Joomla 4.2.1 Released

Joomla 4.2.1 Released

The Joomla! Project is delighted to announce a security release for 4.x series of Joomla which addresses a security vulnerability and contains various bug fixes and improvements

This release continues Joomla 4's high standards in accessible web design and brings exciting new features, highlighting Joomla's values of inclusiveness, simplicity and security into an even more powerful open-source web platform.

With Joomla 4.2.1, we have new and improved features for bloggers and authors, web designers, extension developers and web agencies.

The highlights are:

Keyboard Shortcuts

With the new keyboard shortcuts, you can save time and become more productive.

There are 9 built into the administrator side of your site such as J + F to jump into the search field or J + S to save

And the great news is that other extensions are able to add their own shortcuts as well. Pressing J + X to get a list of them all. The keystrokes are all sequential, making it more accessible than hitting them simultaneously.

Multi-factor Authentication

Until now, Joomla only offered 'Two-Factor' Authentication; with 'Multi-factor' Authentication, we are taking site access security one step further by allowing you to choose different authentication mechanisms to secure your site. You can choose to use a Yubi-key, Web Authentication, a verification code, or a code by email.

The way Multi-factor Authentication works is that you first log in with your username and password. After that, you are presented with another screen to enter your second authentication method.

This means that you will no longer be able to enter your two-factor authentication code on the same page as the login page.

Security Issues Fixed

[20220801] Low Severity - Low Impact - Multiple Full Path Disclosures because of missing '_JEXEC or die check' (affecting Joomla! 4.2.0)

Bug fixes and Improvements with 4.2.1

  • Failure in setting Redis cache
  • Change the db calls back to the getDbo
  • Error when Gather Statistic enabled in Smart Search
  • Fixed menu login with redirect to menu item on multi-language site
  • Add bcmath_compat polyfill for servers without BCmath / GMP support
  • Remove unused imports in Multi-factor Authentication
  • Fix issue "updateCheck is null"
  • Remove hotkeys.js as they have been renamed
  • Stats collection must not be shown in captive MFA pages
  • CLI application crashed when MVCFactory is used
  • Correctly revert pull request no. 38244 for updating from 4.2.0 RC 1

Visit GitHub for the full list of bug fixes.

Click here for full release information.

It's extremely important to keep your Joomla installation, and extensions up to date to minimise the risk of your site being compromised, you should also check that you are not using vulnerable extensions by visiting Joomla! Vulnerable Extensions List.

Many site owners are totally unaware of the status of their Joomla websites, databases, and hosting environments, the potential risks of being compromised, and the implications of private personal data held. Also many site owners are paying extortionate hosting fees for below standard services running on out of date and insecure hosting environments. 

Can you update our Joomla version and extensions?

Yes, for Joomla version updates order our hourly Joomla Specialist Support and Maintenance service, press the add to cart button, select a minimum of one hour and submit a ticket on our helpdesk.

Once you become a customer you get access to a Highly Experienced Joomla Developer and;

  • Access to our secure private support helpdesk site where access credentials are kept along with tasks and changes which are documented in detail.
  • Use of our ticketing system where bugs can be reported, questions asked, and additional features can be requested.
Once an order is placed for the first time and paid for we create you a user account on our secure private support helpdesk site where we will request information which you can provide securely, Your access credentials will be emailed to you as soon as your account is created.

Prepaid support it given high priority, with all of our hourly support time is charged in 10 minute increments and the week ends each Sunday at midnight UK time. All time is logged in your private area on our secure private support helpdesk and detailed invoices are issued weekly along with account statements.

Related Content

The Joomla! Project is pleased to announce the release of Joomla 5.0.3 and 4.4.3. This is a security and bug fix release for the 5.x and 4.x series of...

We are proud to announce the release of Joomla 3.10.14. This version backports the security fix for CVE-2023-40626. This is a commercial security rele...

You can now order our remote Joomla Website Support Services online and pay in GB Pounds, Euros or US Dollars by credit/debit card or by bank transfer...

The Joomla! Project is pleased to announce the release of Joomla 5.0.2 and 4.4.2. This is a bug fix release for the 5.x and 4.x series of Joomla. This...

At Joomla Fixers we provide remote on demand and routine Joomla Website Support, Website Design, Website Development, Website Maintenance, Website Marketing and Website Hosting services to both end users and web design studios alike Worldwide.

Our vast experience gained in supporting, repairing, building, hosting, maintaining and optimising Joomla websites since 2005 combined with our Joomla Website Support System enables us to work very efficiently.

Joomla Fixers-Joomla Website Support and Maintenance Specialists
Realvision Internet Limited
124 City Road
London, EC1V 2NX
United Kingdom


Terms and Conditions
Privacy Policy
Cookie Policy
Privacy-respecting analytics by Matomo

Secure Payments Powered by Stripe