Joomla! 3.9.16 Update - Security & Bugfixes
Joomla 3.9.16 has just been released. The update fixes six security vulnerabilities (Low Priority) and includes more than 20 bug fixes and improvements.
If booked Maintenance service you are already up to date and this email is for information only.
Joomla 3.9.16 Release Notes
Fixed security vulnerability- Low Priority - Core - SQL injection in Featured Articles menu parameters (affecting Joomla 1.7.0 through 3.9.15)
- Low Priority - Core - CSRF in com_templates image actions (affecting Joomla 3.2.0 through 3.9.15)
- Low Priority - Core - XSS in Protostar and Beez3 (affecting Joomla 3.0.0 through 3.9.15)
- Low Priority - Core - Incorrect Access Control in com_templates (affecting Joomla 2.5.0 through 3.9.15)
- Low Priority - Core - Identifier collisions in com_users (affecting Joomla 3.0.0 through 3.9.15)
- Low Priority - Core - Incorrect Access Control in com_fields SQL field (affecting Joomla 3.7.0 through 3.9.15)
Bug fixes and improvements
- Link rel attribute: ‘noopener’, ‘sponsored’ and ‘ugc’ corrected
- Fields - Imagelist: Correction of the directory structure display
- Popular Tags module correction
- Category ID corrected in the Contact Creator plugin
Source: https://www.joomla.org/announcements/release-news/5783-joomla-3-9-16.html
