You can control which file types users are allowed to upload as multimedia attachments in Core+. File type checking is enforced on the server for all multimedia uploads, both through the web interface and the API. Only the file types specified in your configuration are accepted. If a user tries to upload a file type that isn't allowed, they see a clear error message.
Set the allowed file types
A configuration setting named "Multimedia allowed extensions" is available in Administration on the System tab.
In Administration, click Configuration.
Select the System tab.
Find the "Multimedia allowed extensions" setting.
Add the file extensions for the file types you want to allow.
⚠️ Warning: If the list of allowed types is left empty, no files can be uploaded through the standard file upload method.
📌 Note: This setting applies wherever multimedia is uploaded, for example in the Multimedia utility or when uploading a young person's photograph. Some file types are not permitted, to prevent you from accidentally uploading them.
📌 Note: Release reference — Core+ 26.1, item 2029931.
