Ninja Forms
Ninja Forms builds customizable WordPress forms using a visual form builder with fields, submissions, and form management tools.
Ninja Forms (ninja-forms) is a WordPress plugin with 74 published CVE records in this archive. The latest tracked vulnerability was published Sep 22, 2026; the highest published CVSS base score is 9.8.
ninja-formsCVE-2026-94504: Ninja Forms legacy textarea rendering exposes administrators to stored script
An anonymous non-rich-text textarea submission is stored and rendered without safe HTML encoding by the legacy submission editor in Ninja Forms 3.15.3. Attacker-controlled text can escape the textarea context and execute in the WordPress administrative origin when an Administrator opens the attacker-known direct submission URL. The exact field key and URL are not disclosed. Authoritative affected range: <= 3.15.3. Confirmed remediation: 3.15.4.
| Safe version |
|
||
|---|---|---|---|
| Sep 22, 2026 |
CVE-2026-94504
Ninja Forms legacy textarea rendering exposes administrators to stored script
An anonymous non-rich-text textarea submission is stored and rendered without safe HTML encoding by the legacy submission editor in Ninja Forms 3.15.3. Attacker-controlled text can escape the textarea context and execute in the WordPress administrative origin when an Administrator opens the attacker-known direct submission URL. The exact field key and URL are not disclosed. Authoritative affected range: <= 3.15.3. Confirmed remediation: 3.15.4.
|
3.15.4 |
CVE7.2
NVDPending
|
| Sep 22, 2026 |
CVE-2026-92438
Ninja Forms submissions store script for administrative review
An unauthenticated visitor submits malicious field values through a public form. Unescaped output on the administrative submission-edit screen then executes script in the browser of the privileged user reviewing that submission. The export identifies version 3.15.3 but does not disclose the particular field, rendering function or exact edit URL. Authoritative affected range: 3.15.3 to < 3.15.4. Confirmed remediation: 3.15.4.
|
3.15.4 |
CVE8.8
NVDPending
|
| Sep 22, 2026 |
CVE-2026-91827
Ninja Forms CSV export deserializes public submission values
An unauthenticated visitor supplies serialized input through a public form. The value is later deserialized when an administrator exports submissions to CSV. Harmful file operations or code execution require a suitable object gadget chain in another installed component; the export does not identify one or disclose the input field or deserialization function. Administrator export is an explicit prerequisite. Authoritative affected range: 3.15.3 to < 3.15.4. Confirmed remediation: 3.15.4.
|
3.15.4 |
CVE7.5
NVDPending
|
| Sep 09, 2026 |
CVE-2026-11363
Ninja Forms deserializes untrusted action settings during form import
Ninja Forms through 3.14.6 deserializes untrusted input during form import. An Administrator or higher-privileged user can import a crafted form; WPN_Helper::build_nf_cache() immediately calls $action->get_settings(), triggering PHP object injection without a further action. The advisory identifies no usable POP chain in Ninja Forms itself. File deletion, sensitive-data retrieval, or code execution depends on a suitable chain in another installed plugin or theme.
|
3.14.7 |
CVE6.6
NVDPending
|
| Sep 06, 2026 |
CVE-2026-80437
Ninja Forms permits unauthenticated shortcode execution through submitted values
Ninja Forms from 3.14.10 through versions before 3.15.2 substitutes request-derived values into content that it later processes for shortcodes. An unauthenticated submitter can therefore execute any shortcode registered on the site, with the resulting access or state changes determined by the available shortcodes.
|
3.15.2 |
CVE4.8
NVDPending
|
| Sep 05, 2026 |
CVE-2026-19769
Ninja Forms File Uploads permits unauthenticated same-origin script upload
Ninja Forms through 3.15.1, when the File Uploads add-on is active, mishandles an unmatched Repeater child type. An unauthenticated form submitter can route an unwhitelisted child entry into the upload handler and write attacker-supplied HTML containing JavaScript to a web-server-writable location, including the site root, where it runs from the site's origin.
