Joomla 4.3.2 Security and Bug Release (2023)

Joomla 4.3.2 Security and Bug Release

Joomla! The Project is pleased to announce the release of Joomla 4.3.2. This is a security and bugfix release for the Joomla 4.x series.

This release continues Joomla 4's high standards of accessible web design, underscoring Joomla's values ​​of consistency, simplicity and security in an even more powerful open source web platform.

Security issues were fixed with 4.3.2

  • [20230501] Low Severity - Low Impact - Low Probability - Open redirect and XSS inside mfa option (affects Joomla! 4.2.0 - 4.3.1)
    More information
  • [20230502] Moderate Severity - Critical Impact - Low Probability - Prevent mfa screen brute force (affects Joomla! 4.2.0 - 4.3.1)
    More information

Bug fixes and improvements with 4.3.2

This release fixes issues that many users are experiencing during the upgrade process. In particular, this edition concerns:


  • hide table headers instead of skipping them when "show headers" is set to "no"


  • aria-label is not translated in com_banners
  • reset banner copy statistics
  • banner cannot be bulk copied


  • cannot bulk copy contacts


  • Improved validation of content items when only positive integers are allowed


  • TinyMCE prevents white text on a white background in preview
  • TinyMCE editor plugin language breaks if subform fields are empty
  • Codemirror fix path for keybinding script


  • reintroducing specific layouts to render custom contact fields
  • calendar type min/max year
  • PHP warning when initializing text field

Guided tours

  • Data leakage during upgrade or new installations is not necessary for column "extensions".
  • Banner browsing skips some fields
  • Order of modal browses should not be auto-sorted, use browse display order

media manager

  • replace "an error occurred" with "this file type is not supported"
  • alternative refactor session
  • remove the no-console notification

Email templates

  • The label must be quoted before passing to the regular expression
  • the new email template created is not registered correctly in the database (missing extension data and duplicate tags)

search smart

  • add padding to search words highlighted in smart search
  • find if the memory engine is supported


  • router issues on multilingual sites breaking old URLs
  • hide filter_tag url parameter when creating menu item with category type and filtering by tag or tags


  • invalid json string template parameter
  • Removed PHP 8.1 warnings from template manager
  • Missing Cassiopeia black color variant
  • Cassiopeia menu breakpoint for burger to avoid vertical menu

by user

  • Javascript error on login page during MFA
  • Text() not found in user connection
  • Category access levels should not apply to users with core.admin access
  • Usergroups tab uses invalid checkbox IDs
  • Unit locations are not shown in com_user settings
  • removed login message when logging in frontend
  • Fix submit button focus on captive MFA login page in frontend when using Webauthn


  • allow new class when no other class exists
  • when an item is disabled, the menu items icon should show "item not found" and represent a warning instead of a cross with a "publish item" tooltip
  • improved messages when checksum information is missing from an extension (hash codes that prove the file is authentic)
  • Article category module cache no longer fails
  • makes runner/keepalive work with adblockers/no script
  • remove all spaces from the disable_functions string in php.ini before exploding into an array to check and avoid errors
  • undefined key in HTMLDocument setBuffer
  • PluginHelper::getLayoutPath should work in CLI (in non-web environment)
  • Show empty status layout only when cache contains no data
  • improved RSS page title
  • help index update
  • Avisos makes PHP 8.2 without additional Multilingual sample data
  • list-view .js should work with Ajax content

The full list on GitHub is here

Where can I download Joomla 4.3.2?

On the Downloads site, of course :)

new facilities

New installation instructionsmtechnical requirements

Installation 4.3.2

For information

Update 4.3.2

To learn more about our growth strategy, read onthis article.

Where can I find documentation for Joomla 4?

You can find the Joomla 4.3 documentation here:

There are a few tutorials to help you with Joomla 4. You can find existing ones, how to create a plugin or module for Joomla 4, namespace conventions, prepared instructions, using the new web resource classes, and more atΚατηγορία:Joomla!_4.x

Developers are encouraged to help write documentation for Joomla 4 atdocs.joomla.orgto help and guide users and other extension developers.

A JDocs page will help developers see existing documentation and documentation they still need.

We invite you to consult it regularly, update it and provide the missing content:

Most of the feature documentation is now required as we reach the release candidate stage.

