
Report a bug
Request a feature
License portal
What's new
Report a security issue
Search the docs first
Check What's new
File a focused bug report
Flag license/billing issues separately
Report a security vulnerability
If you believe you found a flaw that could let someone bypass authentication, read another tenant’s submissions, execute code, or exfiltrate data without going through the product’s documented controls, treat it as a security report — not a regular bug.What belongs in a security report
Report issues in Flex Forms package code when they affect confidentiality, integrity, or availability — for example:- Authentication or authorization bypass in Studio, fill, embed, or Insights share surfaces
- Cross-tenant or cross-form data leakage in submissions, Contacts, or exports
- Server-side request forgery (SSRF) or unsafe outbound HTTP beyond the documented integration hardening
- Stored or reflected XSS delivered through fill output, embed parents, or shared Insights pages
- Bypass of answer encryption, access gates, or CAPTCHA when the bypass is in product code — not misconfiguration
- Privilege escalation around Studio permissions or Filament policy hooks shipped with the package
What is not a security report
Use the public bug template instead for:- Visual glitches, copy issues, or Studio UX bugs without a security impact
- License portal, billing, or domain activation problems → License Portal
- Integration failures caused by wrong API keys, field maps, or provider rate limits
- Hardening advice for your Laravel app (WAF, CSP, server headers) unless Flex Forms ships insecure defaults you can demonstrate
How to send a private report
Email us privately
Flex Forms security (or prefix your own subject with that phrase so it is routed correctly).Enterprise customers may also reach the priority channel agreed in your plan (email or private Slack) — still mark the message as a security report.Include enough context to reproduce
- Flex Forms version (
composer show janczakb/filament-flex-forms) - Laravel, PHP, Filament, Livewire versions
- Hostname / environment (production, staging, local — no need for secrets)
- Impact — who can exploit it, what data or actions are exposed
- Steps to reproduce — minimal, ordered list
- Proof of concept — curl, screenshots, or a short video if UI-related
- Your contact — email (and optional PGP fingerprint if you encrypt mail)
Wait for acknowledgment before public disclosure
What happens after you report
Supported versions
Security fixes are published for currently supported Flex Forms releases. CheckSECURITY.md on GitHub for the supported version table. If you are on an older major, upgrade via Upgrading before expecting a backport.
What's the expected response time?
What's the expected response time?
Where do I report a security issue?
Where do I report a security issue?
SECURITY.md.Can I get priority support?
Can I get priority support?
How much do plans cost?
How much do plans cost?