|
See mitigation notes |
CVE7.2
NVDPending
|
| Sep 04, 2026 |
CVE-2026-80438
Ninja Forms treats a delegated plugin capability as site administration
Ninja Forms versions 3.14.0 through 3.15.1 accept a Ninja Forms-specific capability as equivalent to full site administration. A user explicitly granted that non-default capability can read settings and stored submissions, overwrite plugin configuration, and create or modify arbitrary posts and pages.
|
3.15.2 |
CVE5.9
NVDPending
|
| Aug 06, 2026 |
CVE-2026-15256
Ninja Forms permits unauthenticated shortcode execution through query-string defaults
Ninja Forms before 3.14.10 allows query-string data used to pre-populate a form field's default value to be processed as shortcode markup. When a configured form is embedded publicly, an unauthenticated attacker can place a registered shortcode in that query value and cause WordPress to execute it while rendering the form. Impact depends on registered shortcodes and may include data disclosure or side effects. The query parameter, field setting, rendering endpoint and PHP function are not disclosed.
|
3.14.10 |
CVE4.8
NVDPending
|
| Jul 24, 2026 |
CVE-2026-15663
Ninja Forms import metadata keys permit SQL injection
Ninja Forms through 3.14.9 lets an administrator import a crafted form whose attacker-controlled settings object contains malicious metadata keys. The normal import listener reads the uploaded file and the nf_batch_process action accepts the decoded import data after manage_options and nonce checks. Those keys can reach SQL assembled by _save_setting() in Model.php and the batch importer's insert_form_meta() while only the metadata values are escaped, allowing additional SQL to be appended to existing database queries. This record received deeper review despite its 4.9 score because the primitive is SQL injection.
|
3.14.10 |
CVE4.9
NVDPending
|
| Jul 21, 2026 |
CVE-2026-65052
Ninja Forms: A security weakness
Ninja Forms is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is < 3.14.9.
|
3.14.9 |
CVE8.7
NVDPending
|
| Jul 21, 2026 |
CVE-2026-65051
Ninja Forms: A security weakness
Ninja Forms is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is < 3.14.9.
|
3.14.9 |
CVE6.9
NVDPending
|
| Jul 21, 2026 |
CVE-2026-65050
Ninja Forms: A security weakness
Ninja Forms is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is < 3.14.9.
|
3.14.9 |
CVE7.1
NVDPending
|
| Jul 21, 2026 |
CVE-2026-65049
Ninja Forms: A security weakness
Ninja Forms is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is < 3.14.9.
|
3.14.9 |
CVE8.4
NVDPending
|
| Jul 21, 2026 |
CVE-2026-65048
Ninja Forms: Cross-site scripting
Ninja Forms is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is 3.10.4 to < 3.14.9.
|
3.14.9 |
CVE9.3
NVDPending
|
| Feb 10, 2026 |
CVE-2026-2268
Ninja Forms: Sensitive information exposure
Ninja Forms is affected by sensitive information exposure. The vulnerable path is reachable without authentication. Successful exploitation can disclose data that should not be available to the caller.
|
See mitigation notes |
CVE7.5
NVDPending
|
| Jan 02, 2026 |
CVE-2025-14072
Ninja Forms: A security weakness
Ninja Forms is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE5.3
NVDPending
|
| Dec 17, 2025 |
CVE-2025-11924
Ninja Forms – The Contact Form Builder That Grows With You: Broken access control
Ninja Forms – The Contact Form Builder That Grows With You is affected by broken access control. The vulnerable path is reachable without authentication. A successful request can reach data or an operation that should be restricted to another user or a more privileged role.