Should I plan to upgrade to Joomla 4.3?

Joomla 4.x is the last major version of Joomla. Joomla 4.3 is the latest minor release.

Joomla 3.10 was released alongside Joomla 4 as the last minor version of Joomla 3 (seethis article).

Joomla 3.10 will continue to be supported until August 2023, although 21 months have passed since the release of Joomla 3.10 and 4.0. Joomla 3 will only receive security releases.

You must be planning or in the process of migrating to the latest version of Joomla.

We provide resources to help with the migration on the documentation site.

Make some noise. Joomla 4.3.2 has been released!

The best Joomla yet has been released. Let's tell the world!

Stay informed about the great new features using the hashtag #Joomla4 and #Joomla4All.

Brochure J4:

J4 Documentation:!

Who is Joomla! For?

Need to build a website? For personal use, your project, charity, non-profit. Perhaps a university or a local government, then Joomla is for you.

An online office needs a well-supported structure that can grow according to the needs of its clients. Then Joomla is for you.

Written by volunteers from all walks of life, it's used online for all kinds of projects: from blogs and intranets to national government websites. From small shops to the world's leading brand websites, Joomla can be developed to meet your needs.

Joomla's strength comes from its ever-evolving code base, following best practices, but also from its large ecosystem of developers who see opportunities in the market and fill those gaps with good software designed to meet real needs.

Joomla 4.3.2 is the latest in a world-class CMS that lets you launch your website knowing it can grow with your needs and scale with your customers.

All this and Joomla 4 is open source software and free to use.

What are you waiting for? Install today and expand your future.

How can you help develop Joomla?

There are several ways you can get actively involved with Joomla. It doesn't matter if you are a coder, developer or Joomla user. You can contact any of our volunteer teams for more information, or if you're ready, you can go directly to Joomla! Bug Squad.

THEJoomla! Bug Squadthis is inCMS Release Teamare some of the most active teams in the CMS development process and are always looking for people (not just developers) who can help sort through bug reports, coding patches, and test solutions. A great way to increase your working knowledge of the Joomla code base and also a great way to meet new people from all over the world.

If you are interested, read about them here.Joomla! Wikiand, if you want to participate, send an emailThis email address is being protected from spam. You need JavaScript enabled to view it..

The Project would also like to thank all contributors who took the time to prepare and submit work for inclusion in the Joomla CMS and framework.

Joomla 4.3.2 is the result of thousands of hours of work by manyvolunteers.

A huge thanks to everyone who contributed to version 4.3.2!

Relevant information

If you're an extension developer, make sure you're subscribed to thegeneral developer mailing list, where you can discuss extension development. News that may affect custom development will also be posted there from time to time.



How long will Joomla 4 be supported? ›

Joomla! 4. x
Development Status
Upcoming Release4.3.3
Release Date of Series17 August 2021
End of Support for 4.x17 October 2025
Download Joomla! 4
1 more row

Is Joomla still supported? ›

When will the support end. Joomla 3 support will end on August 17, 2023. The Joomla team has announced that all users will have to migrate to Joomla 4 before that time to continue being supported for malware and software fixes.

What is the latest update for Joomla 4? ›

Joomla 4.2 is Joomla's latest major version. Joomla 3.10 will continue to be supported with security fixes until 17th August 2023, giving you plenty of time to plan your migration to Joomla 4 and update your extensions (if required) to become Joomla 4 compatible versions.

Why is Joomla open-source? ›

Joomla is an open source Content Management System (CMS), which is used to build websites and online applications. It is free and extendable which is separated into front-end and back-end templates (administrator).

Is Joomla 4 stable? ›

Joomla 4 is currently available as a stable release meaning it can be used for live websites. Most Joomla sites also run some add-on software called extensions which add extra features and functionaloity to Joomla websites.

Is K2 ready for Joomla 4? ›

Given the above, K2 for Joomla 4 will be released as v4 and will most likely only support Joomla 4. We'll keep the 2. x series for Joomla 1.5 - 3. x and update as long as possible to allow you for an easy upgrade path to Joomla 4 (or 5) when you decide to do that.

