
โครงการ Joomla! ประกาศเปิดตัว Joomla 6.1.3 และ Joomla 5.4.8 อย่างเป็นทางการ โดยทั้งสองเวอร์ชันเป็นการอัปเดตในกลุ่ม Security & Bugfix Release สำหรับ Joomla สาย 5.x และ 6.x ซึ่งมุ่งเน้นการแก้ไขช่องโหว่ด้านความปลอดภัย รวมถึงแก้ไขข้อผิดพลาดต่าง ๆ ที่พบในระบบ
การอัปเดตครั้งนี้ยังคงเดินหน้าตามแนวทางของ Joomla ในด้านการพัฒนาเว็บไซต์ที่เข้าถึงได้สำหรับผู้ใช้ทุกกลุ่ม พร้อมให้ความสำคัญกับแนวคิดเรื่อง ความครอบคลุม ความเรียบง่าย และความปลอดภัย เพื่อให้ Joomla ยังคงเป็นแพลตฟอร์ม Open Source สำหรับการพัฒนาเว็บไซต์ที่มีประสิทธิภาพ
Security fixes
- [20260801] - Core - Response header injection in download views
- [20260802] - Core - Improper CORS origin validation
- [20260803] - Core - Inconsistent ACL checks for mutating webservice endpoints
- [20260804] - Core - Improper ACL checks for custom fields webservice endpoints
- [20260805] - Core - Improper ACL checks for category webservice endpoints
- [20260806] - Core - XSS through schema.org outputs
- [20260807] - Core - MFA Authentication Bypass
- [20260808] - Core - Improper ACL checks for batch copy actions
- [20260809] - Core - Improper ACL checks when injection schema.org contact data
- [20260810] - Core - Unrestricted uploads of SHTML files
Bug fixes and improvements
The following bug fixes are included in Joomla! 6.1.3 and Joomla! 5.4.8 (all 5.4 bug fixes are also up-merged into 6.1):
- #46805: [5.4] check ACL when display link to user edit form by @heelc29
- #47202: [5.4] Editing menu item redirects to list view with original filters by @hiteshm0
- #47626: [5.4] Implement date and time validation on input change (and more) by @cyrez
- #47766: [5.4] Better error messages on updateserver errors by @TLWebdesign
- #47780: [5.4] Fix: Change data-nested='true' for nested components (Categories, Menu Items, Modules) by @RiteshGite
- #47886: [5.4] [AI] Fix Global Check-in treating checked_out=0 rows as needing check-in by @genr8r
- #48060: [5.4] Fix article options ignored on article view by @joomdonation
- #48074: [5.4] Prevent DivisionByZeroError in ListModel when list.limit is 0 by @Denitz
- #48080: [5.4] Update joomla/filesystem from 3.2.0 to 3.3.0 and partly backport PR 48038 from 6.1-dev by @richard67
- #48081: [6.1] Remove tinymce Bosnian language files from deleted files list in script.php by @richard6
- #48088: [5.4] fix duplicate no results message in installed languages by @adarshdubey03
- #48091: [5.4][plg_actionlog] log user block/unblock only 1 by @alikon
- #48116: [5.4] Clean up filepatcher remainders from 5.4.7 hotfix on core update by @richard67
- #48163: [5.4] fix division by zero in subforms by @chmst
- #48171: [5.4] Add path traversal checks in com_templates by @SniperSister
- #48173: [5.4] Smart Search: Standardize memory_table_limit by @Hackwar
- #48184: [5.4] awesomplete example typo by @brianteeman
- #48185: [5.4] Backport Fix treeselect indentation- #48125 by @brianteeman
- #48212: [5.4] Fix days_of_week normalization (shorter version) by @tecpromotion
- #48216: [5.4] site offline by @brianteeman
The full list of Pull Requests for Joomla! 6.1.3 on GitHub is available here:
https://github.com/joomla/joomla-cms/milestone/166?closed=1
The full list of Pull Requests for Joomla! 5.4.8 on GitHub is available here: https://github.com/joomla/joomla-cms/milestone/165?closed=1
Where can I download Joomla 6.1.3?
You can find all Joomla 6 downloads through the official downloads page at: https://downloads.joomla.org/cms/joomla6/
New Installations
New installation instructions and technical requirements
Upgrade
Would you like to make a tour of Joomla 6 without having to install it? We have a solution for you: Install Joomla 6 at launch.joomla.org and update it (automatically).
Where can I download Joomla 5.4.8?
Packages in different formats can be downloaded as full packages for installing new Joomla Sites or as update packages for updating an existing Joomla site from:
https://downloads.joomla.org/cms/joomla5/5-4-8
How can I upgrade my site to Joomla 6.1.3?
Good news for Joomla 5.4.x to 6.x, it’s an upgrade, not a migration. Why? Two main reasons:
- Joomla 5 (J5) extensions that have removed all deprecations of code and are using up-to date Joomla code, will work in Joomla 6 (J6)
- Most others will work with the new Behaviour 6 - Backward Compatibility Plugin enabled
The full details are found here: https://guide.joomla.org/user-manual/migration/joomla-5-to-6-planning-and-upgrade-step-by-step
Note: we advise you to first test the upgrade on a copy of your production site.
You may also wonder if you have to upgrade ASAP. We’ll support Joomla 5.4.x until 13 October 2026 with bugfix patches and until 12 October 2027 with security patches. So your site is not at risk if you don’t upgrade now. And don’t forget that some of your extensions may not be yet ready for Joomla 6 (even though most developers have done a great job offering a Joomla 6 test version for a while. You can filter by version in the Joomla Extensions Directory so you can see which are ready for J6 and which are J6 ready with the b/c plugin enabled.




