Skip to content

OpnForm

v2.1.0 Security

This release includes 1 security fix for security teams reviewing exposed deployments.

✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 1 known CVE

Topics

form form-builder laravel marketing-tools nuxt saas

Affected surfaces

auth

Summary

AI summary

Updates Validation, Related, and PR across a mixed release.

Full changelog

This release fixes two self-hosted issues affecting PDF templates and password-protected forms.

Fixed

  • Fixed PDF template zones being placed out of reach when adding fields to a tall PDF page. Newly added zones now stay visible and can be dragged normally.
  • Fixed password-protected forms on plain-HTTP self-hosted instances. Firefox rejected the previous secure-only password cookie on non-HTTPS origins, which made valid passwords appear invalid. HTTPS deployments keep the secure cookie behavior.

Validation

  • Reproduced the password issue in Firefox on a local HTTP self-host-style origin, then verified the form unlocks correctly after the fix.
  • Verified newly added PDF zones stay visible and draggable in the PDF template editor.
  • Ran frontend lint and targeted backend password form tests.

Related

  • PR: https://github.com/OpnForm/OpnForm/pull/1184

Security Fixes

  • Password cookie handling for self‑hosted plain‑HTTP instances no longer rejects valid passwords in Firefox due to secure‑only flag.

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track OpnForm

Get notified when new releases ship.

Sign up free

About OpnForm

Beautiful Open-Source Form Builder

All releases →

Related context

Earlier breaking changes

  • v2.0.0 Requires running new database migrations before using V2 features.

Beta — feedback welcome: [email protected]