
Joomla 5.4.7 and 6.1.2 Security Update Checklist
Use this backup-first Joomla security update checklist to move supported sites to 5.4.7 or 6.1.2, test core workflows, and review extensions separately.

Use this backup-first Joomla security update checklist to move supported sites to 5.4.7 or 6.1.2, test core workflows, and review extensions separately.

Review Twill CMS CVE-2026-15518 with a backup-first Laravel CMS checklist for package versions, media uploads, storage review, and staged updates.

TYPO3 published a High severity Form Framework access-control fix for CVE-2026-11607. Back up, update, restrict form-editing rights, and verify forms.

Drupal.org published July 8 contributed-project advisories including critical unsupported modules and a Location Selector SQL injection fix.

Patch Drupal Tealium iQ Tag Management CVE-2026-13244 and Geolocation Field CVE-2026-13242. Check affected versions, backups, permissions, views, and post-update logs.

CISA added Joomla Content Editor CVE-2026-48907 to KEV. Update JCE Pro to 2.9.99.6 or later, apply the vendor patch package for older sites, and review Joomla for cleanup.

Ghost CMS CVE-2026-26980 is fixed in 6.19.1. Patch Ghost, rotate Admin API credentials, inspect content, and treat WAF coverage as temporary mitigation.

Patch Grav CMS critical and high-severity advisories affecting core, Login, API, and Form components. Safe checklist for website owners and hosting providers.