Web Design

Joomla 5 Stops Getting Bug Fixes October 13, the Day Joomla 6.2 Ships

Joomla 5 support timeline: regular bug fixes for the Joomla 5.4 series end on October 13, 2026, the planned release date of Joomla 6.2, and security fixes continue until October 12, 2027, while Joomla 6 requires PHP 8.3 or later and asks site owners to check every extension and template before upgrading.

Regular Joomla 5 support ends on October 13, 2026, the day Joomla 6.2.0 is scheduled for release, according to the Joomla roadmap. After that date the 5.4 series gets security fixes only, and those stop on October 12, 2027.

For associations, schools and small nonprofits still on Joomla, this is a planning question, not an emergency. This piece covers the Joomla 5 support dates alongside Joomla 4 and 6, what "security only" means in practice, what Joomla 6 requires and removes, and a planning checklist for small teams. Every date and version here comes from Joomla’s own pages, read on September 27, 2026.

The short version: nothing breaks on October 13. Your Joomla 5 site keeps running and keeps getting security patches for another year. What you lose is fixes for ordinary bugs. The deadline that matters is October 12, 2027, and the work between now and then is mostly extension checks and a PHP upgrade on the host. Start with a staging copy this quarter, not next summer.

What changes for Joomla 5 support on October 13

The roadmap lists three dates for the 5.x series. Joomla 5 was released on October 17, 2023. Regular bugfix support ends October 13, 2026. Security-fix-only support ends October 12, 2027.

The August release announcement states the Joomla 5 support dates in plainer terms. The project will support Joomla 5.4.x with bugfix patches until October 13, 2026 and with security patches until October 12, 2027. The page offers those dates as its answer to whether you need to upgrade right away. A year of security coverage is a real runway.

The dates are not arbitrary. Joomla’s software release cycle plans a major version every two years, in October of odd-numbered years. Minor releases come every six months. The fourth minor release (x.4) is a bridge release with no new features. After x.4.0 ships, the project fixes bugs for one year and security issues for two.

Joomla 5.4.0 shipped on October 14, 2025, alongside Joomla 6.0. One year on is October 2026. Two years on is October 2027.

As of September 27, the roadmap listed 5.4.9 and 6.1.4 as the next patch releases, planned for September 29. It did not list a 5.4 release for October 13. Check the roadmap for the current state before you plan around a specific patch number.

The support timeline for Joomla 4, 5 and 6

Here is where each series stands, taken from the roadmap and Joomla’s release announcements.

Series Bug fixes end Security fixes end Status on October 13, 2026
Joomla 4.x (4.4) October 14, 2024 October 14, 2025 End of life
Joomla 5.x (5.4) October 13, 2026 October 12, 2027 Security fixes only
Joomla 6.x October 17, 2028 October 16, 2029 Full support

The Joomla 4 dates come from two announcements. The Joomla 5.2.0 and 4.4.9 release on October 14, 2024 said 4.4.9 marked the end of bug fix updates for 4.4. The Joomla 5.3.4 release on September 30, 2025 said 4.4 would get security patches until October 14, 2025.

The roadmap does not list a Joomla 7 date yet. The release cycle policy points to October 2027 for the next major. The developer manual already has a "6.4 to 7.0" upgrade notes section. Treat October 2027 as the plan, not a promise.

That timing matters. Joomla 5 support ends entirely in the same month the next major is expected. A site still on Joomla 5 at that point would be unsupported, with two major versions to cross.

What security-only Joomla 5 support means in practice

Security-only support is narrower than it sounds. Joomla will keep shipping 5.4.x patch releases while security issues come in. Those releases fix vulnerabilities. They do not fix a broken editor button, a date field that saves the wrong value or an admin screen that throws a warning.

Three practical effects follow.

  • Bugs you hit stay with you. If a bug in core affects your site after October 13, the fix will land in 6.x, not 5.4.
  • Your PHP version will age out. Joomla 5 runs on PHP 8.1 or later. The PHP project lists 8.1 as end of life, and its supported versions page shows 8.2 security support ending December 31, 2026. Joomla 6 needs 8.3.
  • Extension vendors set their own schedules. The Joomla project controls core only. A form, membership or events extension may stop shipping Joomla 5 updates before core does. Check each vendor’s policy.

Security-only Joomla 5 support is a runway, not a place to park. It buys time to test, not a reason to wait.

Joomla 4 shows what happens after security support ends

The best evidence of what end of life means is sitting in Joomla’s own security advisories. Joomla’s security announcements page lists ten core advisories from the August 18 release. Eight of them name affected versions that reach back to Joomla 4 or earlier.

The fixed versions are 5.4.8 and 6.1.3. There is no 4.4 fix. Joomla 4 support ended in October 2025, so the flaws were patched only in supported branches.

That is the pattern to plan against. When Joomla 5 support ends on October 12, 2027, the series lands where Joomla 4 is today. Any vulnerability reported after that date is likely to be fixed only in Joomla 6 or later.