What are the limitations of Joomla? ›

Cons of Joomla! CMS
  • Slightly Complex. As mentioned before, Joomla! is more complex than WordPress, making it difficult to incorporate your own custom design without developer experience. ...
  • Small Module Marketplace. Unlike WordPress, Joomla! has a much more limited marketplace for additional modules and add-ons.
Nov 26, 2014

What is better than Joomla? ›

WordPress's vast number of security plugins provides a better chance of preventing cyberattacks than Joomla. While the setup process may be challenging for beginners, you can always refer to online tutorials or hire a professional for help.

How secure is Joomla? ›

Joomla! is a very secure website management system. It uses a variety of security measures to keep your data safe. Joomla!'s security measures include: -Two-factor authentication: This authentication process requires you to enter two pieces of information, like a password and a code, to access your account.

Is Joomla 4 better than WordPress? ›

Joomla Advantages

Multilingual support – Joomla has multilingual support built-in to the core, while WordPress requires you to use a third-party plugin. Multiple templates – Joomla lets you use different templates for different pieces of content, whereas you can only use one WordPress theme.

What is the difference between Joomla 3 and 4? ›

A: The main differences between Joomla 4 and Joomla 3 are a completely new architecture and codebase, support for modern web technologies like HTML5 and CSS3, an improved user experience with custom fields, a new media manager, an improved administrative interface, and a stronger security system.

What version of PHP does Joomla 4 need? ›

Requirements for Joomla! 4.x
Supported Databases
MySQL5.6 +5.6
PostgreSQL11.0 +11.0
4 more rows

Why is WordPress more popular than Joomla? ›

WordPress is considerably easier to use than Joomla when it comes to getting set up. Your WordPress site can be up and running in a matter of hours, especially if it's a simple blog or a business site with just a few pages. The interface is intuitive and a cinch to learn, even for casual users and non-developers.

Who owns Joomla? ›

Joomla is developed by a community of volunteers supported with the legal, organisational and financial resources of Open Source Matters, Inc.

Is WordPress more secure than Joomla? ›

Understanding that there is no CMS that is 100% secure, Joomla also offers a set of security extensions and plugins. While WordPress requires extra plugins to set up SSL, Joomla has its “Joomla Force SSL”, which allows users to activate Joomla SSL Certificate in their core system without installing any extra extension.

What is Web authentication in Joomla 4? ›

Web Authentication, or WebAuthn for short, allows a user to securely log into a site without using a password — though you still need to provide your username.

How to clear cache in Joomla 4? ›

In the top right corner of the dashboard, you can click on Cache in the area labeled System. Or, you can click on System in the main menu (at left), and then click on Clear Cache in the Maintenance section.

Why is Joomla so slow? ›

A Joomla Website loads its contents and it also loads CSS, JS files which may slow down the whole loading process. CSS & JS files takes a lot of time for rendering and executing. This issue can be easily resolved by: Compressing CSS, JS files.

Is Joomla 3 approaching its end of life? ›

Support ends 17 August 2023.

Does Joomla use SQL? ›

Joomla can use different kinds of SQL database systems and run in a variety of environments with different table-prefixes. In addition to these functions, the class automatically creates the database connection.

How do I protect my Joomla website from hackers? ›

  1. 1 – Update Joomla Core & Extensions. ...
  2. 2 – Remove Unused Templates & Extensions. ...
  3. 3 – Hide the Joomla Admin Panel. ...
  4. 4 – Secure Access Points. ...
  5. 5 – Enable Multi-Factor Authentication. ...
  6. 6 – Practice the Principle of Least Privilege. ...
  7. 7 – Use It or Lose It: Redux (Users) ...
  8. 8 – Monitor Your Site.
Oct 4, 2022

How do I make my Joomla website secure? ›

The following tips will help you increase your Joomla website security.
  1. Use strong login details.
  2. Don't install too many extensions.
  3. Restrict file and directory permissions.
  4. Protect administrator login.
  5. Use a web application firewall.
  6. SSL Certificate.
  7. Monitor your website.
  8. Keep Joomla and its extensions updated.
Jan 5, 2017

Is Drupal better than Joomla? ›

Joomla is easier to use and has a more user-friendly interface, making it a good choice for beginners. Drupal, on the other hand, is more complex and flexible, making it a better option for developers and larger, more complex websites.