|
See mitigation notes |
CVE7.5
NVDPending
|
| Sep 27, 2025 |
CVE-2025-10499
Ninja Forms – The Contact Form Builder That Grows With You: Cross-site request forgery
Ninja Forms – The Contact Form Builder That Grows With You is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
|
See mitigation notes |
CVE4.3
NVDPending
|
| Sep 27, 2025 |
CVE-2025-10498
Ninja Forms – The Contact Form Builder That Grows With You: Cross-site request forgery
Ninja Forms – The Contact Form Builder That Grows With You is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
|
See mitigation notes |
CVE4.3
NVD5.4
|
| Sep 18, 2025 |
CVE-2025-9083
Ninja Forms: Code execution
Ninja Forms is affected by code execution. The vulnerable path is reachable without authentication. Successful exploitation can run attacker-controlled code in the WordPress hosting account.
|
See mitigation notes |
CVE9.8
NVDPending
|
| Jun 27, 2025 |
CVE-2025-5398
Ninja Forms – The Contact Form Builder That Grows With You: Cross-site scripting
Ninja Forms – The Contact Form Builder That Grows With You is affected by cross-site scripting. Exploitation requires an authenticated contributor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVD5.4
|
| May 19, 2025 |
CVE-2025-2561
Ninja Forms: Cross-site scripting
Ninja Forms is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE4.8
NVDPending
|
| May 19, 2025 |
CVE-2025-2560
Ninja Forms: Cross-site scripting
Ninja Forms is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE4.8
NVDPending
|
| May 19, 2025 |
CVE-2025-2524
Ninja Forms: Cross-site scripting
Ninja Forms is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE4.8
NVDPending
|
| Jan 30, 2025 |
CVE-2024-13470
Ninja Forms – The Contact Form Builder That Grows With You: Cross-site scripting
Ninja Forms – The Contact Form Builder That Grows With You is affected by cross-site scripting. Exploitation requires an authenticated contributor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVD5.4
|
| Dec 29, 2024 |
CVE-2024-12238
The Ninja Forms – The Contact Form Builder That Grows With You: A security weakness
The Ninja Forms – The Contact Form Builder That Grows With You is affected by a security weakness. Exploitation requires an authenticated subscriber account. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE6.3
NVDPending
|
| Dec 12, 2024 |
CVE-2024-11052
Ninja Forms – The Contact Form Builder That Grows With You: Cross-site scripting
Ninja Forms – The Contact Form Builder That Grows With You is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE7.2
NVD6.1
|
| Nov 19, 2024 |
CVE-2024-50515
Ninja Forms: Cross-site scripting
Ninja Forms is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE5.9
NVD4.8
|
| Nov 19, 2024 |
CVE-2024-50514
Ninja Forms: Cross-site scripting
Ninja Forms is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE5.9
NVD4.8
|
| Sep 25, 2024 |
CVE-2024-3866
Ninja Forms Contact Form: Cross-site scripting
Ninja Forms Contact Form is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE4.7
NVD6.1
|
| Sep 18, 2024 |
CVE-2024-43999
Ninja Forms: Cross-site scripting
Ninja Forms is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE5.9
NVD4.8
|
| Sep 02, 2024 |
CVE-2024-7354
Ninja Forms: Cross-site scripting
Ninja Forms is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.1
NVD6.1
|
| Aug 26, 2024 |
CVE-2024-39628
Ninja Forms: Cross-site request forgery
Ninja Forms is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
|
See mitigation notes |
CVE5.4
NVD8.8
|
| Jul 09, 2024 |
CVE-2024-37934
Ninja Forms: Code execution
Ninja Forms is affected by code execution. Exposure depends on how the affected operation is made reachable by the site. Successful exploitation can run attacker-controlled code in the WordPress hosting account.
