Joomla 3.x UTD: secure, current & still yours kept up to date by the community
An up-to-date distribution of Joomla 3.x. Backported security fixes, PHP up to 8.5, current MySQL & MariaDB — and a drop-in upgrade for the sites you already run.
According to market share estimates (as of May 2026), Joomla 3.x is currently used on more than 50% of all installed Joomla sites worldwide. However, official support for Joomla 3.x ended in February 2025 (counting the eLTS program).
So we're actively developing Joomla 3.x UTD as an up-to-date distribution of the Joomla 3.x content management system, built to ensure code security, support modern PHP & MySQL/MariaDB versions & fix any broken behaviour that never got sorted before the release of newer major versions of Joomla.
“
A short statement from the maintainers about why Joomla 3.x deserves to stay alive, and who this distribution is for.
IMGMaintainer nameRole, JoomlaWorksplaceholder
// install
Upgrade in place. Or start fresh.
One rolling release, one download path that never changes. Point your backend at our update feed, or extract on top of an existing Joomla 3.x site.
Sites on PHP 7.1 through 7.3 are still offered updates through the Joomla Update component. PHP 7.0 and below is not supported. Moving from 5.6 or 7.x to 7.4 is typically a safe switch — just check your extensions and templates aren't holding you back.
CentOS 7?
Stuck servers
A server hosting Joomla sites on PHP older than 7.2 may be stuck on CentOS 7/cPanel, no longer supported by either vendor. Switching to this distribution takes you closer to upgrading — e.g. AlmaLinux 8 with cPanel, or Ubuntu 22.04+ with Ondřej's PHP repos.
// security
Security fixes, backported as they land
Every official Joomla security release is reviewed against this codebase. When the vulnerable code exists in 3.x, it gets fixed here — including issues listed upstream as affecting only Joomla 4.0 and later.
v3.16Guest account creation via the frontend profile-save action, even with user registration disabledJoomla 6.1 / 5.4
v3.16Arbitrary directory deletion through a path traversal in the file cache's group handlingJoomla 6.1 / 5.4
v3.16Two XSS-filter bypasses using HTML5 entities and unterminated numeric referencesJoomla 6.1 / 5.4
v3.16SSRF: feed, SEF-domain, user-profile website and custom update URL fields restricted to web URL schemesJoomla 6.1 / 5.4
v3.15Local file inclusion (LFI) via the view layout parameterCVE-2026-40383
v3.15SQL injection in the com_tags "all tags" list orderingCVE-2026-352212
v3.16Tagged items in access-restricted categories leaking through tag views and the "Tags - Popular"/"Tags - Similar" modulesJoomla 6.1 / 5.4
v3.16HTTP header injection via an unescaped filename in the banner-tracking download and the contact vCard exportJoomla 6.1 / 5.4
v3.16XSS gaps in JHtml::link()/JHtml::iframe(), the module manager's position column, the toolbar link button and the generic image layout's attribute namesJoomla 6.1 / 5.4
v3.16Missing per-item edit-permission checks in the category and custom-field batch-copy actionsJoomla 6.1 / 5.4
v3.16A missing access check on the second record of a content history comparisonJoomla 6.1 / 5.4
v3.16A missing SHTML file extension in the Template Manager's upload blacklistJoomla 6.1 / 5.4
v3.15Privilege-escalation XSS via language overrides by non-Super-Users with delegated translation accessCVE-2026-48954
v3.15XSS in the template manager's file/image/font editor — three code paths fixed where the official fix covered oneCVE-2026-48950
v3.15Unescaped attribute output in the generic image layout used by extensionsCVE-2026-48953
v3.15Reflected XSS in the com_installer update list viewCVE-2026-48952
v3.15Stored XSS in the content history preview screenCVE-2026-30894
v3.15Password/username reset links sent over plain HTTP even on HTTPS-only sitesCVE-2026-48902
v3.15Access-control bypass allowing anyone to download restricted contacts' vCards in com_contactCVE-2026-48948
New in v3.16 — Little WAF. An opt-in system plugin that filters known attack signatures against abandoned or historically vulnerable third-party extensions before any component runs. Ships with filters for Sourcerer-style {source} URL injection and, as a precaution, Modules Anywhere-style {module}/{modulepos} tags. Disabled by default; more filters will be added over time.
Advisories that don't apply — because the vulnerable feature doesn't exist in 3.x — and issues already covered by earlier hardening are documented in the changelog as well.
Little WAF, a smarter Joomla Update, and a big deprecation sweep
Security fixes backported from the Joomla 6.1.3/5.4.8 and 6.1.4/5.4.9 security releases, each confirmed against this codebase, plus related hardening.
New "Little WAF" opt-in system plugin that filters known attack patterns against vulnerable third-party extensions.
Joomla Update no longer brings back removable core extensions you've uninstalled — and a new "Restore uninstalled core extensions" option brings them back on request, with their tables, menu items and default settings.
