The default language of any content posted is English. Do not create multi-accounts, you will be blocked! For more information about rules, limits, and more, visit the
Help page. Found a dead link? Use the report button!
Security Update
This release addresses a security vulnerability affecting previous Forms versions
CVE: CVE-2026-56291
Security Fixes:
Added server-side validation of allowed file extensions for frontend uploads based on the field configuration
For the Upload File field, a new MIME Types option has been added to improve upload security
Uploaded files now receive randomly generated server-side filenames instead of preserving client filenames
Added CSRF protection to frontend file upload requests
Affected Versions: 2.4.0 and earlier
Action Required:
Update to Forms 2.4.1 immediately
Review the images/baforms/uploads/ directory, including all subdirectories, and remove any unexpected PHP files, as uploaded content directories should not contain executable PHP files
Acknowledgement: Vulnerability was responsibly disclosed by Phil Taylor