://endoflife.date/joomla
Lifecycle Dates
- End of Service Life
- Oct 14, 2025
- Last OEM Support
- Oct 15, 2024
OEM vs. 3rd Party Support
See how third-party support compares to the vendor contract for Joomla! 4 — monitoring, break/fix, vulnerability work, operations and compliance, before and after EOSL.
| Feature | OEM Support | 3rd Party Support |
|---|---|---|
| Post-EOSL Support | ||
| Break/Fix Support | Until EOSL | |
| 24/7 Monitoring | ||
| Vulnerability Scanning & Remediation | ||
| Managed Operations | ||
| Procedure & Configuration Review | ||
| Compliance & Audit Documentation | Limited | |
| Discounted Migration to Other Platforms |
Why Choose 3rd Party Support for Joomla! 4?
Vulnerability Remediation
Scanning, mitigation and patch-around guidance for Joomla! 4 when the vendor no longer ships fixes.
Compliance Maintenance
Procedure review, controls evidence and the documentation auditors ask for — maintained continuously, not scrambled at audit time.
24/7 Expert Support
Engineers who know this release monitor, manage and fix issues around the clock — break/fix to managed operations.
Joomla! 4 Support: Frequently Asked Questions
Is the Joomla! 4 still supported?
Joomla! ended support for the Joomla! 4 on Oct 14, 2025 — no more patches or fixes from the vendor. Third-party support keeps it covered: our engineers manage issues, remediate vulnerabilities, and help you maintain compliance for as long as you run it.
When is the Joomla! 4 end of service life (EOSL) date?
Joomla! lists the end of service life for the Joomla! 4 as Oct 14, 2025.
Can I keep using the Joomla! 4 after its EOSL date?
Yes. EOSL means Joomla! stops issuing patches and support — the software itself keeps running. Third-party support covers it from there: issue management, security vulnerability remediation, and the compliance documentation auditors ask for, for as long as you choose to run it.
How much does third-party support for the Joomla! 4 cost?
Typically 40-70% below the OEM maintenance renewal price. Exact pricing depends on quantity, service level and location — request a quote and we respond within 24 hours.
Known Vulnerabilities Affecting Joomla! 4
76 published CVEs affect the Joomla! 4, including 25 rated critical or high severity. Joomla! no longer ships security patches for this release — our engineers provide mitigation guidance, workarounds and hardening support.
| CVE | Severity | CVSS | Published | Summary |
|---|---|---|---|---|
| CVE-2026-48902 | CRITICAL | 9.8 | May 26, 2026 | The password and username reset features created plain http links for https connections if the "Force SSL" flag wasn't explicitly set. |
| CVE-2022-23799 | CRITICAL | 9.8 | Mar 30, 2022 | An issue was discovered in Joomla! 4.0.0 through 4.1.0. Under specific circumstances, JInput pollutes method-specific input bags with $_REQUEST data. |
| CVE-2022-23797 | CRITICAL | 9.8 | Mar 30, 2022 | An issue was discovered in Joomla! 3.0.0 through 3.10.6 & 4.0.0 through 4.1.0. Inadequate filtering on the selected Ids on an request could resulted into an possible SQL injection. |
| CVE-2022-23795 | CRITICAL | 9.8 | Mar 30, 2022 | An issue was discovered in Joomla! 2.5.0 through 3.10.6 & 4.0.0 through 4.1.0. A user row was not bound to a specific authentication mechanism which could under very special circumstances allow an account takeover. |
| CVE-2024-27185 | CRITICAL | 9.1 | Aug 20, 2024 | The pagination class includes arbitrary parameters in links, leading to cache poisoning attack vectors. |
| CVE-2021-26040 | CRITICAL | 9.1 | Aug 24, 2021 | An issue was discovered in Joomla! 4.0.0. The media manager does not correctly check the user's permissions before executing a file deletion command. |
| CVE-2026-35223 | HIGH | 8.6 | May 26, 2026 | An improper access check allows unauthorized access to com_config webservice endpoints. |
| CVE-2026-23899 | HIGH | 8.6 | Apr 1, 2026 | An improper access check allows unauthorized access to webservice endpoints. |
| CVE-2026-23898 | HIGH | 8.6 | Apr 1, 2026 | Lack of input validation leads to an arbitrary file deletion vulnerability in the autoupdate server mechanism. |
| CVE-2026-48904 | HIGH | 8.2 | May 26, 2026 | An improper access check allows privelege escalation through the com_users group editing webservice endpoint. |
| CVE-2026-48898 | HIGH | 8.2 | May 26, 2026 | An improper access check allows privilege escalation through the com_users batch task. |
| CVE-2026-48897 | HIGH | 8.2 | May 26, 2026 | Insufficient state checks lead to a vector that allows to bypass 2FA checks. |
| CVE-2026-48896 | HIGH | 8.2 | May 26, 2026 | Insufficient state checks lead to a vector that allows to bypass 2FA checks. |
| CVE-2026-48901 | HIGH | 7.5 | May 26, 2026 | The InputFilter::getInstance() method omitted a security sensitive parameter from the instance cache key. |
| CVE-2026-40383 | HIGH | 7.5 | May 26, 2026 | An improper validation of user-supplied input leads to a local file inclusion vulnerability. |
| CVE-2025-25227 | HIGH | 7.5 | Apr 8, 2025 | Insufficient state checks lead to a vector that allows to bypass 2FA checks. |
| CVE-2024-40749 | HIGH | 7.5 | Jan 7, 2025 | Improper Access Controls allows access to protected views. |
| CVE-2024-40748 | HIGH | 7.5 | Jan 7, 2025 | Lack of output escaping in the id attribute of menu lists. |
| CVE-2024-27187 | HIGH | 7.5 | Aug 20, 2024 | Improper Access Controls allows backend users to overwrite their username when disallowed. |
| CVE-2023-40626 | HIGH | 7.5 | Nov 29, 2023 | The language file parsing process could be manipulated to expose environment variables. Environment variables might contain sensible information. |
Showing the 20 most severe of 76 known CVEs.
Get Third Party Support