NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
PyPI · #1179 most downloaded on PyPI
Form rendering, validation, and CSRF protection for Flask with WTForms.
Last release 5 months ago
23 Apr 2026
Release timing varies
gaps range from 3 months to 3.1 years
Most releases are documented
notes for 31 of 51 stable releases
1 version withdrawn
withdrawn after publishing
16 years old
52 releases · first in 2010
pre-commit autoupdate by @azmeuk in #607
Full Changelog: v1.2.2...v1.3.0
One column per quarter.
Released 2026-04-23
Don't read the whole uploaded files to know their size. 635
Stop support for Python 3.9. Start support for Python 3.14. 648
Migrate the project to uv. 649
Allow setting a nonce on ~flask_wtf.recaptcha.RecaptchaField (string or zero-argument callable) for nonce-based Content Security Policies. 312
Add csrf_meta_tag() helper and WTF_CSRF_META_NAME setting to render the CSRF token as an HTML <meta> tag.
Forward keyword arguments passed to the reCAPTCHA widget as HTML attributes on the captcha <div>, with the field id used as a default id. 353
Add apply_exemptions parameter to ~flask_wtf.csrf.CSRFProtect.protect so @csrf.exempt keeps working when validation is triggered manually. 419
Add RECAPTCHA_ENABLED setting. 509
Move the project to the pallets-eco organization. #602
Released 2024-10-20
Move the project to the pallets-eco organization. 602
Stop support for Python 3.8. Start support for Python 3.13. 603
Fix a bug introduced with #556 where file validators were editing the file fields content. #578
Released 2023-10-02
Fix a bug introduced with 556 where file validators were editing the file fields content. 578
Add field MultipleFileField . FileRequired , FileAllowed , FileSize now can be used to validate multiple files #556 #338
Released 2023-10-01
Add field MultipleFileField . FileRequired , FileAllowed , FileSize now can be used to validate multiple files #556 #338
Fixed Flask 2.3 deprecations of werkzeug.urls.url_encode and flask.Markup #565 #561
Released 2023-09-29
Fixed Flask 2.3 deprecations of werkzeug.urls.url_encode and flask.Markup #565 #561
Stop support for python 3.7 #574
Use pyproject.toml instead of setup.cfg #576
Fixed nested blueprint CSRF exemption #572
Fixed validate extra_validators parameter. #548
Released 2023-01-17
validate extra_validators parameter. #548validate_on_submit takes a extra_validators parameters #479
This release fixes compatibility with Werkzeug 2.1.
This release fixes compatibility with Werkzeug 2.1.
Released 2022-03-31
Update compatibility with the latest Werkzeug release. #511
Changes: https://github.com/lepture/flask-wtf/blob/v0.15.1/docs/changelog.rst
Released 2021-05-25
Add python_requires metadata to avoid installing on unsupported Python versions. #442
Changes: https://github.com/lepture/flask-wtf/blob/v0.15.0/docs/changelog.rst
Released 2021-05-24
Drop support for Python < 3.6. #416
FileSize validator. #307 , #365
Extra requirement email installs the email_validator package. #423
Fixed Flask 2.0 warnings. #434
Various documentation fixes. #315 , #321 , #335 , #344 , #386 , #400 , #404 , #420 , #437
Various CI fixes. #405 , #438
- Fix deprecated imports from werkzeug and collections .
Released 2020-02-06
Fix deprecated imports from werkzeug and collections .
- Fix bug where FlaskForm assumed meta argument was not None if it was passed. #278
Released 2017-01-10
Fix bug where FlaskForm assumed meta argument was not None if it was passed. #278
- FileField is no longer deprecated. The data is checked during processing and only set if it’s a valid file.
Released 2017-01-10
Fix bug where the file validators would incorrectly identify an empty file as valid data. #276 , #277
FileField is no longer deprecated. The data is checked during processing and only set if it’s a valid file.
has_file is deprecated; it’s now equivalent to bool(field.data) .
FileRequired and FileAllowed work with both the Flask-WTF and WTForms FileField classes.
The Optional validator now works with FileField .
- CsrfProtect.error_handler is deprecated. #264
Released 2017-01-06
Use ItsDangerous to sign CSRF tokens and check expiration instead of doing it ourselves. #264
All tokens are URL safe, removing the url_safe parameter from generate_csrf . #206
All tokens store a timestamp, which is checked in validate_csrf . The time_limit parameter of generate_csrf is removed.
Remove the app attribute from CsrfProtect , use current_app . #264
CsrfProtect protects the DELETE method by default. #264
The same CSRF token is generated for the lifetime of a request. It is exposed as g.csrf_token for use during testing. #227 , #264
CsrfProtect.error_handler is deprecated. #264
Handlers that return a response work in addition to those that raise an error. The behavior was not clear in previous docs.
