Joomla! 5
Joomla! 5
Third-party support for the Joomla! 5: 24/7 engineers manage issues, remediate vulnerabilities, and help you maintain compliance — independent of the vendor contract.
24/7 engineers own your Joomla! 5 incidents end to end.
Mitigation and patch-around guidance when the vendor no longer ships fixes.
Controls evidence and documentation that keep auditors satisfied.
Specifications
- product
- joomla
- release
- 5
- product Label
- Joomla!
- release Label
- 5
- codename
- lts
- latest Version
- 5.4.112
- release Date
- 2023-10-14
- maintained
- true
- source Url
- https://endoflife.date/joomla
Lifecycle Dates
- End of Service Life
- Oct 12, 2027
- Last OEM Support
- Oct 13, 2026
OEM vs. 3rd Party Support
See how third-party support compares to the vendor contract for Joomla! 5 — monitoring, break/fix, vulnerability work, operations and compliance, before and after EOSL.
| Feature | OEM Support | 3rd Party Support |
|---|---|---|
| Post-EOSL Support | ||
| Break/Fix Support | Until EOSL | |
| 24/7 Monitoring | ||
| Vulnerability Scanning & Remediation | ||
| Managed Operations | ||
| Procedure & Configuration Review | ||
| Compliance & Audit Documentation | Limited | |
| Discounted Migration to Other Platforms |
Why Choose 3rd Party Support for Joomla! 5?
Vulnerability Remediation
Scanning, mitigation and patch-around guidance for Joomla! 5 when the vendor no longer ships fixes.
Compliance Maintenance
Procedure review, controls evidence and the documentation auditors ask for — maintained continuously, not scrambled at audit time.
24/7 Expert Support
Engineers who know this release monitor, manage and fix issues around the clock — break/fix to managed operations.
Joomla! 5 Support: Frequently Asked Questions
Is the Joomla! 5 still supported?
Yes. The Joomla! 5 is currently supported by Joomla!, and third-party support is available as an alternative — issue management, vulnerability remediation, and compliance help independent of the vendor contract.
When is the Joomla! 5 end of service life (EOSL) date?
Joomla! lists the end of service life for the Joomla! 5 as Oct 12, 2027.
Can I keep using the Joomla! 5 after its EOSL date?
Yes. EOSL means Joomla! stops issuing patches and support — the software itself keeps running. Third-party support covers it from there: issue management, security vulnerability remediation, and the compliance documentation auditors ask for, for as long as you choose to run it.
How much does third-party support for the Joomla! 5 cost?
Typically 40-70% below the OEM maintenance renewal price. Exact pricing depends on quantity, service level and location — request a quote and we respond within 24 hours.
Known Vulnerabilities Affecting Joomla! 5
63 published CVEs affect the Joomla! 5, including 20 rated critical or high severity. Our 24/7 engineers help you assess exposure, prioritize fixes and apply available patches.
| CVE | Severity | CVSS | Published | Summary |
|---|---|---|---|---|
| CVE-2026-48902 | CRITICAL | 9.8 | May 26, 2026 | The password and username reset features created plain http links for https connections if the "Force SSL" flag wasn't explicitly set. |
| CVE-2024-27185 | CRITICAL | 9.1 | Aug 20, 2024 | The pagination class includes arbitrary parameters in links, leading to cache poisoning attack vectors. |
| CVE-2026-35223 | HIGH | 8.6 | May 26, 2026 | An improper access check allows unauthorized access to com_config webservice endpoints. |
| CVE-2026-23899 | HIGH | 8.6 | Apr 1, 2026 | An improper access check allows unauthorized access to webservice endpoints. |
| CVE-2026-23898 | HIGH | 8.6 | Apr 1, 2026 | Lack of input validation leads to an arbitrary file deletion vulnerability in the autoupdate server mechanism. |
| CVE-2026-48904 | HIGH | 8.2 | May 26, 2026 | An improper access check allows privelege escalation through the com_users group editing webservice endpoint. |
| CVE-2026-48898 | HIGH | 8.2 | May 26, 2026 | An improper access check allows privilege escalation through the com_users batch task. |
| CVE-2026-48897 | HIGH | 8.2 | May 26, 2026 | Insufficient state checks lead to a vector that allows to bypass 2FA checks. |
| CVE-2026-48896 | HIGH | 8.2 | May 26, 2026 | Insufficient state checks lead to a vector that allows to bypass 2FA checks. |
| CVE-2026-48901 | HIGH | 7.5 | May 26, 2026 | The InputFilter::getInstance() method omitted a security sensitive parameter from the instance cache key. |
| CVE-2026-40383 | HIGH | 7.5 | May 26, 2026 | An improper validation of user-supplied input leads to a local file inclusion vulnerability. |
| CVE-2025-25227 | HIGH | 7.5 | Apr 8, 2025 | Insufficient state checks lead to a vector that allows to bypass 2FA checks. |
| CVE-2024-40749 | HIGH | 7.5 | Jan 7, 2025 | Improper Access Controls allows access to protected views. |
| CVE-2024-40748 | HIGH | 7.5 | Jan 7, 2025 | Lack of output escaping in the id attribute of menu lists. |
| CVE-2024-27187 | HIGH | 7.5 | Aug 20, 2024 | Improper Access Controls allows backend users to overwrite their username when disallowed. |
| CVE-2023-40626 | HIGH | 7.5 | Nov 29, 2023 | The language file parsing process could be manipulated to expose environment variables. Environment variables might contain sensible information. |
| CVE-2015-4654 | HIGH | 7.5 | Jun 18, 2015 | SQL injection vulnerability in the EQ Event Calendar component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter to eqfullevent. |
| CVE-2010-2679 | HIGH | 7.5 | Jul 8, 2010 | SQL injection vulnerability in the Weblinks (com_weblinks) component in Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a view action to index.php. |
| CVE-2008-6852 | HIGH | 7.5 | Jul 7, 2009 | SQL injection vulnerability in the Ice Gallery (com_ice) component 0.5 beta 2 for Joomla! allows remote attackers to execute arbitrary SQL commands via the catid parameter to index.php. |
| CVE-2009-1499 | HIGH | 7.5 | May 1, 2009 | SQL injection vulnerability in the MailTo (aka com_mailto) component in Joomla! allows remote attackers to execute arbitrary SQL commands via the article parameter in index.php. NOTE: SecurityFocus states that this issue has been disputed by the vendor. |
Showing the 20 most severe of 63 known CVEs.
Get Third Party Support