Does IKEA use Joomla? ›

IKEA is a prominent ready-to-sell furniture store using Joomla websites. Based out of Sweden, it has branches all over the world and its furniture is regarded of highest quality.

What percentage of websites use Joomla? ›

Joomla's market share is only 2.7%, about 20 times smaller than WordPress'. Nearly 85,000 million-dollar companies chose to use Joomla in 2022. Joomla has a total download of 123 million, the same as Mario Kart Tour when it was first released in 2019. Joomla's website gets 700,000 to 800,000 visits per month.

What are the disadvantages of Joomla CMS? ›

Potential disadvantages of Joomla include its steep learning curve and lack of certain features. Some disadvantages of using Joomla include: -Slow: Joomla can be slow to load, especially on large websites. -Limited features: Joomla doesn't offer as many features as some other more popular content management systems.

What encryption does Joomla use for password? ›

Joomla < 3.2

Passwords are MD5 hashed and salted.

What database does Joomla use? ›

MySQL is the most popular database system. It's widely used in many database-driven applications, such as Joomla. phpMyAdmin is the most popular open source tool for accessing and editing MySQL databases.

What is the advantage of Joomla? ›

Build powerful PHP applications

Joomla is not only a CMS, but also a stable and lightweight PHP framework which allows you to write web and command line applications in PHP. The Joomla Framework is easy to adapt and extend according to your needs.

Is Joomla the best CMS? ›

Joomla CMS is best used if you still need one or plan to hire someone with development experience. The interface is more “beginner-friendly,” but some coding skills will be required to get the backend up. Even managing your products is possible without changing tabs. In this case, he is a clear winner.

Which is easier to use WordPress or Joomla? ›

WordPress is relatively easy to use and most users will be acclimated within just a few minutes. However, the advanced features will take much longer to master. Joomla's primary focus is on more advanced technical user, so it has a larger learning curve.

Which is the best forum for Joomla? ›

List of the Best Joomla Forum Extensions So Far
  • Kunena.
  • Chrono Forums.
  • TF Form.
  • CJ Form.
  • JFusion Forum and Category.
  • JFusion Forum Posts.
  • JFusion Forum Topic.
  • JFusion Forum Notification.
Nov 9, 2021

Which slider is best for Joomla? ›

Smart Slider 3 is the top rated slider extension for Joomla with more than 900.000 satisfied users.

What is the best responsive Joomla template? ›


When it comes to responsive Joomla free templates, Purity III is among the greatest options out there. It's a flexible framework for building any kind of Joomla site, from a personal blog to a corporate portfolio.

Which is the best Joomla LMS extension? ›

  • Quix. Joomla website without hassle. Visual Site Builder. Drag & Drop realtime editing. Header & Footer Builder. Endless design customization. Blocks Templates. Pre-designed section templates. Page Templates. Pre-designed page template library. Performance & SEO. ...
  • vs The Competition.
  • Templates.
  • Resources.
May 7, 2023

Is PHP 4 deprecated? ›

PHP 4 style constructors (methods that have the same name as the class they are defined in) are deprecated, and will be removed in the future. PHP 7 will emit E_DEPRECATED if a PHP 4 constructor is the only constructor defined within a class.

How to install languages in Joomla 4? ›

Select System from the sidebar. Under Manage, select Languages. You'll see your current language listed. To add more, select Install Languages.

What is small PHP maximum post size in Joomla 4? ›

This is the maximum amount of data that can be sent via POST to the server. This includes form submissions for articles, media (images, videos) and extensions. This value is less than 8MB which may impact on uploading large extensions. This is set in the php.

What is the most advanced WordPress form? ›

The most advanced form plugin for WordPress is Gravity Forms. It offers a comprehensive suite of features, including multi-step forms, advanced conditional logic, calculation fields, and the ability to accept payments. It also has extensive add-ons to integrate with various services, catering to advanced users.

What makes Joomla unique? ›

A huge reason Joomla is so popular worldwide is the extensive internationalized language support it offers. Joomla can be installed in many different languages, or with multiple languages, and it offers basic multilingual features right out of the box.

Which CMS is better than WordPress? ›

Drupal is a full CMS that targets the same demographic as WordPress does. Unlike WordPress, which began as a dedicated blogging platform, Drupal has been a CMS from the very beginning. Like WordPress, it's both free and open-source, and it's available for quick installation from most web hosting providers.

