Joomla! 3.8.8 is now available and it's a security release. Since few security issues and bugs have been resolved, we're considering this a security fix and we recommend all Joomla website owners have this upgrade done.
This is a security release which addresses 9 security vulnerabilities, contains over 50 bug fixes, and includes various security related improvements.
Joomla! 3.8.8 Release (joomla.org)
What's in Joomla! 3.8.8?
Security Issues Fixed:
- Low Priority - Core - ACL violation in access levels (affecting Joomla 2.5.0 through 3.8.7)
- Low Priority - Core - Add phar files to the upload blacklist (affecting Joomla 2.5.0 through 3.8.7)
- Moderate Priority - Core - Information Disclosure about unpublished tags (affecting Joomla 3.1.0 through 3.8.7)
- Low Priority - Core - Installer leaks plain text password to local user (affecting Joomla 3.0.0 through 3.8.7)
- Moderate Priority - Core - XSS Vulnerabilities & additional hardening (affecting Joomla 3.0.0 through 3.8.7)
- Low Priority - Core - Filter field in com_fields allows remote code execution (affecting Joomla 3.7.0 through 3.8.7)
- Low Priority - Core - Session deletion race condition (affecting Joomla 3.0.0 through 3.8.7)
- Low Priority - Core - Possible XSS attack in the redirect method (affecting Joomla 3.2.1 through 3.8.7)
- Low Priority - Core - XSS vulnerability in the media manager (affecting Joomla 1.5.0 through 3.8.7)
Bug fixes and Improvements:
- Miscellaneous accessibility improvements for the Backend
- Updated CodeMirror to 5.37 and various improvements
- Improved handling of numeric user group names
- [com_content] Filter by no author
- Added support for PHP 7.3's is_countable function
- Sending passwords by email disabled by default for new installs
The previous release was on April 19, 2018.
Our Website Maintenance Department will be in contact with our clients regarding this upgrade. If you need this upgrade done on your website, please contact us.
Thank you,
-Tony