Visforms 5.6.0
Date: October 6, 2025
Stabilität: Stable
Compatibility: PHP 8.0, 8.1, 8.2, 8.3, 8.4
System Requirements: Joomla 5, Joomla 6 with Plugin Behavior - Backward Compatibility 6
New Features
- Form configuration: Advanced caching protection
Bug Fixes
- Fixed: The input field for the Visforms Captcha is automatically focused in the UI framework ‘None’.
- Fixed: Missing space between custom CSS classes for input field and standard CSS classes for input field.
- Fixed: Records in the _save table are displayed as checked out.
Improvements
Code Refactoring:
- Joomla 6 ready
Further information
Visforms 5.6.1
Date: October 14, 2025
Stabilität: Stable
Compatibility: PHP 8.0, 8.1, 8.2, 8.3, 8.4
System Requirements: Joomla 5, Joomla 6 with Plugin Behavior - Backward Compatibility 6
Improvements
- Enhancement of the advanced caching protection introduced in 5.6.0
Visforms 5.6.2
Date: April 13, 2026
Stability: Stable
Compatibility: PHP 8.0, 8.1, 8.2, 8.3, 8.4
System Requirements: Joomla 5, Joomla 6 with Plugin Behavior - Backward Compatibility 6
Bug Fixes
- Fixed: Some remaining ‘Deprecated’ PHP warnings for outdated technologies.
Improvements
- Security: jQuery Validate has been updated to version 1.22.1.
Visforms 5.6.3
Date: July 23, 2026
Stability: Stable
Compatibility: PHP 8.0, 8.1, 8.2, 8.3, 8.4
System Requirements: Joomla 5, Joomla 6 with Plugin Behavior - Backward Compatibility 6
New Features
- Spam protection: Support for time-based spambot classification.
Bug Fixes
- Fixed: Form configuration: Once checked, checkbox Honeypot cannot be unchecked.
Improvements
- Security: Check uploaded files with function InputFilter::isSafeFile().
Visforms 5.6.4
Date: August 18, 2026
Stability: Stable
Compatibility: PHP 8.0, 8.1, 8.2, 8.3, 8.4
System Requirements: Joomla 5, Joomla 6 with Plugin Behavior - Backward Compatibility 6
Security
- AI-assisted vulnerability remediation by security researcher Yukusawa18.
- Arbitrary PHP creation and raw write leads to RCE.
- Arbitrary file deletion through path traversal, missing authorization, and missing CSRF protection.
- Bypass of form-edit authorization and can redirect future form submissions to an attacker-selected mailbox.
- Bypass of the Joomla core.create permission.
- Unauthenticated verification-mail and verification-table amplification for arbitrary form IDs.
- External redirect through the submitted return parameter on an invalid form submission.