What is the salary of Joomla? ›

Average salary for a Joomla Developer in India is 6 Lakhs per year (₹50.0k per month).

Is eBay using Joomla? ›

eBay (NASDAQ:EBAY), the world's largest online marketplace, today announced an agreement to use Joomla, the most popular open source content management system (CMS), to launch a community portal as part of eBay's internal analytics platform.

Does GoDaddy support Joomla? ›

GoDaddy hosting can be used for self-installation of popular CMS, including WordPress, Joomla, Magento and Drupal.

Which CMS is more secure? ›

WordPress, Drupal, and Joomla are among the best and more secure CMS for creating top-notch websites. It is tough to select a single platform among these three options as all have their own merits and demerits.

Is WordPress the most hacked CMS? ›

WordPress is the most popular CMS in the world. It powers more websites than any other software. WordPress is used by over 800 million websites worldwide. But unfortunately, that popularity also makes it one of the most common targets for hackers.

What is the largest danger in WordPress site security? ›

Below are the top 7 WordPress security threats and how to fix them.
  1. Password hacking. ...
  2. SQL injections. ...
  3. Database attacks. ...
  4. Brute force attacks. ...
  5. Hijacking an open user. ...
  6. Cross-site scripting (XSS) ...
  7. DDoS Attacks.
Mar 10, 2023

How long will Joomla 3.10 be supported? ›

Support ends on 17 August 2023 for Joomla 3.10.

What are the weaknesses of Joomla? ›

Higher Degree of Complexity than WordPress

When compared to WordPress, a notable disadvantage of Joomla is that it is more complex. Its user interface is more complex, and it has more functions that make it more complicated than WordPress or other simpler CMS platforms. This complexity translates to a learning curve.

What are the disadvantages of using Joomla? ›

Disadvantages Of Joomla

Unlike WordPress, Joomla does not offer you free hosting. You will have to host your website on the server and you need to pay for it. Given the other advantages, this should not be the reason you rebut from using Joomla. Cost is something you must consider every time.

Is Joomla obsolete? ›

Joomla is still a stable product. It'll likely be the same, reliable CMS in 2021, 2022 and 2023. If you are looking for a safe, reliable solution for your website with specific strengths, then of course Joomla is definitely still a good choice for a CMS in 2021.

Is WordPress easier to use than Joomla? ›

Ease-of-Use Comparison

WordPress is relatively easy to use and most users will be acclimated within just a few minutes. However, the advanced features will take much longer to master. Joomla's primary focus is on more advanced technical user, so it has a larger learning curve.

How safe is Joomla? ›

Joomla has a strong reputation for security compared to other CMS platforms like WordPress, Drupal, and Magento. Features such as two-factor authentication, administrator privilege control, and secure password encryption make Joomla one of the most secure CMS platforms.

How to install Joomla without losing data? ›

How to Reinstall Joomla
  1. Backup your website and your database. ...
  2. Download the same version of Joomla that you have. ...
  3. Rename the directory containing your current Joomla website. ...
  4. Re-create your old directory. ...
  5. Upload a fresh copy of Joomla. ...
  6. Run the Joomla installer.

Can you upgrade from Joomla 3 to Joomla 4? ›

Now finally it's time to migrate from Joomla 3 to Joomla 4 by updating and installing Joomla 4. To do the same, continue with these steps: Click on System > Global Configuration > Server Tab > Error Report > Maximum. Click on Save and close.


Top Articles
Latest Posts
Article information

Author: Melvina Ondricka

Last Updated: 08/12/2023

Views: 6525

Rating: 4.8 / 5 (48 voted)

Reviews: 87% of readers found this page helpful

Author information

Name: Melvina Ondricka

Birthday: 2000-12-23

Address: Suite 382 139 Shaniqua Locks, Paulaborough, UT 90498

Phone: +636383657021

Job: Dynamic Government Specialist

Hobby: Kite flying, Watching movies, Knitting, Model building, Reading, Wood carving, Paintball

Introduction: My name is Melvina Ondricka, I am a helpful, fancy, friendly, innocent, outstanding, courageous, thoughtful person who loves writing and wants to share my knowledge and understanding with you.