Joomla 4 sites are exposed to the August advisories. The MFA bypass and seven other flaws fixed in August list Joomla 4.0.0 onward as affected, with fixes only in 5.4.8 and 6.1.3. A Joomla 4 site cannot be patched for them. Move it to Joomla 5.4 first, then plan the step to Joomla 6.

The August release: ten fixes and an MFA bypass

The Joomla 6.1.3 and 5.4.8 release came out on August 18, 2026 and fixed ten security issues. Half involve access control checks, three of them on web service endpoints. Others cover CORS origin checks, cross-site scripting in schema.org output, header injection in download views and uploads of SHTML files.

The one to note is advisory 20260807, an MFA authentication bypass. Joomla’s advisory rates impact High and severity Moderate. It describes insufficient state checks that let an attacker get past two-factor checks. The CVE is CVE-2026-73337. Affected versions are 4.0.0 through 5.4.7 and 6.0.0 through 6.1.2.

For small organizations, MFA is often the main control on admin accounts. If you turned it on after reading our guide to multi-factor authentication, this is the patch that keeps it doing its job. Joomla 5 support still covers you here: update to 5.4.8 or later now, before any upgrade planning.

What Joomla 6 requires: PHP and database versions

The Joomla 6 technical requirements raise the PHP floor. The 5.4 requirements page lists different numbers. Here are the two side by side.

Component Joomla 5.x Joomla 6.x
PHP 8.1.0 minimum, 8.3 recommended 8.3.0 minimum, 8.4 recommended
MySQL 8.0.13 minimum 8.0.13 minimum, 8.4 recommended
MariaDB 10.4.0 minimum 10.6 supported, 10.4 minimum
PostgreSQL 12.0 minimum 14.0 supported, 12.0 minimum

The PHP change is the one most likely to need your host. Check which version your hosting account runs today. Joomla 6 needs PHP 8.3 or later.

The database column needs a note. Joomla’s manual lists a "supported" version and a lower "minimum" for MariaDB and PostgreSQL. It says versions below the supported line are not officially supported by maintainers. Joomla’s own step-by-step upgrade guide lists MariaDB 10.6 and PostgreSQL 14.0 as the requirements. Plan to the supported numbers.

Web servers change little. Apache 2.4 and IIS 10 stay the same. Nginx moves to 1.26 supported. Required PHP modules are unchanged: json, simplexml, dom, zlib, gd and a MySQL or PostgreSQL driver.

If your team also maintains custom PHP code, our look at what PHP 8.6 deprecates covers the next round of language changes.

What Joomla 6 removes, and how the compatibility plugins work

Joomla calls the move from 5.4 to 6 "an upgrade, not a migration." The core data and structure carry over. Extensions are where the work sits.

The removed and backward incompatibility notes list roughly 30 changes. The ones most likely to affect older extensions:

  • CMSObject is gone from core. Model items now come back as plain PHP objects, so code that calls get() and set() on them breaks.
  • The CMS Input class is removed. Extensions must use the framework Input class instead.
  • The CMS Filesystem package moved. It now lives in the Backward Compatibility 6 plugin and is deprecated.
  • Legacy application classes are removed. The CMS BaseApplication and CliApplication classes are gone, and the JPATH_PLATFORM constant is no longer defined.
  • Table loading changed. Tables are now created directly rather than through Table::getInstance().

Two plugins soften the change. The compatibility plugin notes explain how they work. Joomla 5 has a plugin named Backward Compatibility. Joomla 6 has one named Backward Compatibility 6. Search for either name in the plugin manager.

The Joomla 5 plugin must be disabled before you start the upgrade. If the site breaks when you disable it, re-enable it and fix the errors while still on 5.4. On an upgraded site, the Joomla 6 plugin is enabled. On a fresh Joomla 6 install, it is installed but disabled.

Extension compatibility is the real schedule

Core is the easy part. The August announcement warns that some extensions may not be ready for Joomla 6. It points readers to the Joomla Extensions Directory, which can filter by supported version.

Joomla’s planning and upgrade guide sorts extensions into four groups. Some work on Joomla 6 without help. Some work only with the Backward Compatibility 6 plugin on. Some are broken. Some break the whole site.

The guide also notes a limit of the pre-update check in Joomla Update. That screen shows which extensions report Joomla 6 compatibility. It depends on developers reporting that correctly, so treat it as a first pass.

For association and nonprofit sites, the high-risk extensions are the ones tied to money and members. Check membership, donation, event registration and payment extensions first. A broken payment flow costs more than a broken slideshow. If one has no Joomla 6 release, that answer decides your timeline more than the end of Joomla 5 support does.

What Joomla 6.2 adds on October 13

Joomla 6.2 is a minor release, and most of it is editorial polish. The 6.2 Beta 1 announcement lists secure article previews without a frontend login, a native Read More button, a unified link picker, TinyMCE 8.8.2 and a language fallback chain.