Minimum database versions raised to MySQL 5.5.3, MariaDB 5.5 and PostgreSQL 9.0. The update channel now accepts any Joomla 3.x installation, with migrations going back to Joomla 2.5.0.
Removed cache/session drivers that can't work on PHP 7.1+ (APC, Memcache, XCache, Cache_Lite) and the legacy mysql driver. Memcached is no longer "Experimental" after fixing its locking bugs.
Fixed updates failing on sites that uninstalled Banners, Contacts, News Feeds or Smart Search, stale caches on Redis/Memcached/APCu/WinCache, and PHP 8.1–8.5 deprecation warnings across an 805-file sweep.
v3.15July 18, 2026
13 CVE backports, module caching that finally respects your settings
Modules set to "Use Global" caching (mod_menu and 25 others) no longer ignore Global Configuration's Cache Time in favour of a near-fixed 15-minute refresh. Fixed automatically on upgrade.
New explicit "Use custom cache time" option on all 26 cache-capable core modules — including mod_whosonline, which supports caching for the first time.
"Sort by Author" in Extensions → Manage, to separate third-party extensions from core when auditing large sites.
Minimum-PHP check raised from a stale 5.3.10 to 7.1.0, and the update feed lowered to match — PHP 7.1–7.3 sites keep receiving patches.
Fixed stale beez3/hathor database entries (#7), a PHP 8.4 lcg_value() deprecation (#12), literal "_QQ_" text across 80 language files, and a misleading "Refresh Manifest Cache failed" warning.
v3.14July 4, 2026
PHP 8.5 deprecation fixes
Fixed null array offsets in HtmlDocument::getBuffer()/setBuffer() and the deprecated imagedestroy() call (via PR #13).
Language file versioning now in line with the main version.
v3.13May 31, 2026
A tidier Isis admin
The Isis administrator template now uses CSS view transitions, with all obsolete CSS removed.
Further PHP 8.x compatibility fixes, and a fix for the database version mismatch under Extensions → Manage → Database.
v3.12May 21, 2026
Built-in update server
Sites on 3.12+ receive updates directly via the Joomla backend updater.
Removed legacy bundled items: eos310 & phpversioncheck quickicon plugins, beez3 and hathor templates (defaults fall back to protostar and isis).
Additional security patches backported from Joomla 4/5/6.
v3.11April 20, 2026
PHP 8.5 and the first CVE backports
Compatible with PHP up to 8.5, and works better with MySQL 8.x.
Security patches for CVEs reported after Joomla 3.10.20 eLTS was released.
// database
Database support
Database support in Joomla 3.x was always centred on MySQL/MariaDB. PostgreSQL and SQL Server work with the core, but several core and third-party extensions only ship MySQL/MariaDB database scripts, so expect rough edges there.
Database
Minimum
Status
MySQL
5.5.3
Tested and actively supported (5.7 or newer recommended)
MariaDB
5.5
Tested and actively supported
PostgreSQL
9.0
Inherited from stock Joomla 3.x, not tested by this project
SQL Server / Azure SQL
2008 R2
Inherited from stock Joomla 3.x, not tested by this project
The installer enforces these minimums. Once a site runs 3.16 or newer, it won't be offered further updates while its database is below them, and sees a notice in Joomla Update instead.
Notes on MySQL 8.x
For Joomla 3.x to work flawlessly with MySQL 8.0 or newer, enable native password authentication in my.cnf. Use one or the other, not both. These settings don't apply to MariaDB.
Site owners, agencies and hosts on moving their Joomla 3.x sites to UTD.
placeholder content
IMGName SurnameAgency · 40 client sites
Testimonial from an agency about upgrading client sites in place, and what it saved compared to a full migration.
IMGName SurnameHosting provider
Testimonial from a hosting company about finally retiring old PHP versions and servers across their fleet.
IMGName SurnameSite owner
Short testimonial from a small site owner on how simple the backend update was.
// long-term plan · a different project
A leaner fork is on the way
A new fork based on Joomla 3.x is a work in progress — but very, very active. When released, it will feature:
01 · core
Stripped down
Joomla 3.x with all non-essential extensions removed.
02 · php
PHP 7.4 → 8.x
Fully compatible with PHP versions from 7.4 to 8.x and so on.
03 · database
Latest MySQL & MariaDB
Fully compatible with the latest versions of both.
04 · content
K2 for content
com_content and anything related is removed entirely, decoupling content features from a solid CMS base that keeps true backwards compatibility with past releases of the fork.
05 · admin
Admin refresh
A refreshed administrator experience.
06 · js
Modern JS only
Gradual jQuery/MooTools removal.
07 · future
Built to last
Gradual codebase modernization to support future PHP & MySQL/MariaDB versions without much effort.
// community
Get involved
This is a community effort. Report bugs, contribute fixes, or ask the codebase directly.