Subscription 6.2.x

Subscription 6.2.0

Date: June 29, 2026
Stability: Stable
Compatibility: PHP 8.0, 8.1, 8.2, 8.3, 8.4, 8.5
System Requirements: Joomla 6, Visforms Base Package 6.2.0

New Feature

  • Location field: Save addresses to other form fields.
  • Location field: Generate address search based on data from other form fields.
  • Location field: Save address search string to a form field.
  • Bootstrap 5: Sublayout ‘Individuell Layout’: New options: Insert line break before/after field.
  • Upload field: Resize large image files in the browser before upload.
  • Upload field: Drag-and-drop file selection.
  • Upload field: Retain original filename during upload and overwrite previously uploaded files with the same name.
  • Upload field: Conditional display: Use non-empty upload fields as control fields.
  • Frontend data view: Search filter: New option: Display filter bar in a space-saving layout.
  • Frontend data view: Search filter: New option: Hide sort order filter.
  • Frontend data view: Search filter: New option: Hide arrows in sort order filter.
  • Multi-page forms: New option: “Next” button text.

Bug Fixes

Improvements

  • PHP 8.5 compatibility.
  • Extensive revision of language tags and consolidation of translations.* Refactoring of the JavaScript for the location field.
  • Refactoring of the JavaScript for the location field.
  • Dynamic, asynchronous loading of Google Maps libraries.
  • Refactoring of search filters in the frontend data view.
  • Native JavaScript implementation without the jQuery library.
  • Refactoring of export/import functionality.
  • Use of the Joomla table prefix placeholder instead of named table prefixes.

Subscription 6.2.1

Datum: 13.08.2026
Stability: Stable
Compatibility: PHP 8.0, 8.1, 8.2, 8.3, 8.4, 8.5
System Requirements: Joomla 6, Visforms Base Package 6.2.1

Bug Fixes

  • SQL fields: Field value from the SQL statement is not set correctly in the edit view.
  • SQL list box: An error occurs when the SQL list box option Process SQL in edit view is set to No.

Security

  • AI-assisted vulnerability remediation by security researcher Yukusawa18.
  • Arbitrary PHP creation and raw write leads to RCE.
  • Arbitrary file deletion through path traversal, missing authorization, and missing CSRF protection.
  • Bypass of form-edit authorization and can redirect future form submissions to an attacker-selected mailbox.
  • Bypass of the Joomla core.create permission.
  • Unauthenticated verification-mail and verification-table amplification for arbitrary form IDs.
  • External redirect through the submitted return parameter on an invalid form submission.