Joom Donation 7.6 Released - Important Security Update
please update
Key Security Improvements in Joom Donation 7.6- Improved protection against SQL injection
This release fixes an unauthenticated blind SQL injection issue in data validation. Input data is now handled more securely before being processed by the system. - Stronger file upload restrictions
File upload handling has been improved with stricter checks and validation to help prevent unsafe or unauthorized files from being uploaded through frontend forms or user-accessible areas. - Protection against reflected XSS
The donation form has been improved to reduce the risk of reflected Cross-Site Scripting (XSS). User-submitted data is now filtered and escaped more carefully before being displayed. - Improved Invoice Download Access Control
This release fixes an IDOR (Insecure Direct Object Reference) issue in invoice download. Additional access checks have been added to help ensure users can only download invoices they are authorized to access.
Additional Security-Related Enhancements
- Input filtering - User input is checked, cleaned, and validated more carefully before being processed.
- Payment IPN / callback validation - Payment notification and callback requests are validated more strictly to help ensure they come from trusted payment sources.
- Currency checking - Currency data is checked more carefully to help prevent invalid, unexpected, or manipulated payment values.
Joomla 3 Security Fix Availability
For customers who are still using Joom Donation on Joomla 3, we also provide a security-fixed version for Joomla 3 in specific cases.
Customers with a valid subscription, or customers whose subscription expired in 2026, can create a support ticket in the Joom Donation category. Our team will then provide the Joom Donation version for Joomla 3 that includes fixes for these security issues.
Reacted by: