Is this fact? Can someone tell me what I need to update.. Update to 4.4.11? Wondering what settings I will lose on updating ? took a lot to get this the way I wanted it...
Plugin: VirtueMart (com_virtuemart) below 4.4.11 - Unauthenticated Reflected XSS and Authenticated SQL Injection
VirtueMart e-commerce component. CVE-2025-55757 (unauthenticated reflected XSS, affects 1.0.0-4.4.10) and CVE-2025-25228 (authenticated SQL injection in product management, affects 1.0.0-4.4.7). Fixed in 4.4.11. Rule pinned to component type because the Xmap and OSMap VirtueMart bridge plugins ship under element com_virtuemart at their own low versions.
https://nvd.nist.gov/vuln/detail/CVE-2025-55757
VirtueMart is at version 4.6.8 at this moment.
VirtueMart is Joomla 5 compatible since VM 4.2.6 (released 29 January 2024).
Your version of VirtueMart (4.2.4) is close to 3 years old.
Joomla 4 is EOL since October 2025.
There have been several recurity releases.
VirtueMart news: https://virtuemart.net/news
I strongly recomend you update to the latest version*!
Remember, your webshop holds the personal data of your customers!
I recomend to test the update on a copy of your site first.
Create a backup with Akeeba Backup.
Install WAMPServer or MAMP on your computer to create a local server.
Copy and install your webshop on your local server with Akeeba Kickstart.
Update this copy.
This way you know what to expect during the update process and solve potential issues, without affecting your live webshop.
And if something does go wrong, you don't have to panic: just reinstall the copy and start over.
Note:
* There is a VirtueMart 4.9. This is the beta for VM5, do not use a beta on a live website!