v3.16 is out — Little WAF, a smarter Joomla Update and a new round of backported security fixes →

Joomla 3.x UTD: secure, current & still yours kept up to date by the community

An up-to-date distribution of Joomla 3.x. Backported security fixes, PHP up to 8.5, current MySQL & MariaDB — and a drop-in upgrade for the sites you already run.

~/sites/example.com — upgrade

    
// why this exists

Official support ended. We kept going.

According to market share estimates (as of May 2026), Joomla 3.x is currently used on more than 50% of all installed Joomla sites worldwide. However, official support for Joomla 3.x ended in February 2025 (counting the eLTS program).

So we're actively developing Joomla 3.x UTD as an up-to-date distribution of the Joomla 3.x content management system, built to ensure code security, support modern PHP & MySQL/MariaDB versions & fix any broken behaviour that never got sorted before the release of newer major versions of Joomla.

“
A short statement from the maintainers about why Joomla 3.x deserves to stay alive, and who this distribution is for.
IMGMaintainer nameRole, JoomlaWorks placeholder
// install

Upgrade in place. Or start fresh.

One rolling release, one download path that never changes. Point your backend at our update feed, or extract on top of an existing Joomla 3.x site.

Full guide on GitHub →
existing sites · web ui

Joomla Update component

In the backend, open the Joomla Update options (or Global Configuration) and use these settings. Refresh, and the latest release shows up.

Update Channel
Custom URL
Min. Stability
Stable
custom url
https://joomlaworks.github.io/joomla-3.x/list.xml

Future updates appear there too, with super admin notifications if enabled.

existing sites · cli

One-liner over SSH

On a typical Linux server, cd into your Joomla site's folder and run:

bash
wget -qO- https://github.com/joomlaworks/joomla-3.x/archive/refs/heads/main.tar.gz | tar -xz --strip-components=1 && rm -rf installation .github .gitignore *.md

Extracting the zip manually? Remember to remove the /installation folder afterwards.

new sites

Fresh install

Extract the latest rolling release where you want the site to be, then follow the normal Joomla installation process.

Download joomla-latest.zip
rolling release
…/releases/download/rolling/joomla-latest.zip

Built and tested for Linux/BSD. XAMPP or MAMP should work, but aren't tested.

// compatibility

It runs where your sites already live

PHP 7.4 is the recommended baseline, not a hard cutoff. Older servers keep getting security patches while you plan the move.

PHP 8.5

Modern stacks

Compatible with PHP up to 8.5, MySQL 8.x and current MariaDB releases. Deprecations are fixed as they're reported.

MySQL & MariaDB notes →
PHP 7.1+

Older hosts

Sites on PHP 7.1 through 7.3 are still offered updates through the Joomla Update component. PHP 7.0 and below is not supported. Moving from 5.6 or 7.x to 7.4 is typically a safe switch — just check your extensions and templates aren't holding you back.

CentOS 7?

Stuck servers

A server hosting Joomla sites on PHP older than 7.2 may be stuck on CentOS 7/cPanel, no longer supported by either vendor. Switching to this distribution takes you closer to upgrading — e.g. AlmaLinux 8 with cPanel, or Ubuntu 22.04+ with Ondřej's PHP repos.

// security

Security fixes, backported as they land

Every official Joomla security release is reviewed against this codebase. When the vulnerable code exists in 3.x, it gets fixed here — including issues listed upstream as affecting only Joomla 4.0 and later.

