Joomla Legal File Types and Maximum Upload Size

Joomla Legal File Types and Maximum Upload Size

By default, Joomla allows uploads only for specific file types and limits the maximum file size that can be uploaded.

For example, a standard Joomla installation allows the following file extensions:

bmp,csv,doc,gif,ico,jpg,jpeg,odg,odp,ods,odt,pdf,png,ppt,swf,txt,xcf,xls,BMP,CSV,DOC,GIF,ICO,JPG,JPEG,ODG,ODP,ODS,ODT,PDF,PNG,PPT,SWF,TXT,XCF,XLS

This list does not include many common file types, including several used by modern versions of Microsoft Office.

Fortunately, you can easily change these settings.


Allow Additional File Types

  • Log in to your Joomla administrator area.
  • Go to Content > Media.
  • Click the Options button in the top-right corner.

the Options button

In the Options screen, you can see the file extensions that Joomla currently allows.

Allowed Extensions

When adding or editing file extensions, follow these guidelines:

  • List the extensions in alphabetical order.
  • Separate each extension with a comma.
  • Do not include the period (.) before the extension. For example, use png,gif instead of .png,.gif.
  • Include both lowercase and uppercase versions of each extension.

Increase the Maximum Upload Size

On the same screen, you can also increase Joomla's default maximum upload size of 10 MB to a value that better suits your site.

The Maximum Size setting

Note: The maximum value you can use may also be limited by your web hosting account's PHP configuration. If Joomla does not accept the size you specify, contact your hosting provider.


Other Media Manager Options

This page also contains several advanced settings. Unless you understand what each option does, we recommend leaving them at their default values.

Other Advanced Settings

  • Maximum Size (in MB). Specifies the largest file size users can upload through the Media Manager. The default value is 10 MB. This limit cannot exceed the maximum upload size configured in your PHP and web server settings.
  • Path to Files Folder. Specifies where non-image files, such as PDFs, Word documents, spreadsheets, audio, and videos, are stored. By default, Joomla uses <joomla_root>/files. You can create a different folder and enter its path here if required.
  • Path to Images Folder. Specifies where uploaded images are stored. By default, Joomla uses <joomla_root>/images. If you choose a different folder, it should remain accessible through the Media Manager.
  • Restrict Uploads. Determines whether Joomla enforces upload restrictions based on the allowed file extensions and MIME type settings. The default value is Yes. We recommend leaving this enabled for security.
  • Allowed Extensions. Lists the file extensions that Joomla allows users to upload. The default list includes common image, audio, video, and document formats. To allow additional file types, add their extensions to this comma-separated list.
  • Check MIME Types. Verifies that uploaded files match their expected MIME types. This helps prevent malicious files from being uploaded with misleading file extensions. We recommend leaving this setting enabled. If legitimate files are rejected because of incorrect MIME type detection, you can temporarily disable it for troubleshooting.
  • Legal Image Extensions (File Types). Specifies which file extensions Joomla recognises as valid image files. By default, Joomla allows bmp, gif, jpg, jpeg, png, webp, and avif.
  • Legal Audio Extensions (File Types). Specifies which file extensions Joomla recognises as valid audio files. By default, Joomla allows mp3, m4a, mp4a, and ogg.
  • Legal Video Extensions (File Types). Specifies which file extensions Joomla recognises as valid video files. By default, Joomla allows mp4, mp4v, mpeg, mov, and webm.
  • Legal Document Extensions (File Types). Specifies which file extensions Joomla recognises as valid document files. By default, Joomla allows odg, odp, ods, odt, pdf, ppt, txt, xcf, xls, and csv.
  • Ignored Extensions. Lists file extensions that Joomla excludes from MIME type checking. This option is primarily intended for advanced use cases where certain file types produce incorrect MIME information. By default, no extensions are ignored.
  • Legal MIME Types. Specifies the MIME types Joomla accepts for uploaded files. The default list covers the supported image, audio, video, and document formats. You should only modify this setting if you need to support additional file types and understand the security implications.
  • Illegal MIME Types. Specifies MIME types that Joomla always blocks from being uploaded. By default, this list includes HTML- and script-related MIME types, helping prevent potentially dangerous files from being uploaded. We recommend leaving this setting unchanged.
  • Legal File Extensions (File Types). Lists file extensions that Joomla treats as safe generic files. Unlike the image, audio, video, and document lists, these files are not assigned to a specific media category. Leave the default value unless you need to support additional safe file types.
  • Legal MIME Types (Text). Specifies the MIME types associated with the generic file extensions listed above. Joomla uses this list together with the Legal File Extensions setting to validate uploads. Only modify it if you add new file types and know their correct MIME types.
  • Illegal File Extensions. Lists file extensions that Joomla blocks regardless of the other upload settings. This provides an additional layer of protection against potentially dangerous files, such as executable scripts. We recommend leaving the default list unchanged.

What's Next?

Save $1,000's when you sign up for Joomlashack's Everything Club.

You will get your hands on our extensive range of over 20 extensions, plus legendary support!

Click here to join the Everything Club