• Nullsto Rules must be read before making a post, otherwise you will get permanent warning points or a permanent ban.

    Nullsto Forum provides CLEAN and SAFE resources. You can use them for development and testing if you are on Windows and have an antivirus that alerts you about a possible infection: It is a false positive since every script is double checked by our experts. While downloading a resource, we recommend that you add Nullsto to your trusted sites/sources or temporarily disable your antivirus. "Enjoy your presence on Nullsto"
MachForm - HTML Form Builder Online, PHP Form Creator

MachForm - HTML Form Builder Online, PHP Form Creator v30.0 Nulled

No permission to download
Decryption key:


MachForm - HTML Form Builder Online, PHP Form Creator v30.0 Nulled
= Changelog
  • Security: Resolved a critical authentication bypass vulnerability (credit to Josh Cool).
  • Security: Strengthened CSRF token validation across administrative endpoints.
  • Security: Resolved Cross-Site Scripting (XSS) on Users / Entries page and Grid widget (credit to The Chinese University of Hong Kong – ITSC)
  • Security: Updated Axios library to use version 1.15.0
  • Bugfix: Accessibility issue (missing label) with “Other” field on Checkboxes/Multiple Choice
  • Bugfix: Display issue with rating field on mobile devices
  • Bugfix: Fixed incorrect “required” validation when a matrix field is being duplicated
  • Bugfix: Errors on Stripe payment page when being embedded across different domain
  • Bugfix: Uploaded files can’t be accessed on incomplete entries section
  • Bugfix: Success page doesn’t display correctly after PayPal payment completed
  • Bugfix: File upload counter not being calculated correctly when validation errors occur
Decryption Key For :


MachForm - HTML Form Builder Online, PHP Form Creator v29.0 Nulled
=
MachForm v29 is now available for download via your . This release addresses multiple security vulnerabilities identified in the previous version. We strongly recommend updating your installation immediately.

Security Patches​

  • Stored Cross-Site Scripting (XSS): We have resolved a vulnerability in the form editor that allowed users with editing permissions to inject malicious JavaScript into the Media field.
  • Open Redirect: We addressed an issue in the login logic where the from parameter was not properly validated, potentially allowing attackers to redirect users to malicious domains upon login.
  • HTML Injection: A vulnerability in the user creation process has been fixed. Previously, insufficient validation allowed HTML code to be injected into notification emails, presenting a potential phishing vector.
  • User Enumeration: We have standardized responses in the password reset feature to prevent attackers from determining which email addresses exist in the system.

Technical Disclosure​

Full technical details regarding these vulnerabilities will be published in the CVE database shortly. We will update this post with the corresponding CVE IDs as they become available.

Acknowledgments​

We appreciate the work of Jacopo Taccucci for his diligence and expertise in responsibly identifying and reporting these issues.

PHP & MySQL Version Requirements​

MachForm v29 requires the minimum version of PHP on your server to be at least PHP 8.1 and MySQL version at least MySQL 5.7. If you’re still using an older version, you’ll need to upgrade your PHP and/or MySQL version first.

Changelog​

  • Security: Resolved a Stored Cross-Site Scripting (XSS) vulnerability within the form builder interface.
  • Security: Patched an “Open Redirect” vulnerability in the authentication flow.
  • Security: Fixed an HTML injection vulnerability affecting the user creation process.
  • Security: Mitigated a User Enumeration vector on the password reset page.
  • Security: Enhanced password policies by enforcing strong passwords and implementing a strength meter on the reset page.
  • Security: Updated administrative workflows: Admins must now generate reset links rather than changing user passwords directly.
  • Performance: Integrated the OpenSpout library to optimize memory usage when exporting large Excel datasets.
  • Performance: Optimized the “Choice Limit” logic to eliminate processing delays on forms with a high volume of fields.
  • Compatibility: Resolved code deprecation warnings to ensure full compatibility with PHP 8.5.
  • Bugfix: Fixed an issue where Microsoft 365 refresh tokens failed to renew correctly after 90 days.

How to Update​

This update is provided at no cost for users with an active support contract. You can download the package from the .
Please follow the official upgrade guide here:
MachForm v27.0 - HTML Form Builder Online, PHP Form Creator

Decryption Key For :

v27.0
  • Feature: SSO (Single Sign-On) support for login authentication
  • Feature: Added option to throttle file uploads per IP address per hour
  • Security: Improved file uploads security against spam bots submissions
  • Bugfix: Grid widget can’t use relative date format for filtering
  • Bugfix: Importing form doesn’t include the approval status field
  • Bugfix: Languages not loaded correctly in merge tags
  • Bugfix: Missing “reply to” information when resending entry using confirmation email template
  • Bugfix: Smart folder using conditions from “Created Date” or “Last Entry Date” caused query error
  • Update: Added Ukrainian language and currency
  • Update: Added approver name into {approval_note} merge tag
  • Update: Updated axios library with the latest version (1.11.0)
Top