This release includes 1 security fix for security teams reviewing exposed deployments.
Topics
Affected surfaces
ReleasePort's take
Moderate signalVersion v2.0.0 introduces PDF generation, computed variables across form artifacts, third‑party imports, version history with restore, enriched analytics dashboards, UI enhancements in the builder, new pricing tiers and self‑hosted licensing, plus a mandatory database migration before using V2 features.
Why it matters: The release adds multiple productivity‑focused features (PDF generation, computed variables, import support, enhanced analytics) but requires running new database migrations (severity 70) before any V2 functionality can be used; plan upgrade windows accordingly.
Summary
AI summaryUpdates Highlights, Also included, and Upgrade notes across a mixed release.
Changes in this release
| Type | Severity | Summary | CVE |
|---|---|---|---|
| Security | Medium |
Hardens upload handling, validates public webhook URLs, and strengthens rate limiting for submission processing. Hardens upload handling, validates public webhook URLs, and strengthens rate limiting for submission processing. Source: granite4.1:30b@2026-06-08-audit Confidence: low |
— |
| Breaking | High |
Requires running new database migrations before using V2 features. Requires running new database migrations before using V2 features. Source: llm_adapter@2026-06-08 Confidence: high |
— |
| Feature | Medium |
Adds PDF generation and template support for submissions. Adds PDF generation and template support for submissions. Source: llm_adapter@2026-06-08 Confidence: high |
— |
| Feature | Medium |
Adds computed variables to reuse formulas across forms, emails, PDFs, and logic. Adds computed variables to reuse formulas across forms, emails, PDFs, and logic. Source: llm_adapter@2026-06-08 Confidence: high |
— |
| Feature | Medium |
Adds third‑party form import from Typeform, Tally, Google Forms, and Fillout. Adds third‑party form import from Typeform, Tally, Google Forms, and Fillout. Source: llm_adapter@2026-06-08 Confidence: high |
— |
| Feature | Medium |
Adds version history with restore capability for forms and submissions. Adds version history with restore capability for forms and submissions. Source: llm_adapter@2026-06-08 Confidence: high |
— |
| Feature | Medium |
Adds submission summaries showing aggregate field‑level statistics. Adds submission summaries showing aggregate field‑level statistics. Source: llm_adapter@2026-06-08 Confidence: high |
— |
| Feature | Medium |
Refreshes analytics with views, submissions, partials, and traffic breakdowns by source, device, browser, OS, and country. Refreshes analytics with views, submissions, partials, and traffic breakdowns by source, device, browser, OS, and country. Source: llm_adapter@2026-06-08 Confidence: high |
— |
| Feature | Medium |
Enhances dynamic builder with placeholders, help text, and answer/computed value mentions in more places. Enhances dynamic builder with placeholders, help text, and answer/computed value mentions in more places. Source: llm_adapter@2026-06-08 Confidence: high |
— |
| Feature | Medium |
Introduces new plan tiers (Free, Pro, Business, Enterprise) and self‑hosted feature gating with licensing settings. Introduces new plan tiers (Free, Pro, Business, Enterprise) and self‑hosted feature gating with licensing settings. Source: llm_adapter@2026-06-08 Confidence: high |
— |
| Bugfix | Medium |
Improves Google OAuth flows with import‑specific intent handling and robustness. Improves Google OAuth flows with import‑specific intent handling and robustness. Source: llm_adapter@2026-06-08 Confidence: high |
— |
| Bugfix | Low |
Updates pricing, billing, and Stripe provisioning infrastructure. Updates pricing, billing, and Stripe provisioning infrastructure. Source: granite4.1:30b@2026-06-08-audit Confidence: low |
— |
Full changelog
OpnForm V2 is a major release focused on more powerful form building, richer submission workflows, and a clearer foundation for billing, self-hosting, and plan-based feature access.
Highlights
- PDF generation and templates: create or upload PDF templates, map form answers into PDF zones, generate PDFs from submissions, let respondents download PDFs after submission, and attach generated PDFs to email notifications.
- Computed variables: define formulas from answers and reuse computed results across forms, emails, PDFs, logic, and dynamic text.
- Third-party form import: import forms from supported builders including Typeform, Tally, Google Forms, and Fillout.
- Version history and restore: review previous versions of forms and submissions, then restore them when needed.
- Submission summaries: view aggregate field-level summaries for text, numbers, dates, matrix fields, ratings, payments, and answer distributions.
- Improved analytics: refreshed stats with views, submissions, partial submissions, and traffic breakdowns by source, device, browser, OS, and country.
- Dynamic builder improvements: placeholders, help text, integrations, and notifications can use answer mentions and computed values in more places.
- New plan and feature access system: V2 introduces Free, Pro, Business, Enterprise, and self-hosted feature gates, plan changes, yearly upgrades, and legacy/LTD grandfathering through plan overrides.
- Self-hosted licensing improvements: license keys, activations, checkout sessions, cloud license checks, and feature-gated self-hosted capabilities are now part of the platform foundation.
Also included
- Better AI form generation prompts and paid-plan prompt length handling.
- More robust Google OAuth flows, including import-specific intent handling.
- Improved integration logic and dynamic value parsing in email/integration workflows.
- Safer upload handling, public webhook URL validation, rate-limit hardening, and submission processing fixes.
- Updated pricing, billing, and Stripe provisioning infrastructure.
- Many backend, frontend, test, and CI updates needed for the V2 platform.
Upgrade notes
- This release includes new database migrations. Run the normal migration flow before using the new features.
- Some new V2 features are plan-gated. Existing legacy Pro and AppSumo/LTD entitlements are preserved through grandfathered plan overrides where applicable.
- Self-hosted instances should review the new license-related settings and feature flags before upgrading.
- Billing and Stripe plan management now rely on the new plan configuration and provisioning flow.
Key pull requests
- #1053 - OpnForm V2
- #1152 - Backfill legacy select option IDs
- #1153 - Fix AppSumo feature plan tags
- #1155 - Gate self-hosted licensed features
Full diff: https://github.com/OpnForm/OpnForm/compare/v1.13.2...cac715f21268c0338531e17209bc0574d9b30cd2
Breaking Changes
- New database migrations are required before using V2 features.
- Self‑hosted licensing settings and feature flags must be reviewed prior to upgrade.
Security Fixes
- Safer upload handling, public webhook URL validation, rate‑limit hardening, and submission processing fixes improve overall security posture.
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
Related context
Related tools
Beta — feedback welcome: [email protected]