Security Update
This release addresses a security vulnerability affecting previous Forms versions
CVE: CVE-2026-56291
Security Fixes:
Affected Versions: 2.4.0 and earlier
- Added server-side validation of allowed file extensions for frontend uploads based on the field configuration
- For the Upload File field, a new MIME Types option has been added to improve upload security
- Uploaded files now receive randomly generated server-side filenames instead of preserving client filenames
- Added CSRF protection to frontend file upload requests
Action Required: Update to Forms 2.4.1 immediately
Acknowledgement: Vulnerability was responsibly disclosed by Phil E. Taylor
Added
Fixed
- Accessible Design Option
- Aria Label for Submit button field
- Ability to navigate the form using a keyboard
- Full compatibility with the default Joomla plugin "Additional Accessibility Features"
- Built-in Google reCAPTCHA integration
- Fiscalization for payment gateways: Cloudpayments, Robokassa, and YooKassa
- Ability to set the time for the Submit Expiration Date
- Issue related to form submitting limitation by IP address
- Small design issues in the admin panel
Added
Updated
- Native compatibility with Joomla 5
- Undo or redo changes in the form editor
- Submission limitations
- Cloudflare Turnstile integration
- Google Sheets integration
- Google Drive integration
Fixed
- Telegram integration
- Issues with the code editor
- Issues with CLI commands
- Issues with complex conditional logic rules and PayPal integration.
- Creating PDF files in PHP 8.x
- CSS issue with calendar z-index
- CSS issue with displaying help text on mobile devices
- CSS issue with form templates in the editor
- Design styles for field calculation
- Issues with the settings panel in sidebar mode
- Issues with dark mode in Joomla 5
v.2.2.1
v.2.2.0.2
- Added: Compatibility with Joomla 5;
- Fixed: Issues with Joomla 5 admin template in dark mode;
- Fixed: Code editor in Joomla 5;
- Fixed: Issue with a signature field;
- Fixed: Issue with disabled reCAPTCHA plugin in Joomla plugins;
- Fixed: Issue with redirect after submit;
- Fixed: Issue with drag and drop field custom HTML.
- Fixed: Conflict of signature field and 3rd-party templates;
- Fixed: Issue with disabled Google's reCAPTCHA plugin;
- Fixed: Conflict with 3d-party redirects on site.