Download Our Latest Software

Akeeba Ticket System 5.6.1 Stable

Released on: 2026-09-25 01:57 CDT

What's new?

Security hardening. This version concludes our full audit of the code, addressing the remaining issues, and hardening the extension's security posture.

Enforced version compatibility checks. The package now checks your Joomla and PHP version when you try to install it. If it detects an incompatible Joomla and/or PHP version it will refuse to install / uninstall / update and tell you. The extension itself will warn you about the incompatibility and refuse to run. This is an additional protection against accidentally breaking your site by installing an incompatible version of our software or your site, or updating / downgrading Joomla or PHP outside the supported range after installing the extension.

Removed legacy error handler. The legacy error handler would show very detailed site and server information whenever an error occurred in the backend of the site. Joomla 4 and later have their own error handler showing the same level of detail when you enable Site Debug. We removed our handler in favor of the core-provided solution.

Removed legacy BBCode parser. A long-deprecated BBCode parser, kept only to render tickets and manager notes created many years ago, allowed stored Cross-Site Scripting. We removed it; any old post or manager note still using BBCode tags will now show them as plain text instead of formatted content.

Changelog

Critical bugs and important changes

  • PHP and Joomla minimum and maximum version compatibility is now enforced
  • Supported versions are now Joomla! 5.4 to 6.2 and PHP 8.1 to 8.6

New features

  • Mail Fetch: option to verify the mail server's TLS certificate

Removed features

  • Removed legacy BBCode parser
  • Removed legacy error handler

Bug fixes

  • [HIGH] Attachment downloads had inadequate authorisation
  • [HIGH] Smart Search could surface posts of tickets unpublished, deleted, or made private
  • [HIGH] Web Push could leak its configuration
  • [LOW] Any backend support agent could read the CRON and mail fetch logs
  • [LOW] Attachment downloads did not encode the file name properly, and allowed MIME sniffing and caching
  • [LOW] Custom ticket status labels and avatar URLs were output without escaping
  • [LOW] List sort columns could've malfunctioned due to typos
  • [LOW] Only Super Users could publish or unpublish auto-replies and canned replies from their lists
  • [LOW] Refreshing Gmail tokens wrote verbose connection details to the server's error log
  • [LOW] The Attachments folder option was always ignored
  • [LOW] Typos in the default attachment extension lists kept .shb and .asp files blocked
  • [LOW] When cleaning one cache failed, the remaining caches were not cleaned either
  • [MEDIUM] API lists and write endpoints ignored whether the caller can view the ticket
  • [MEDIUM] Backend ticket, post, and manager note pages showed records of tickets the user cannot view
  • [MEDIUM] Batch ticket processing ignored category Deny rules and ticket visibility, and ran on the frontend
  • [MEDIUM] Downgrading to Core left behind some non-updatable plugins
  • [MEDIUM] Editing a post could move it, and its attachments, into another ticket
  • [MEDIUM] Inadequate single- and cross-category authorisation controls for Manager Notes
  • [MEDIUM] Joomla Privacy data removal and export requests failed and left all ticket data in place
  • [MEDIUM] Mail template tags could be typed into ticket bodies
  • [MEDIUM] Unpublished posts, and private attachments, could be emailed to users not allowed to see them
  • [MEDIUM] Web Push subscriptions let registered users make the server send requests to internal addresses

Miscellaneous changes

  • Added attachments limit for tickets and replies posted over email
  • Batch ticket commands are authorised only in the controller
  • Declare the core.options permission so it can be granted per user group
  • Errors thrown by custom upgrade handlers are now reported when Joomla's Debug Site setting is on
  • Funnel query construction through the Helper\DbQuery::create() compatibility helper
  • HTMLPurifier's definition cache is now really disabled when the cache folder is not writable
  • Improved email references to make it harder to guess the site secret
  • Improved entropy for naming of on-disk attachments
  • Improved filtering for the layout URL parameter
  • Improved logic when editing private tickets owned by a user who can no longer create private tickets
  • Improved the way stored attachment file names are used when downloading attachments
  • Log viewer now escapes its output for improved resiliency
  • Logs require Site Debug enabled to store potentially sensitive information
  • Mail fetching now uses the stable Horde IMAP 3.1 library instead of a development branch
  • Removed dead code paths for Joomla! and PHP versions below the supported minimums
  • Stricter authorisation checks on invited users operations
  • Stricter category controls when editing a ticket
  • Stricter controls against trying to reply by email to a manager's note notification when Mail Fetch is enabled
  • Stricter controls over which mail authentication classes can be instantiated
  • The installer now refuses to install on untested, newer Joomla! and PHP versions
  • Tighter authorisation for scheduling settings, enable plugins, or reset email templates

Release files

Akeeba Ticket System Core

pkg_ats-5.6.1-core.zip

1.14 Mb

PHP 8.1 PHP 8.2 PHP 8.3 Joomla! 5.3 Joomla! 5.4 PHP 8.4 Joomla! 6.0 Joomla! 6.1 Joomla! 6.2 PHP 8.5 PHP 8.6

Download now