#200 , #209 , #243 , #252
Use Form.Meta instead of deprecated SecureForm for CSRF (and everything else). #216 , #271
csrf_enabled parameter is still recognized but deprecated. All other attributes and methods from SecureForm are removed. #271
Provide WTF_CSRF_FIELD_NAME to configure the name of the CSRF token. #271
validate_csrf raises wtforms.ValidationError with specific messages instead of returning True or False . This breaks anything that was calling the method directly. #239 , #271
CSRF errors are logged as well as raised. #239
CsrfProtect is renamed to CSRFProtect . A deprecation warning is issued when using the old name. CsrfError is renamed to CSRFError without deprecation. #271
FileField is deprecated because it no longer provides functionality over the provided validators. Use wtforms.FileField directly. #272
- Deprecation warning for Form is shown during __init__ instead of immediately when subclassing. #262
Released 2016-10-6
Deprecation warning for Form is shown during init instead of immediately when subclassing. #262
Don’t use pkg_resources to get version, for compatibility with GAE. #261
- Form is renamed to FlaskForm in order to avoid name collision with WTForms’s base class. Using Form will show a deprecation warning. #250
Released 2016-09-29
Form is renamed to FlaskForm in order to avoid name collision with WTForms’s base class. Using Form will show a deprecation warning. #250
hidden_tag no longer wraps the hidden inputs in a hidden div. This is valid HTML5 and any modern HTML parser will behave correctly. #193 , #217
flask_wtf.html5 is deprecated. Import directly from wtforms.fields.html5 . #251
is_submitted is true for PATCH and DELETE in addition to POST and PUT . #187
generate_csrf takes a token_key parameter to specify the key stored in the session. #206
generate_csrf takes a url_safe parameter to allow the token to be used in URLs. #206
form.data can be accessed multiple times without raising an exception. #248
File extension with multiple parts ( .tar.gz ) can be used in the FileAllowed validator. #201
- Abstract protect_csrf() into a separate method.
Released 2015-07-09
Abstract protect_csrf() into a separate method.
Update reCAPTCHA configuration.
Fix reCAPTCHA error handle.
- Use the new reCAPTCHA API. #164
Released 2015-01-21
Use the new reCAPTCHA API. #164
- Add configuration: WTF_CSRF_HEADERS . #159
Released 2014-11-16
Add configuration: WTF_CSRF_HEADERS . #159
Support customize hidden tags. #150
And many more bug fixes.
- Update translation for reCaptcha. #146
Released 2014-09-03
Update translation for reCaptcha. #146
- Update RECAPTCHA_API_SERVER_URL . #145
Released 2014-08-26
Update RECAPTCHA_API_SERVER_URL . #145
Update requirement Werkzeug >= 0.9.5.
Fix CsrfProtect exempt for blueprints. #143
- Add configuration: WTF_CSRF_METHODS .
Released 2014-07-16
Add configuration: WTF_CSRF_METHODS .
Support WTForms 2.0 now.
Fix CSRF validation without time limit ( time_limit=False ).
csrf_exempt supports blueprint. #111
- csrf_token for all template types. #112
Released 2014-03-21
csrf_token for all template types. #112
Make FileRequired a subclass of InputRequired . #108
- Bugfix for csrf module when form has a prefix.
Released 2013-12-20
Bugfix for csrf module when form has a prefix.
Compatible support for WTForms 2.
Remove file API for FileField
- Fix validation of recaptcha when app in testing mode. #89
Released 2013-10-02
Fix validation of recaptcha when app in testing mode. #89
Bugfix for csrf module. #91
- No DateInput widget in HTML5. #81
Released 2013-09-11
Upgrade WTForms to 1.0.5.
No lazy string for i18n. #77
No DateInput widget in HTML5. #81
PUT and PATCH for CSRF. #86
- Compatibility with Flask < 0.10. #82
Released 2013-08-21
Compatibility with Flask < 0.10. #82
- Use default HTML5 widgets and fields provided by WTForms.
Released 2013-08-15
Add i18n support. #65
Use default HTML5 widgets and fields provided by WTForms.
Python 3.3+ support.
Redesign form, replace SessionSecureForm .
CSRF protection solution.
Drop WTForms imports.
Fix recaptcha i18n support.
Fix recaptcha validator for Python 3.
More test cases, it’s 90%+ coverage now.
Redesign documentation.
- Recaptcha Validator now returns provided message. #66
Released 2013-03-28
Recaptcha Validator now returns provided message. #66
Minor doc fixes.
Fixed issue with tests barking because of nose/multiprocessing issue.
- Update documentation to indicate pending deprecation of WTForms namespace facade.
Released 2013-03-13
Update documentation to indicate pending deprecation of WTForms namespace facade.
PEP8 fixes. #64
Fix Recaptcha widget. #49
Initial development by Dan Jacob and Ron Duplain.
Initial development by Dan Jacob and Ron Duplain.
Changes
Version 1.2.0
Version 1.1.2
Version 1.1.1
Version 1.1.0
Version 1.0.1
Version 1.0.0
Version 0.15.1
Version 0.15.0
Version 0.14.3
Version 0.14.2
Version 0.14.1
Version 0.14
Version 0.13.1
Version 0.13
Version 0.12
Version 0.11
Version 0.10.3
Version 0.10.2
Version 0.10.1
Version 0.10.0
Version 0.9.5
Version 0.9.4
Version 0.9.3
Version 0.9.2
Version 0.9.1
Version 0.9.0
Version 0.8.4
Version 0.8.3
Version 0.8.2 and prior
© Copyright 2010 WTForms. Created using Sphinx 4.5.0.
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →