Visforms 5.6.x

Visforms 5.6.0

Date: October 6, 2025
Stabilität: Stable
Compatibility: PHP 8.0, 8.1, 8.2, 8.3, 8.4
System Requirements: Joomla 5, Joomla 6 with Plugin Behavior - Backward Compatibility 6

New Features

  • Form configuration: Advanced caching protection

Bug Fixes

  • Fixed: The input field for the Visforms Captcha is automatically focused in the UI framework ‘None’.
  • Fixed: Missing space between custom CSS classes for input field and standard CSS classes for input field.
  • Fixed: Records in the _save table are displayed as checked out.

Improvements

Code Refactoring:

  • Joomla 6 ready

Further information

Visforms 5.6.1

Date: October 14, 2025
Stabilität: Stable
Compatibility: PHP 8.0, 8.1, 8.2, 8.3, 8.4
System Requirements: Joomla 5, Joomla 6 with Plugin Behavior - Backward Compatibility 6

Improvements

  • Enhancement of the advanced caching protection introduced in 5.6.0

Visforms 5.6.2

Date: April 13, 2026
Stability: Stable
Compatibility: PHP 8.0, 8.1, 8.2, 8.3, 8.4
System Requirements: Joomla 5, Joomla 6 with Plugin Behavior - Backward Compatibility 6

Bug Fixes

  • Fixed: Some remaining ‘Deprecated’ PHP warnings for outdated technologies.

Improvements

  • Security: jQuery Validate has been updated to version 1.22.1.

Visforms 5.6.3

Date: July 23, 2026
Stability: Stable
Compatibility: PHP 8.0, 8.1, 8.2, 8.3, 8.4
System Requirements: Joomla 5, Joomla 6 with Plugin Behavior - Backward Compatibility 6

New Features

  • Spam protection: Support for time-based spambot classification.

Bug Fixes

  • Fixed: Form configuration: Once checked, checkbox Honeypot cannot be unchecked.

Improvements

  • Security: Check uploaded files with function InputFilter::isSafeFile().

Visforms 5.6.4

Date: August 18, 2026
Stability: Stable
Compatibility: PHP 8.0, 8.1, 8.2, 8.3, 8.4
System Requirements: Joomla 5, Joomla 6 with Plugin Behavior - Backward Compatibility 6

Security

  • AI-assisted vulnerability remediation by security researcher Yukusawa18.
  • Arbitrary PHP creation and raw write leads to RCE.
  • Arbitrary file deletion through path traversal, missing authorization, and missing CSRF protection.
  • Bypass of form-edit authorization and can redirect future form submissions to an attacker-selected mailbox.
  • Bypass of the Joomla core.create permission.
  • Unauthenticated verification-mail and verification-table amplification for arbitrary form IDs.
  • External redirect through the submitted return parameter on an invalid form submission.