Two items matter for maintenance. Per the beta announcement, the extension installer gains a security flag for updates, and it shows the highest severity among pending updates. Those make it easier to see which updates are security fixes.

The Beta 3 post of September 15 put Release Candidate 1 on September 29 and the stable release on October 13. It also said the beta is not for production. If you move to Joomla 6 now, you will be on 6.1. Under the release policy, 6.1 stops getting support when 6.2 ships, so plan a routine minor update to 6.2 soon after.

An upgrade plan for nonprofits and small agencies

This checklist follows Joomla’s own guide and adds the steps small teams tend to skip.

  1. Patch first. Update every Joomla 5 site to 5.4.8 or later. Joomla 5 support still delivers these fixes, so use them before any planning.

  2. Move Joomla 4 sites to 5.4. Joomla documents the upgrade to 6 from 5.4, which it calls the bridge release. A 4.x site goes to 5.4 first.

  3. Inventory extensions. List everything in Extensions: Manage. Note the vendor, current version and Joomla 6 status for each. Mark anything tied to payments, forms or member data.

  4. Check PHP on the host. Open System Information and read the PHP and database versions. If PHP is below 8.3, ask the host how to switch and whether the plan allows it.

  5. Back up and test the restore. Take a full backup of files and database, then restore it somewhere to prove it works. Our backup strategy basics covers the principle.

  6. Build a staging copy. Run the upgrade on a subdomain or local copy, never production first.

Running the staging upgrade and going live

Once staging exists, the Joomla guide lays out the upgrade itself. These steps continue the list above.

  1. Disable the Joomla 5 compatibility plugin on staging. Fix whatever breaks while still on 5.4.

  2. Turn on debug mode. If the upgrade fails, debug output usually names the extension at fault.

  3. Switch the update channel. In System, Update, Joomla, open Options and set the channel to Joomla Next.

  4. Read the pre-update check. Resolve anything marked as a required setting. Note extensions with unknown status.

  5. Run the upgrade and test the paths that matter. Log in with MFA, submit each form, run a test donation or registration and check the admin screens editors use.

  6. Repeat on production. Take a fresh backup, then upgrade. Turn debug mode off when you finish.

Agencies with many client sites should do one representative site end to end first. The extension list from that site will predict most of the problems on the rest. If your portfolio also includes Drupal, the Drupal 10 end of life on December 9, 2026 lands in the same planning window. For background on the platform itself, see our explainer on what Joomla is.

Frequently Asked Questions

When does Joomla 5 support end?

Regular bug fixes end on October 13, 2026. Security fixes continue until October 12, 2027. After that, Joomla 5 is end of life and gets no patches from the project.

Will my Joomla 5 site stop working on October 13?

No. Nothing changes on the site itself. Joomla 5 support moves to security fixes only, so new bug fixes go to Joomla 6 while security patches keep coming for 5.4 until October 12, 2027.

Is Joomla 4 still supported?

No. Joomla 4.4 got its last bug fixes on October 14, 2024 and security patches until October 14, 2025. The ten advisories fixed in August 2026 were patched only in 5.4.8 and 6.1.3.

What was the Joomla MFA bypass fixed in August?

Advisory 20260807, CVE-2026-73337. Insufficient state checks let an attacker bypass two-factor checks. It affects 4.0.0 through 5.4.7 and 6.0.0 through 6.1.2. The fix is in 5.4.8 and 6.1.3.

What PHP version does Joomla 6 need?

PHP 8.3.0 at minimum, with 8.4 recommended. Joomla 5 runs on 8.1 and later, so many sites need a PHP upgrade on the host before moving to Joomla 6.

Can I upgrade from Joomla 4 straight to Joomla 6?

Joomla documents the upgrade to 6 from Joomla 5.4, which it calls the bridge release. Move a Joomla 4 site to 5.4 first, then upgrade to 6.

Do I need to rebuild my site to move to Joomla 6?

Usually not. Joomla describes the move from 5.4 to 6 as an upgrade, not a migration. The work is checking extensions and templates, and fixing any that use code Joomla 6 removed.

Does Joomla 5 support cover my extensions?

No. Joomla 5 support covers Joomla core only. Each extension vendor sets its own schedule for Joomla 5 updates, so check the vendors behind your forms, payments and membership tools directly.

What does the Backward Compatibility 6 plugin do?

It keeps some older code working on Joomla 6 so extensions written for Joomla 5 can still run. It is enabled on upgraded sites and disabled on new installs. The separate Joomla 5 compatibility plugin must be disabled before you upgrade.

Should I wait for Joomla 6.2 before upgrading?

There is no need. Test on staging now with 6.1. Moving from 6.1 to 6.2 is a routine minor update, and 6.2 is scheduled for October 13, 2026.

When is Joomla 7 expected?

Joomla’s release policy plans a major version every two years in October of odd-numbered years, which points to October 2027. The roadmap does not yet list a Joomla 7 date.

Digital Matters

Web Design Desk