|
See mitigation notes |
CVE5.4
NVD9.8
|
| Jun 19, 2024 |
CVE-2023-38393
Ninja Forms: A security weakness
Ninja Forms is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE7.6
NVD8.8
|
| Jun 19, 2024 |
CVE-2023-38386
Ninja Forms: A security weakness
Ninja Forms is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE7.6
NVD9.8
|
| Apr 17, 2024 |
CVE-2023-36505
Ninja Forms Contact Form: A security weakness
Ninja Forms Contact Form is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE6.8
NVD7.2
|
| Apr 11, 2024 |
CVE-2024-29220
Ninja Forms: Cross-site scripting
Ninja Forms is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.1
NVDPending
|
| Apr 11, 2024 |
CVE-2024-26019
Ninja Forms: Cross-site scripting
Ninja Forms is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE5.4
NVDPending
|
| Apr 11, 2024 |
CVE-2024-25572
Ninja Forms: Cross-site request forgery
Ninja Forms is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
|
See mitigation notes |
CVE8.8
NVDPending
|
| Mar 29, 2024 |
CVE-2024-2113
Ninja Forms Contact Form – The Drag and Drop Form Builder for: Cross-site request forgery
Ninja Forms Contact Form – The Drag and Drop Form Builder for is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
|
See mitigation notes |
CVE4.3
NVD4.3
|
| Mar 29, 2024 |
CVE-2024-2108
Ninja Forms Contact Form – The Drag and Drop Form Builder for: Cross-site scripting
Ninja Forms Contact Form – The Drag and Drop Form Builder for is affected by cross-site scripting. Exploitation requires an authenticated author account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE4.6
NVD5.4
|
| Feb 02, 2024 |
CVE-2024-0685
Ninja Forms Contact Form – The Drag and Drop Form Builder for: SQL injection
Ninja Forms Contact Form – The Drag and Drop Form Builder for is affected by SQL injection. The vulnerable path is reachable without authentication. A successful request can alter database queries and expose or modify WordPress data.
|
See mitigation notes |
CVE5.9
NVD9.8
|
| Dec 07, 2023 |
CVE-2023-35909
Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress: Denial of service
Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress is affected by denial of service. Exposure depends on how the affected operation is made reachable by the site. A successful request can exhaust or disrupt the affected operation and make site functionality unavailable.
|
See mitigation notes |
CVE5.3
NVD5.3
|
| Nov 06, 2023 |
CVE-2023-5530
Ninja Forms Contact Form: Cross-site scripting
Ninja Forms Contact Form is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVEPending
NVD4.8
|
| Jul 27, 2023 |
CVE-2023-37979
Ninja Forms: Cross-site scripting
Ninja Forms is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE7.1
NVD6.1
|
| May 15, 2023 |
CVE-2023-1835
Ninja Forms Contact Form: Cross-site scripting
Ninja Forms Contact Form is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.1
NVD6.1
|
| Sep 26, 2022 |
CVE-2022-2903
Ninja Forms Contact Form: Code execution
Ninja Forms Contact Form is affected by code execution. Exposure depends on how the affected operation is made reachable by the site. Successful exploitation can run attacker-controlled code in the WordPress hosting account.
|
See mitigation notes |
CVE7.2
NVD7.2
|
| Jul 04, 2022 |
CVE-2021-25066
Ninja Forms Contact Form: Cross-site scripting
Ninja Forms Contact Form is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVEPending
NVD4.8
|
| Jul 04, 2022 |
CVE-2021-25056
Ninja Forms Contact Form: Cross-site scripting
Ninja Forms Contact Form is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVEPending
NVD4.8
|
| Jun 16, 2022 |
CVE-2021-36827
Ninja Forms Contact Form: Cross-site scripting
Ninja Forms Contact Form is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE4.8
NVD4.8
|
| Nov 29, 2021 |
CVE-2021-24889
Ninja Forms Contact Form: SQL injection
Ninja Forms Contact Form is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
|
See mitigation notes |
CVEPending
NVD7.2
|
| Sep 22, 2021 |
CVE-2021-34648
Ninja Forms: A security weakness
Ninja Forms is affected by a security weakness. Exploitation requires an authenticated WordPress account. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE6.4
NVD4.3
|
| Sep 22, 2021 |
CVE-2021-34647
Ninja Forms: Sensitive information exposure
Ninja Forms is affected by sensitive information exposure. Exploitation requires an authenticated WordPress account. Successful exploitation can disclose data that should not be available to the caller.