Detailed changelog →
v3.16Guest account creation via the frontend profile-save action, even with user registration disabledJoomla 6.1 / 5.4
v3.16Arbitrary directory deletion through a path traversal in the file cache's group handlingJoomla 6.1 / 5.4
v3.16Two XSS-filter bypasses using HTML5 entities and unterminated numeric referencesJoomla 6.1 / 5.4
v3.16SSRF: feed, SEF-domain, user-profile website and custom update URL fields restricted to web URL schemesJoomla 6.1 / 5.4
v3.15Local file inclusion (LFI) via the view layout parameterCVE-2026-40383
v3.15SQL injection in the com_tags "all tags" list orderingCVE-2026-352212
v3.16Tagged items in access-restricted categories leaking through tag views and the "Tags - Popular"/"Tags - Similar" modulesJoomla 6.1 / 5.4
v3.16HTTP header injection via an unescaped filename in the banner-tracking download and the contact vCard exportJoomla 6.1 / 5.4
v3.16XSS gaps in JHtml::link()/JHtml::iframe(), the module manager's position column, the toolbar link button and the generic image layout's attribute namesJoomla 6.1 / 5.4
v3.16Stored XSS: contact name/position/category echoed unescaped into public-facing schema.org markupJoomla 6.1 / 5.4
v3.16Missing per-item edit-permission checks in the category and custom-field batch-copy actionsJoomla 6.1 / 5.4
v3.16A missing access check on the second record of a content history comparisonJoomla 6.1 / 5.4
v3.16A missing SHTML file extension in the Template Manager's upload blacklistJoomla 6.1 / 5.4
v3.15Privilege-escalation XSS via language overrides by non-Super-Users with delegated translation accessCVE-2026-48954
v3.15XSS in the template manager's file/image/font editor — three code paths fixed where the official fix covered oneCVE-2026-48950
v3.15Unescaped attribute output in the generic image layout used by extensionsCVE-2026-48953
v3.15Reflected XSS in the com_installer update list viewCVE-2026-48952
v3.15Stored XSS in the content history preview screenCVE-2026-30894
v3.15Password/username reset links sent over plain HTTP even on HTTPS-only sitesCVE-2026-48902
v3.15Access-control bypass allowing anyone to download restricted contacts' vCards in com_contactCVE-2026-48948

New in v3.16 — Little WAF. An opt-in system plugin that filters known attack signatures against abandoned or historically vulnerable third-party extensions before any component runs. Ships with filters for Sourcerer-style {source} URL injection and, as a precaution, Modules Anywhere-style {module}/{modulepos} tags. Disabled by default; more filters will be added over time.

Advisories that don't apply — because the vulnerable feature doesn't exist in 3.x — and issues already covered by earlier hardening are documented in the changelog as well.

// changelog

What's been happening

All releases →
v3.16October 3, 2026
latest

Little WAF, a smarter Joomla Update, and a big deprecation sweep

  • Security fixes backported from the Joomla 6.1.3/5.4.8 and 6.1.4/5.4.9 security releases, each confirmed against this codebase, plus related hardening.
  • New "Little WAF" opt-in system plugin that filters known attack patterns against vulnerable third-party extensions.
  • Joomla Update no longer brings back removable core extensions you've uninstalled — and a new "Restore uninstalled core extensions" option brings them back on request, with their tables, menu items and default settings.
  • Minimum database versions raised to MySQL 5.5.3, MariaDB 5.5 and PostgreSQL 9.0. The update channel now accepts any Joomla 3.x installation, with migrations going back to Joomla 2.5.0.
  • Removed cache/session drivers that can't work on PHP 7.1+ (APC, Memcache, XCache, Cache_Lite) and the legacy mysql driver. Memcached is no longer "Experimental" after fixing its locking bugs.
  • Fixed updates failing on sites that uninstalled Banners, Contacts, News Feeds or Smart Search, stale caches on Redis/Memcached/APCu/WinCache, and PHP 8.1–8.5 deprecation warnings across an 805-file sweep.
v3.15July 18, 2026

13 CVE backports, module caching that finally respects your settings

  • Modules set to "Use Global" caching (mod_menu and 25 others) no longer ignore Global Configuration's Cache Time in favour of a near-fixed 15-minute refresh. Fixed automatically on upgrade.
  • New explicit "Use custom cache time" option on all 26 cache-capable core modules — including mod_whosonline, which supports caching for the first time.
  • "Sort by Author" in Extensions → Manage, to separate third-party extensions from core when auditing large sites.
  • Minimum-PHP check raised from a stale 5.3.10 to 7.1.0, and the update feed lowered to match — PHP 7.1–7.3 sites keep receiving patches.
  • Fixed stale beez3/hathor database entries (#7), a PHP 8.4 lcg_value() deprecation (#12), literal "_QQ_" text across 80 language files, and a misleading "Refresh Manifest Cache failed" warning.
v3.14July 4, 2026

PHP 8.5 deprecation fixes

  • Fixed null array offsets in HtmlDocument::getBuffer()/setBuffer() and the deprecated imagedestroy() call (via PR #13).
  • Language file versioning now in line with the main version.
v3.13May 31, 2026

A tidier Isis admin

  • The Isis administrator template now uses CSS view transitions, with all obsolete CSS removed.
  • Further PHP 8.x compatibility fixes, and a fix for the database version mismatch under Extensions → Manage → Database.
v3.12May 21, 2026

