Joomla 3.8.8 is now available. This is a security release which addresses 9 security vulnerabilities, contains over 50 bug fixes, and includes various security related improvements.
What's in 3.8.8?
Joomla 3.8.8 addresses 9 security vulnerabilities / hardenings and several bugs, including:
Security Issues Fixed
- Low Priority - Core - ACL violation in access levels (affecting Joomla 2.5.0 through 3.8.7) More information »
- Low Priority - Core - Add phar files to the upload blacklist (affecting Joomla 2.5.0 through 3.8.7) More information »
- Moderate Priority - Core - Information Disclosure about unpublished tags (affecting Joomla 3.1.0 through 3.8.7) More information »
- Low Priority - Core - Installer leaks plain text password to local user (affecting Joomla 3.0.0 through 3.8.7) More information »
- Moderate Priority - Core - XSS Vulnerabilities & additional hardening (affecting Joomla 3.0.0 through 3.8.7) More information »
- Low Priority - Core - Filter field in com_fields allows remote code execution (affecting Joomla 3.7.0 through 3.8.7) More information »
- Low Priority - Core - Session deletion race condition (affecting Joomla 3.0.0 through 3.8.7) More information »
- Low Priority - Core - Possible XSS attack in the redirect method (affecting Joomla 3.2.1 through 3.8.7) More information »
- Low Priority - Core - XSS vulnerability in the media manager (affecting Joomla 1.5.0 through 3.8.7) More information »
Please see the documentation wiki for the security recommendations for updated sites.
More details about the session deletion race condition are available on the Developer Network site.
Bug fixes and Improvements
- Miscellaneous accessibility improvements for the Backend
- Updated CodeMirror to 5.37 and various improvements #20269 #19833 #12542
- Improved handling of numeric user group names #20091
- [com_content] Filter by no author #20245
- Added support for PHP 7.3’s
is_countable
function #20441 - Sending passwords by email disabled by default for new installs #20247
Visit GitHub for the full list of bug fixes.
Download
New Installations
Download Joomla 3.8.8English (UK), 3.8.8 Full Package
Upgrade Packages
Upgrade PackagesJoomla 3 upgrade packages
Note: Please read the update instructions before updating.
Please remember to backup your site before updating and to clear your site, administrator and browser cache after updating.
If you find a bug in Joomla please report it on the Joomla! Issue Tracker.
Please see the documentation wiki for FAQs regarding the 3.8.8 release.
A Huge Thank You to Our Volunteers!
A big thank you goes out to everyone that contributed to the 3.8 releases!
Make the next Joomla release even better
Joomla 3.9, 3.10 and 4.0 are in the works. If you would like to help improve them you can make a direct difference! You can find more information about these releases on GitHub:
- Joomla 3.9 milestone: https://github.com/joomla/joomla-cms/milestone/20
- Joomla 3.10 milestone: https://github.com/joomla/joomla-cms/milestone/34
- Joomla 4.0 milestone: https://github.com/joomla/joomla-cms/milestone/5
We invite you to download these upcoming releases on the nightly build page (for testing purposes only - do not use on production sites).
Join the Joomla Volunteer Community and contribute your skills and time to help Joomla grow even more:
- Become a tester - no special skills required, but able to install test releases, and follow reporting instructions
- Help us translate - for those who speak English and any other language
- Document new features - for those who can write tutorials and technical documentation
- Other areas - find one that fits your skills and interests.
Stay updated on the latest project news and important announcements by subscribing to the Joomla Newsletter as well as the Developer Newsletter.
Spread the Joomla Love
Has Joomla helped you do your job better, saved you money, allowed you to do more with your website? You can help others experience the same results and find out about this great Open Source Content Management System by telling others.
Share the news!
Don't forget to visit the Joomla 3.8 Landing Page to get an overview of the new features, download our wide range of imagery available for sharing in blog posts, via social media, or in banners on your site. They can be found on the Joomla 3.8 Imagery page. And if you want to translate them, you can find the source files here.
We would love you to spread the Joomla love and get the word out to your network.
Are you a journalist, blogger or evangelist?
Please feel free to get in touch with the This email address is being protected from spambots. You need JavaScript enabled to view it. for interviews and other content.