|
See mitigation notes |
CVE6.5
NVD4.0
|
| Apr 05, 2021 |
CVE-2021-24166
wp_ajax_nf_oauth_disconnect from the Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress: A security weakness
wp_ajax_nf_oauth_disconnect from the Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVEPending
NVD5.4
|
| Apr 05, 2021 |
CVE-2021-24165
Ninja Forms Contact Form: An open redirect
Ninja Forms Contact Form is affected by an open redirect. Exposure depends on how the affected operation is made reachable by the site. A crafted link can redirect visitors from the trusted site to an attacker-controlled destination.
|
See mitigation notes |
CVEPending
NVD6.1
|
| Apr 05, 2021 |
CVE-2021-24164
Ninja Forms Contact Form: A security weakness
Ninja Forms Contact Form is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVEPending
NVD4.3
|
| Apr 05, 2021 |
CVE-2021-24163
SendWP Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress: A security weakness
SendWP Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVEPending
NVD8.8
|
| Jan 06, 2021 |
CVE-2020-36175
Ninja Forms: A security weakness
Ninja Forms is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVEPending
NVD5.3
|
| Jan 06, 2021 |
CVE-2020-36174
Ninja Forms: Cross-site request forgery
Ninja Forms is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
|
See mitigation notes |
CVEPending
NVD6.5
|
| Jan 06, 2021 |
CVE-2020-36173
Ninja Forms: A security weakness
Ninja Forms is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVEPending
NVD5.3
|
| Apr 29, 2020 |
CVE-2020-12462
Ninja Forms: Cross-site scripting
Ninja Forms is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVEPending
NVD6.1
|
| Feb 14, 2020 |
CVE-2020-8594
Ninja Forms: Cross-site scripting
Ninja Forms is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVEPending
NVD5.4
|
| Aug 22, 2019 |
CVE-2018-20981
Ninja Forms: A security weakness
Ninja Forms is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVEPending
NVD9.1
|
| Aug 22, 2019 |
CVE-2018-20980
Ninja Forms: A security weakness
Ninja Forms is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVEPending
NVD7.5
|
| Aug 22, 2019 |
CVE-2017-18574
Ninja Forms: A security weakness
Ninja Forms is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVEPending
NVD6.1
|
| Aug 14, 2019 |
CVE-2019-15025
Ninja Forms: SQL injection
Ninja Forms is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
|
See mitigation notes |
CVEPending
NVD9.8
|
| Dec 03, 2018 |
CVE-2018-19796
Ninja Forms: An open redirect
Ninja Forms is affected by an open redirect. Exposure depends on how the affected operation is made reachable by the site. A crafted link can redirect visitors from the trusted site to an attacker-controlled destination.
|
See mitigation notes |
CVEPending
NVD6.1
|
| Nov 15, 2018 |
CVE-2018-19287
Ninja Forms: Cross-site scripting
Ninja Forms is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVEPending
NVD6.1
|
| Sep 01, 2018 |
CVE-2018-16308
Ninja Forms: A security weakness
Ninja Forms is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVEPending
NVD8.6
|
| Feb 21, 2018 |
CVE-2018-7280
Ninja Forms: Cross-site scripting
Ninja Forms is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVEPending
NVD6.1
|
| May 14, 2016 |
CVE-2016-1209
Ninja Forms: Code execution
Ninja Forms is affected by code execution. Exposure depends on how the affected operation is made reachable by the site. Successful exploitation can run attacker-controlled code in the WordPress hosting account.
|
See mitigation notes |
CVEPending
NVD9.8
|
| Mar 05, 2015 |
CVE-2015-2220
Ninja Forms: Cross-site scripting
Ninja Forms is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVEPending
NVD4.3
|
| Mar 05, 2015 |
CVE-2014-9688
Ninja Forms: A security weakness
Ninja Forms is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVEPending
NVD7.5
|