News
- Details
- Written by: Bjørn Ove Bremnes
- Parent Category: News
- Category: News - Security News
BCLog has been presented as a free Joomla administrator audit tool, but the available evidence does not independently confirm its current version, licence, compatibility, installation process or feature set. For Joomla teams, the useful takeaway is broader: an audit log can strengthen operational visibility when it is deployed, reviewed and protected as one part of a layered security programme.
Read more: BCLog Audit Tool Availability: What Joomla Administrators Should Know
- Details
- Written by: Bjørn Ove Bremnes
- Parent Category: News
- Category: News - Security News
A reproducible Joomla extension development environment gives every contributor the same starting point: the same application services, project layout and repeatable local workflow. This practical guide shows how to combine VS Code devcontainers and Docker for isolated Joomla extension work while keeping databases, secrets and deployment artefacts under control.
Read more: Reproducible Joomla Extension Development with VS Code Devcontainers and Docker
- Details
- Written by: Bjørn Ove Bremnes
- Parent Category: News
- Category: News - Security News
This Joomla technical guide explains how to investigate two confusing Joomla 3.x PDF upload messages: Invalid file: The file contains PHP code and Upload Failed: No data. The errors commonly point to file-validation, PHP, server, temporary-directory, or security-filtering issues, and they do not by themselves establish that a site has been compromised.
Read more: Fix PDF Upload Errors in Joomla 3.x: PHP Code and No Data
- Details
- Written by: Bjørn Ove Bremnes
- Parent Category: News
- Category: News - Security News
CVE-2026-48939 is a critical iCagenda file-upload vulnerability that can result in PHP code execution on affected Joomla sites. Administrators should upgrade the extension immediately, then investigate for signs of unauthorised uploads or execution because the flaw is listed in CISA’s Known Exploited Vulnerabilities catalog.
Read more: Critical iCagenda File Upload RCE: Patch CVE-2026-48939 Now