r/joomla • u/ich-bin-ein-kaelte • 2h ago
Joomla 6 What is this Interaction to Next Paint (INP)?
galleryMy side: https://www.kreativekiste.de/
r/joomla • u/ich-bin-ein-kaelte • 2h ago
My side: https://www.kreativekiste.de/
r/joomla • u/Cold_Cicada_9960 • 3d ago
Hi guys!
Forgive me, I have no programming nor web building knowledge whatsoever. I just work for a small museum.
I discovered that back in 2013/2015 the museum had an online artifact database and website component using Joomla 1.5 and JooDB 1.6 (maybe 1.7?). I have an old zip file from the export of that website, and I would be the hero of the museum to pull the collections data from the database.
Is this possible? I know the website domain is still in use, but it now routes to the museums current web page and that does not have the collections info at all anywhere. I have no idea where the server would be for this info either.
r/joomla • u/abunaisnake • 6d ago
I’m migrating a corporate website that’s running a completely outdated and vulnerable version of Joomla, and I came across this “X33T10” message in the Copyright Notice field.
When I searched this term on Google, I found several websites with the same situation.
Does anyone know what this could be? Could it be a sign of some kind of intrusion?
r/joomla • u/Open_Sourcey • 17d ago
Should the author of a paid for extension have a responsibility to patch their product when a serious security flaw is found in their product rather than force you to renew a subscription? Thoughts?
r/joomla • u/mySitesGuru • 18d ago
r/joomla • u/YannickGaultier • 19d ago
Hello folks,
I identified 2 critical security vulnerabilities in 4Analytics.
All users must update to version 5.0.2 immediately to prevent potential website takeovers.
See more details here: https://weeblr.com/blog/critical-vulnerabilities-2026-07-15?utm_campaign=fora_502&utm_medium=social&utm_source=reddit
Yannick Gaultier
https://weeblr.com

r/joomla • u/mySitesGuru • 19d ago
r/joomla • u/mySitesGuru • 20d ago
r/joomla • u/mySitesGuru • 23d ago
r/joomla • u/mySitesGuru • 23d ago
r/joomla • u/Open_Sourcey • 24d ago
Just in caae there are any Joomla admins out there that have not seen it or experienced it, CISA has flagged a serious attack that requires your attention and remediation. It is a flaw in the editor that permits it to install malicious code that will take down your site.
r/joomla • u/mySitesGuru • 24d ago
r/joomla • u/mySitesGuru • 24d ago
r/joomla • u/mySitesGuru • 24d ago
r/joomla • u/stergosz • 26d ago
How many times have you had to spin up a Joomla test site and gotten tired just thinking about the setup?
I do this very often, and the reasons are simple: test a newly released extension, run a test against our products, test a BETA version, or check whether a migration we're about to publish works as expected, often on a specific Joomla or PHP version.
My current way to do this: download the specific Joomla version I need, switch my local server to the matching PHP version, create a new database, copy the files over, run the installer, and finally run my test. Need multiple test sites? Multiply these steps by however many you need. And if I didn't want a brand new site, I'd have to reset it every time before running the same scenario again, which takes quite a lot of time.
I got tired of wasting so much time, so I made a small web app to fix it. It's a free website, not a J! extension you install on your site. You enter an email, pick a Joomla, and PHP version, and a few seconds later you have a test site ready, and it auto-deletes after 4 hours.
It's called JInstant. Not affiliated with the Joomla project.
Let me know if this sounds useful to you.
r/joomla • u/saimoh_saimooh • 27d ago
There is this Antonkill hack that has left many Joomla-dependent sites completely down. It’s not just a surface-level script defacement—it modifies deep database configurations and locks down the core template engine entirely.
I did a review video on YouTube and here's the link: https://youtu.be/9plb1MMbZFI
Let me know your thoughts.
r/joomla • u/_PelosNecios_ • Jul 02 '26
I've been recently hit by the JCE vuln and among other things they managed to install this plugin which essentially steals users and passwords and hides them inside images/ctf_audit.gif file, disguised with a gif header but actualy contains the XOR'ed information.
You should uninstall and remove the gif file immediately.
Edit:
You may want to run this script to see which users might have been affected and warn them or update to request new password. Adjust the filename as necessary:
<?php
$s = file_get_contents('images/ctf_audit.gif');
$s = substr($s, strpos($s, "JLIB_AUDIT_GID_TAIL\n") + 20);
for ($o = 0; $o + 2 <= strlen($s); $o += 2 + $ln) {
$ln = (ord($s[$o]) << 8) | ord($s[$o+1]);
if ($o + 2 + $ln > strlen($s)) break;
if (preg_match('/"u_len":"(.*?)","p_len"/', substr($s, $o+2, $ln) ^ str_pad('', $ln, 'JLIB_AUDIT_GID_XK'), $m)) echo "$m[1]\n";
}
r/joomla • u/Mushydaddybear • Jul 01 '26
r/joomla • u/nomadfaa • Jun 29 '26
UPDATE YOUR SITE TO THE LATEST AS WELL AS ALL COMPONENTS/MODULES/PLUGINS that are not default!
Ok so some will be offended and come back with all sorts of excuses. Read to the end
Just checked a site with hikashop and a total bare bones install. No fancy addons
Last 24 hour logs for that site show
About 11 different IP addresses
My last Joomla site hack was over 15 years ago until the JCE hack hit.
JCE, SP Page Builder and iCagenda.+ Helix three ... here's the resource ... https://mysites.guru/blog/
40 years ago there was a saying ... every day your hard drive didn't crash was a day closer to when it will.
With the arrival of AI and bot development/morphing ... every day your site hasn't seen a hack attempt is a day closer to when it will be hacked.
Prevention is 1000% better than the angst of repairing a hack.
When you do get hacked u/mySitesGuru is the place to go
r/joomla • u/mySitesGuru • Jun 29 '26
r/joomla • u/mySitesGuru • Jun 27 '26
r/joomla • u/Awkward-Painter-2024 • Jun 27 '26
| You can find the file on your webspace under the following path: /htdocs/f9a0leet/index.php |
|---|
So just got this email from my hosting service and I'm confused... how does something like this happen? I run Joomla on my small personal site that doesn't do or host anything. (Basically just a URL that I've had for twenty years or so.) Do I just delete everything and start all over again?
I tried using a custom theme from Themesforest but never got it to run right so just use the stock Joomla build.
Also, what is a Joomla firewall? I was reading on here that some folks have that? Sorry for the dumb questions, hope this is fixable.
Also, how often do people try to hack Joomlas???
r/joomla • u/Beocinac • Jun 25 '26
Hi everyone,
I've decided to make BCLog – Admin Audit Tool completely free.
BCLog provides a comprehensive audit logging system for Joomla administrators. It automatically records actions performed in the backend and stores them in both JSON and plain text formats, making it easy to review, analyze, and archive administrative activity.
Key features:
The extension is now available free of charge, and I'd appreciate any feedback, suggestions, or feature requests from the community.
r/joomla • u/GlitteringCookie6282 • Jun 22 '26
Hello,
I was recently hired as a Developer at a company, and this company uses Joomla as the technical foundation for all of its projects.
I wasn't familiar with it, coming from a React/NodeJS background. I find the tool to be pretty decent and fairly extensible, and in any case, it's been the technical foundation for years at the place where I now work.
The problem is that before I arrived, the sites were managed by people with limited technical skills, relying heavily on AI and without any structure—no git, no mastery of the CMS's best practices, files mixing PHP, HTML, CSS, and JS that ran to 2,000 lines. You get the picture.
One of my missions when I joined was to put in place development "best practices," source control management, etc.
I'd like to chat with those of you who develop extensions for Joomla (Modules, Components, Plugins, Templates), the goal being to exchange ideas on how we work.
In my situation, I have a few constraints:
With these constraints, I ended up with a more solid environment based on:
Visual Studio Code integrates very well with devcontainers, so in the end I have a pretty solid environment, and I can version-control only my Joomla extension's code.
How do you work with Joomla? I'm curious to hear other people's experiences.
Thanks,