Joomla! 6
Joomla! 6
Third-party support for the Joomla! 6: 24/7 engineers manage issues, remediate vulnerabilities, and help you maintain compliance — independent of the vendor contract.
24/7 engineers own your Joomla! 6 incidents end to end.
Mitigation and patch-around guidance when the vendor no longer ships fixes.
Controls evidence and documentation that keep auditors satisfied.
Specifications
- product
- joomla
- release
- 6
- product Label
- Joomla!
- release Label
- 6
- codename
- lts
- latest Version
- 6.1.3
- release Date
- 2025-10-14
- maintained
- true
- source Url
- https://endoflife.date/joomla
Lifecycle Dates
- End of Service Life
- Oct 16, 2029
- Last OEM Support
- Oct 17, 2028
OEM vs. 3rd Party Support
See how third-party support compares to the vendor contract for Joomla! 6 — monitoring, break/fix, vulnerability work, operations and compliance, before and after EOSL.
| Feature | OEM Support | 3rd Party Support |
|---|---|---|
| Post-EOSL Support | ||
| Break/Fix Support | Until EOSL | |
| 24/7 Monitoring | ||
| Vulnerability Scanning & Remediation | ||
| Managed Operations | ||
| Procedure & Configuration Review | ||
| Compliance & Audit Documentation | Limited | |
| Discounted Migration to Other Platforms |
Why Choose 3rd Party Support for Joomla! 6?
Vulnerability Remediation
Scanning, mitigation and patch-around guidance for Joomla! 6 when the vendor no longer ships fixes.
Compliance Maintenance
Procedure review, controls evidence and the documentation auditors ask for — maintained continuously, not scrambled at audit time.
24/7 Expert Support
Engineers who know this release monitor, manage and fix issues around the clock — break/fix to managed operations.
Joomla! 6 Support: Frequently Asked Questions
Is the Joomla! 6 still supported?
Yes. The Joomla! 6 is currently supported by Joomla!, and third-party support is available as an alternative — issue management, vulnerability remediation, and compliance help independent of the vendor contract.
When is the Joomla! 6 end of service life (EOSL) date?
Joomla! lists the end of service life for the Joomla! 6 as Oct 16, 2029.
Can I keep using the Joomla! 6 after its EOSL date?
Yes. EOSL means Joomla! stops issuing patches and support — the software itself keeps running. Third-party support covers it from there: issue management, security vulnerability remediation, and the compliance documentation auditors ask for, for as long as you choose to run it.
How much does third-party support for the Joomla! 6 cost?
Typically 40-70% below the OEM maintenance renewal price. Exact pricing depends on quantity, service level and location — request a quote and we respond within 24 hours.
Known Vulnerabilities Affecting Joomla! 6
45 published CVEs affect the Joomla! 6, including 14 rated critical or high severity. Our 24/7 engineers help you assess exposure, prioritize fixes and apply available patches.
| CVE | Severity | CVSS | Published | Summary |
|---|---|---|---|---|
| CVE-2026-48902 | CRITICAL | 9.8 | May 26, 2026 | The password and username reset features created plain http links for https connections if the "Force SSL" flag wasn't explicitly set. |
| CVE-2026-35223 | HIGH | 8.6 | May 26, 2026 | An improper access check allows unauthorized access to com_config webservice endpoints. |
| CVE-2026-23899 | HIGH | 8.6 | Apr 1, 2026 | An improper access check allows unauthorized access to webservice endpoints. |
| CVE-2026-23898 | HIGH | 8.6 | Apr 1, 2026 | Lack of input validation leads to an arbitrary file deletion vulnerability in the autoupdate server mechanism. |
| CVE-2026-48904 | HIGH | 8.2 | May 26, 2026 | An improper access check allows privelege escalation through the com_users group editing webservice endpoint. |
| CVE-2026-48898 | HIGH | 8.2 | May 26, 2026 | An improper access check allows privilege escalation through the com_users batch task. |
| CVE-2026-48897 | HIGH | 8.2 | May 26, 2026 | Insufficient state checks lead to a vector that allows to bypass 2FA checks. |
| CVE-2026-48896 | HIGH | 8.2 | May 26, 2026 | Insufficient state checks lead to a vector that allows to bypass 2FA checks. |
| CVE-2026-48901 | HIGH | 7.5 | May 26, 2026 | The InputFilter::getInstance() method omitted a security sensitive parameter from the instance cache key. |
| CVE-2026-40383 | HIGH | 7.5 | May 26, 2026 | An improper validation of user-supplied input leads to a local file inclusion vulnerability. |
| CVE-2015-4654 | HIGH | 7.5 | Jun 18, 2015 | SQL injection vulnerability in the EQ Event Calendar component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter to eqfullevent. |
| CVE-2010-2679 | HIGH | 7.5 | Jul 8, 2010 | SQL injection vulnerability in the Weblinks (com_weblinks) component in Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a view action to index.php. |
| CVE-2008-6852 | HIGH | 7.5 | Jul 7, 2009 | SQL injection vulnerability in the Ice Gallery (com_ice) component 0.5 beta 2 for Joomla! allows remote attackers to execute arbitrary SQL commands via the catid parameter to index.php. |
| CVE-2009-1499 | HIGH | 7.5 | May 1, 2009 | SQL injection vulnerability in the MailTo (aka com_mailto) component in Joomla! allows remote attackers to execute arbitrary SQL commands via the article parameter in index.php. NOTE: SecurityFocus states that this issue has been disputed by the vendor. |
| CVE-2026-48905 | MEDIUM | 6.9 | May 26, 2026 | Lack of input filtering leads to an XSS vector in the HTML filter code. |
| CVE-2026-48903 | MEDIUM | 6.9 | May 26, 2026 | Inadequate content filtering within the checkAttribute methods leads to XSS vulnerabilities in various components. |
| CVE-2026-35222 | MEDIUM | 6.9 | May 26, 2026 | Improperly validated order clauses lead to a SQL injection vulnerability in com_tags. |
| CVE-2026-35221 | MEDIUM | 6.9 | May 26, 2026 | Improperly built filter clauses lead to a SQL injection vulnerability in the search query for com_finder. |
| CVE-2026-30895 | MEDIUM | 6.9 | May 26, 2026 | Lack of output escaping leads to a XSS vector in the readmore links for com_content. |
| CVE-2026-30894 | MEDIUM | 6.9 | May 26, 2026 | Lack of output escaping leads to a XSS vector in the content history component. |
Showing the 20 most severe of 45 known CVEs.
Get Third Party Support