
โครงการ Joomla! ประกาศเปิดตัว Joomla 6.1.4 และ Joomla 5.4.9 อย่างเป็นทางการ โดยทั้งสองเวอร์ชันเป็นการอัปเดตประเภท Security & Bugfix Release สำหรับ Joomla สาย 5.x และ 6.x โดยมุ่งเน้นการแก้ไขช่องโหว่ด้านความปลอดภัย รวมถึงแก้ไขข้อผิดพลาดและปรับปรุงการทำงานของระบบ
การอัปเดตครั้งนี้ยังคงเดินหน้าตามแนวทางของ Joomla ในการพัฒนาแพลตฟอร์ม Open Source ที่ให้ความสำคัญกับการเข้าถึงเว็บไซต์ของผู้ใช้ทุกกลุ่ม ความเรียบง่าย และความปลอดภัย
พบปัญหาที่ทราบใน Joomla 5.4.9
สำหรับผู้ที่ใช้งาน Joomla 5.4.9 มีปัญหาที่ควรทราบเป็นพิเศษเกี่ยวกับ Web Services API
Web Services API ไม่สามารถใช้งานคำสั่ง PATCH ได้
เมื่อพยายามแก้ไขข้อมูลผ่าน Web Services API โดยใช้ HTTP PATCH request เช่น การแก้ไขข้อมูล Banner หรือข้อมูลผู้ใช้ ระบบจะเกิด Fatal Error ทำให้ไม่สามารถอัปเดตข้อมูลดังกล่าวได้
ปัญหานี้เป็น Known Issue ของ Joomla 5.4.9 และควรพิจารณาก่อนอัปเดตเว็บไซต์ที่มีการใช้งาน Web Services API ในลักษณะดังกล่าว
วิธีแก้ไขปัญหา
Joomla ได้จัดทำรายละเอียดเกี่ยวกับวิธีแก้ไขปัญหานี้ไว้แล้ว และการแก้ไขอย่างเป็นทางการจะถูกรวมอยู่ใน Joomla 5.4.10
รายละเอียดเพิ่มเติมสามารถดูได้จากคู่มือ Joomla:
https://manual.joomla.org/updates/53-54/known-issues/5.4.9/
Security fixes
- [20260901] - XSS in HTMLHelper::link method
- [20260902] - Core - Unauthorized user account creation via profile.save controller
- [20260903] - Core - Improper ACL checks for access level webservice endpoints
- [20260904] - Core - XSS in the generic media output layouts
- [20260905] - Core - Arbitrary directory deletion via cache purge action
- [20260906] - Core - Improper ACL checks in content history comparison view
- [20260907] - Core - Improper ACL checks in outputs for tagged items
- [20260908] - Core - XSS in HTML Mail Templates
- [20260909] - Core - SSRF vectors in various core extensions
- [20260910] - Core - Improper ACL checks for workflow stage changes
- [20260911] - Core - XSS in link toolbar layout
- [20260912] - Core - XSS in module list
- [20260913] - Core - Improper ACL checks for varous webservice edit tasks
- [20260914] - Core - MFA Authentication Bypass through rememberme cookies
- [20260915] - Core - XSS filter bypass in InputFilter via HTML5 entity decode mismatch
- [20260916] - Core - XSS filter bypass in InputFilter via whitespace characters in HTML data URIs
Bug fixes and improvements
The following bug fixes are included in Joomla! 6.1.4 and Joomla! 5.4.9 (all 5.4 bug fixes are also up-merged into 6.1):
- #46860: [5.4] Ensure absolute logo image URLs in Schema.org JSON-LD by @sathwikre
- #47213: [5.4] Fix null value for date in publish_up by @chmst
- #47461: [5.4] Fix unset operation on field variable by @ramalama
- #47495: [5.4] Ensure 'option' and 'title' attributes are respected in alternative layout XML by @Divya3215
- #47638: [5.4] Fix Tags Menu URL Parameter Issue by @CSGoat0
- #47935: [5.4] [AI] [com_media] Allow image editor to re-save file back to original non-ASCII filename by @thoni56
- #47966: [5.4] Show readmore in mod_articles when introtext_limit truncates text by @rish106-hub
- #48036: [5.4] Fix: Close/Hide dropdown before it is prematurely disabled by @hiteshm0
- #48047: [5.4] Escape csv formula characters in banner tracks export by @arib06
- #48056: [5.4] Use hash_equals for totp code verification by @arib06
- #48120: [5.4] Fix open_basedir restriction error in imagelist custom field by @bhuvan-somisetty
- #48130: [5.4] Safeguard php_uname function call by @alikon
- #48144: [5.4] smart search indexer with posgresql by @alikon
- #48208: [5.4] Fix category associations lost when a translation is unpublished by @krishnagandhicode
- #48221: [5.4] Prevent duplicate entires in #__ucm_content on every article (contaning tags) save. by @hiteshm0