Built-in update server

  • Sites on 3.12+ receive updates directly via the Joomla backend updater.
  • Removed legacy bundled items: eos310 & phpversioncheck quickicon plugins, beez3 and hathor templates (defaults fall back to protostar and isis).
  • Additional security patches backported from Joomla 4/5/6.
v3.11April 20, 2026

PHP 8.5 and the first CVE backports

  • Compatible with PHP up to 8.5, and works better with MySQL 8.x.
  • Security patches for CVEs reported after Joomla 3.10.20 eLTS was released.
// database

Database support

Database support in Joomla 3.x was always centred on MySQL/MariaDB. PostgreSQL and SQL Server work with the core, but several core and third-party extensions only ship MySQL/MariaDB database scripts, so expect rough edges there.

DatabaseMinimumStatus
MySQL5.5.3Tested and actively supported (5.7 or newer recommended)
MariaDB5.5Tested and actively supported
PostgreSQL9.0Inherited from stock Joomla 3.x, not tested by this project
SQL Server / Azure SQL2008 R2Inherited from stock Joomla 3.x, not tested by this project

The installer enforces these minimums. Once a site runs 3.16 or newer, it won't be offered further updates while its database is below them, and sees a notice in Joomla Update instead.

Notes on MySQL 8.x

For Joomla 3.x to work flawlessly with MySQL 8.0 or newer, enable native password authentication in my.cnf. Use one or the other, not both. These settings don't apply to MariaDB.

my.cnf · MySQL 8.0 only
default_authentication_plugin = mysql_native_password
my.cnf · MySQL 8.4+
mysql_native_password         = ON
authentication_policy         = mysql_native_password

Recommended for maximum compatibility in both MySQL and MariaDB:

my.cnf · MySQL & MariaDB
sql_mode = ""
// extensions

Your extensions keep working

Templates and extensions built for Joomla 3.x run unchanged. A directory of actively maintained, tested-compatible extensions is planned.

placeholder content
extension screenshot · 16:9
DeveloperContent

Extension name

One-line description of what the extension does and which UTD version it was last tested on.

extension screenshot · 16:9
DeveloperTemplate

Template name

One-line description of what the template does and which UTD version it was last tested on.

extension screenshot · 16:9
DeveloperSecurity

Extension name

One-line description of what the extension does and which UTD version it was last tested on.

Extension developers: ensure your extension update XML files don't stop at Joomla 3.10.x. Do your users a favour ;)

Get listed →
// by the numbers

Momentum, measured

Six releases since April. Every one of them shipped security work.

805
files swept for PHP 8.1–8.5 deprecations in v3.16
Minimum PHP7.1
Recommended PHP7.4+
Compatible up toPHP 8.5
Compatibility →
6
releases in 2026
v3.16Oct 3
v3.15Jul 18
v3.14Jul 4
v3.13May 31
v3.12May 21
v3.11Apr 20
The changelog →
23
stars on GitHub
Watchers8
Forks1
Open issues4
The repo →
// voices

From the people running it

Site owners, agencies and hosts on moving their Joomla 3.x sites to UTD.

placeholder content
IMGName SurnameAgency · 40 client sites

Testimonial from an agency about upgrading client sites in place, and what it saved compared to a full migration.

IMGName SurnameHosting provider

Testimonial from a hosting company about finally retiring old PHP versions and servers across their fleet.

IMGName SurnameSite owner

Short testimonial from a small site owner on how simple the backend update was.

// long-term plan · a different project

A leaner fork is on the way

A new fork based on Joomla 3.x is a work in progress — but very, very active. When released, it will feature:

01 · core

Stripped down

Joomla 3.x with all non-essential extensions removed.

02 · php

PHP 7.4 → 8.x

Fully compatible with PHP versions from 7.4 to 8.x and so on.

03 · database

Latest MySQL & MariaDB

Fully compatible with the latest versions of both.

04 · content

K2 for content

com_content and anything related is removed entirely, decoupling content features from a solid CMS base that keeps true backwards compatibility with past releases of the fork.

05 · admin

Admin refresh

A refreshed administrator experience.

06 · js

Modern JS only

Gradual jQuery/MooTools removal.

07 · future

Built to last

Gradual codebase modernization to support future PHP & MySQL/MariaDB versions without much effort.