- Posts: 13738
- Thank you received: 1803
Need help with Joomla? We are available for hire to help with Joomla customization, upgrades, maintenance, and custom development.
Explore our services
All questions about EDocman extension
EDocman 3.9.0 Security Release — Important Update Recommended
- Dang Thuc Dam
-
Topic Author
- Offline
- Administrator
-
Less
More
3 weeks 6 days ago - 3 weeks 3 days ago #178968
by Dang Thuc Dam
We are issuing this urgent notice to inform all EDocman users about the immediate availability of EDocman 3.9.0, an important security and maintenance update
This release focuses on strengthening the overall security of EDocman, improving compatibility with modern Joomla versions, updating older Joomla API usage where needed, and addressing potential security issues discovered during our recent internal review and responsible third-party security reporting.
We strongly recommend that all EDocman customers update to version 3.9.0 as soon as possible.
What Has Been Improved in EDocman 3.9.0
EDocman 3.9.0 includes multiple improvements designed to reduce security risks and improve data protection across the component.The update includes:
Security Issues Addressed
As part of this release, we addressed a reported security issue that could affect certain front-end request handling in previous versions of EDocman.We also reviewed related areas of the component and improved how EDocman validates input, builds database queries, and handles redirects. These changes help reduce the risk of unauthorized data access, unsafe query handling, and improper redirect behavior.This release is intended to provide stronger protection for both site administrators and end users.
Joomla Compatibility and Code Modernization
In this release, we also updated several parts of EDocman to better align with current Joomla development standards.These changes improve compatibility with newer Joomla versions, reduce reliance on older APIs, and make the component more stable, secure, and easier to maintain going forward.
Responsible Security Disclosure
We would like to thank the security researcher who privately reported an important security issue to us and gave us time to investigate, fix, and prepare this release before any public disclosure.Responsible disclosure helps protect users and website owners. We appreciate the cooperation and professionalism shown during the reporting process.
After receiving the report, our team immediately reviewed the affected code, prepared fixes, and performed a broader security review to identify and address similar patterns elsewhere in the component.
Who Should Update?
All EDocman users should update to EDocman 3.9.0.
This update is especially important for websites that:
Recommended Action
Please update your website to EDocman 3.9.0 immediately.Before updating, we recommend:
Special note for Joomla 3 customers
For customers who are still running Joomla 3, we understand that you may not be able to install the latest standard EDocman package directly.
If you have an active EDocman subscription, or if your EDocman subscription expired in early 2026, please submit a support ticket under the EDocman category. Our team will provide you with a patched EDocman package compatible with Joomla 3 free of charge.
This allows eligible Joomla 3 customers to apply the necessary security fix while maintaining compatibility with their existing Joomla 3 websites.
Responsible Security Disclosure
We would like to give a huge shoutout to Phil Taylor from mysites.guru for responsibly identifying and reporting the vulnerability, and for helping us throughout the process of verifying the issue, preparing the fix, and getting the patched release shipped.
Responsible disclosure helps protect Joomla website owners and the wider Joomla community. We truly appreciate Phil’s time, professionalism, and support during this process.
If you are looking for an easy way to manage Joomla websites, we encourage you to give mysites.guru a try. It helps keep your Joomla sites updated and monitored from a single dashboard, quietly working in the background so you can focus on what matters most: your clients.
Final Notes
Security is an ongoing process. With EDocman 3.9.0, we have not only fixed the reported vulnerability but also improved several related areas of the codebase to provide stronger protection for our customers.
We will continue reviewing and improving EDocman to ensure it remains secure, reliable, and compatible with current Joomla versions.
EDocman 3.9.0 Security Release — Important Update Recommended was created by Dang Thuc Dam
We are issuing this urgent notice to inform all EDocman users about the immediate availability of EDocman 3.9.0, an important security and maintenance update
This release focuses on strengthening the overall security of EDocman, improving compatibility with modern Joomla versions, updating older Joomla API usage where needed, and addressing potential security issues discovered during our recent internal review and responsible third-party security reporting.
We strongly recommend that all EDocman customers update to version 3.9.0 as soon as possible.
What Has Been Improved in EDocman 3.9.0
EDocman 3.9.0 includes multiple improvements designed to reduce security risks and improve data protection across the component.The update includes:
- Improved handling of database queries.
- Stronger validation of front-end request data.
- Better escaping and filtering of user-supplied values.
- Safer processing of document filters, category filters, and date filters.
- Improved protection for public front-end tasks.
- Safer redirect handling.
- Additional review of access and permission-related logic.
Security Issues Addressed
As part of this release, we addressed a reported security issue that could affect certain front-end request handling in previous versions of EDocman.We also reviewed related areas of the component and improved how EDocman validates input, builds database queries, and handles redirects. These changes help reduce the risk of unauthorized data access, unsafe query handling, and improper redirect behavior.This release is intended to provide stronger protection for both site administrators and end users.
