Subscription 6.2.0
Date: June 29, 2026
Stability: Stable
Compatibility: PHP 8.0, 8.1, 8.2, 8.3, 8.4, 8.5
System Requirements: Joomla 6, Visforms Base Package 6.2.0
New Feature
- Location field: Save addresses to other form fields.
- Location field: Generate address search based on data from other form fields.
- Location field: Save address search string to a form field.
- Bootstrap 5: Sublayout ‘Individuell Layout’: New options: Insert line break before/after field.
- Upload field: Resize large image files in the browser before upload.
- Upload field: Drag-and-drop file selection.
- Upload field: Retain original filename during upload and overwrite previously uploaded files with the same name.
- Upload field: Conditional display: Use non-empty upload fields as control fields.
- Frontend data view: Search filter: New option: Display filter bar in a space-saving layout.
- Frontend data view: Search filter: New option: Hide sort order filter.
- Frontend data view: Search filter: New option: Hide arrows in sort order filter.
- Multi-page forms: New option: “Next” button text.
Bug Fixes
Improvements
- PHP 8.5 compatibility.
- Extensive revision of language tags and consolidation of translations.* Refactoring of the JavaScript for the location field.
- Refactoring of the JavaScript for the location field.
- Dynamic, asynchronous loading of Google Maps libraries.
- Refactoring of search filters in the frontend data view.
- Native JavaScript implementation without the jQuery library.
- Refactoring of export/import functionality.
- Use of the Joomla table prefix placeholder instead of named table prefixes.
Subscription 6.2.1
Datum: 13.08.2026
Stability: Stable
Compatibility: PHP 8.0, 8.1, 8.2, 8.3, 8.4, 8.5
System Requirements: Joomla 6, Visforms Base Package 6.2.1
Bug Fixes
- SQL fields: Field value from the SQL statement is not set correctly in the edit view.
- SQL list box: An error occurs when the SQL list box option Process SQL in edit view is set to No.
Security
- AI-assisted vulnerability remediation by security researcher Yukusawa18.
- Arbitrary PHP creation and raw write leads to RCE.
- Arbitrary file deletion through path traversal, missing authorization, and missing CSRF protection.
- Bypass of form-edit authorization and can redirect future form submissions to an attacker-selected mailbox.
- Bypass of the Joomla core.create permission.
- Unauthenticated verification-mail and verification-table amplification for arbitrary form IDs.
- External redirect through the submitted return parameter on an invalid form submission.