- #48233: [5.4] Backport of security flag for updates by @laoneo
- #48234: [5.4] Make filter button visible in articles category list by @drmenzelit
- #48238: [5.4] [AI] Fix invalid jobLocationType values in JobPosting schema output by @Otto-Deviant1904
- #48248: [5.4] Fix Tags alias uniqueness bug by @hiteshm0
- #48252: [6.1] Add language retrieval in edit_container.php by @brianteeman
- #48274: [5.4] Fix errors in Template Manager by @joomdonation
- #48280: [5.4] Fix warning when access none source files in Template Manager by @joomdonation
- #48286: [5.4] Calendar Keyboard navigation [a11y] by @brianteeman
- #48304: [6.1] Remove csrf token check from POWcaptcha by @HLeithner
- #48320: [5.4] Prevent duplicate item selection causing 404 delete errors in media manager by @hiteshm0
- #48327: [5.4] Template Override Count - fix by @brianteeman
- #48328: [5.4] Fix duplicate options in fields by @chmst
- #48339: [6.1] fix category list filter by month error by @heelc29
- #48347: [5.4] Cast preg_match result to boolean in isImage method by @Bakual
- #48362: [5.4] Fix fulltext caption in the legacy newsflash module by @chmst
- #48368: [6.1] InstallerScriptTrait::allowDowngrades not working by @n3t
- #48386: [5.4] Fix archive extract error in template manager by @joomdonation
- #48434: [5.4] [AI] Fix untranslated buttons in the TinyMCE builder by @tecpromotion
- #48450: [5.4] Fix errors in ComponentlayoutField by @joomdonation
- #48468: [5.4] Fix clearing the workflows context selector - redo of #48079 for 5.4 by @richard67
The full list of Pull Requests for Joomla! 6.1.4 on GitHub is available here:
https://github.com/joomla/joomla-cms/milestone/168?closed=1
The full list of Pull Requests for Joomla! 5.4.9 on GitHub is available here: https://github.com/joomla/joomla-cms/milestone/167?closed=1
Where can I download Joomla 6.1.4?
You can find all Joomla 6 downloads through the official downloads page at: https://downloads.joomla.org/cms/joomla6/
New Installations
New installation instructions and technical requirements
Upgrade
Would you like to make a tour of Joomla 6 without having to install it? We have a solution for you: Install Joomla 6 at launch.joomla.org and update it (automatically).
Where can I download Joomla 5.4.9?
Packages in different formats can be downloaded as full packages for installing new Joomla Sites or as update packages for updating an existing Joomla site from:
https://downloads.joomla.org/cms/joomla5/5-4-9
How can I upgrade my site to Joomla 6.1.4?
Good news for Joomla 5.4.x to 6.x, it’s an upgrade, not a migration. Why? Two main reasons:
- Joomla 5 (J5) extensions that have removed all deprecations of code and are using up-to date Joomla code, will work in Joomla 6 (J6)
- Most others will work with the new Behaviour 6 - Backward Compatibility Plugin enabled
The full details are found here: https://guide.joomla.org/user-manual/migration/joomla-5-to-6-planning-and-upgrade-step-by-step
Note: we advise you to first test the upgrade on a copy of your production site.
You may also wonder if you have to upgrade ASAP. We’ll support Joomla 5.4.x until 13 October 2026 with bugfix patches and until 12 October 2027 with security patches. So your site is not at risk if you don’t upgrade now. And don’t forget that some of your extensions may not be yet ready for Joomla 6 (even though most developers have done a great job offering a Joomla 6 test version for a while. You can filter by version in the Joomla Extensions Directory so you can see which are ready for J6 and which are J6 ready with the b/c plugin enabled.