Joomla Compatibility and Code Modernization
In this release, we also updated several parts of EDocman to better align with current Joomla development standards.These changes improve compatibility with newer Joomla versions, reduce reliance on older APIs, and make the component more stable, secure, and easier to maintain going forward.
Responsible Security Disclosure
We would like to thank the security researcher who privately reported an important security issue to us and gave us time to investigate, fix, and prepare this release before any public disclosure.Responsible disclosure helps protect users and website owners. We appreciate the cooperation and professionalism shown during the reporting process.
After receiving the report, our team immediately reviewed the affected code, prepared fixes, and performed a broader security review to identify and address similar patterns elsewhere in the component.
Who Should Update?
All EDocman users should update to EDocman 3.9.0.
This update is especially important for websites that:
- Allow public front-end access to EDocman.
- Use document subscription or unsubscribe features.
- Use front-end document listing and filtering.
- Store private or user-related document data.
- Run EDocman on production Joomla websites.
Recommended Action
Please update your website to EDocman 3.9.0 immediately.Before updating, we recommend:
- Make a full backup of your website files and database.
- Install the latest EDocman package.
- Clear Joomla and browser cache after updating.
- Test document listing, downloads, subscriptions, and unsubscribe features.
- Confirm that front-end and back-end EDocman pages work as expected.
Special note for Joomla 3 customers
For customers who are still running Joomla 3, we understand that you may not be able to install the latest standard EDocman package directly.
If you have an active EDocman subscription, or if your EDocman subscription expired in early 2026, please submit a support ticket under the EDocman category. Our team will provide you with a patched EDocman package compatible with Joomla 3 free of charge.
This allows eligible Joomla 3 customers to apply the necessary security fix while maintaining compatibility with their existing Joomla 3 websites.
Responsible Security Disclosure
We would like to give a huge shoutout to Phil Taylor from mysites.guru for responsibly identifying and reporting the vulnerability, and for helping us throughout the process of verifying the issue, preparing the fix, and getting the patched release shipped.
Responsible disclosure helps protect Joomla website owners and the wider Joomla community. We truly appreciate Phil’s time, professionalism, and support during this process.
If you are looking for an easy way to manage Joomla websites, we encourage you to give mysites.guru a try. It helps keep your Joomla sites updated and monitored from a single dashboard, quietly working in the background so you can focus on what matters most: your clients.
Final Notes
Security is an ongoing process. With EDocman 3.9.0, we have not only fixed the reported vulnerability but also improved several related areas of the codebase to provide stronger protection for our customers.
We will continue reviewing and improving EDocman to ensure it remains secure, reliable, and compatible with current Joomla versions.
Please update to EDocman 3.9.0 as soon as possible.
Last edit: 3 weeks 3 days ago by Dang Thuc Dam.
The following user(s) said Thank You: Michael Lieder, Greg Troin, Johnny
Please Log in or Create an account to join the conversation.
- Mary
-
- Offline
- Senior Member
-
3 weeks 5 days ago #178972
by Mary
Replied by Mary on topic EDocman 3.9.0 Security Release — Important Update Recommended
I have one site on Joomla 3 and I got the message Cannot install Edocman in a Joomla! release prior to 4.2.0
Error installing package. In all honesty, the site only uses EDocman to display a handful of documents and is not used regularly. What safeguards should I put in place?
Error installing package. In all honesty, the site only uses EDocman to display a handful of documents and is not used regularly. What safeguards should I put in place?
Please Log in or Create an account to join the conversation.
- Dang Thuc Dam
-
Topic Author
- Offline
- Administrator
-
Less
More
- Posts: 13738
- Thank you received: 1803
3 weeks 5 days ago #178975
by Dang Thuc Dam
Replied by Dang Thuc Dam on topic EDocman 3.9.0 Security Release — Important Update Recommended
Hi Mary,
Please submit a support ticket under the EDocman category.
Once we receive your ticket, we will send you the security patch version for Joomla 3.
Thanks,
Dam
Please submit a support ticket under the EDocman category.
Once we receive your ticket, we will send you the security patch version for Joomla 3.
Thanks,
Dam
The following user(s) said Thank You: Mary
Please Log in or Create an account to join the conversation.
- kamicode
- Offline
- New Member
-
Less
More
- Posts: 1
- Thank you received: 0
3 weeks 4 days ago #178988
by kamicode
Replied by kamicode on topic EDocman 3.9.0 Security Release — Important Update Recommended
Would it be possible to get version 3.8 of eDocman, we have 3.9 but need to do a file compare to identify the fixes for our corporate client. I see no way to download previous versions on the website.
Many thanks
Many thanks
Please Log in or Create an account to join the conversation.
Moderators: Dang Thuc Dam
Support
Documentation
Information
Copyright © 2026 Joomla Extensions by Joomdonation. All Rights Reserved.
joomdonation.com is not affiliated with or endorsed by the Joomla! Project or Open Source Matters.
The Joomla! name and logo is used under a limited license granted by Open Source Matters the trademark holder in the United States and other countries.
The Joomla! name and logo is used under a limited license granted by Open Source Matters the trademark holder in the United States and other countries.