Ninja Forms
Ninja Forms is a WordPress component with 66 published CVE records in this archive. The latest tracked vulnerability was published Jul 24, 2026; the highest CVE/CNA score is 9.8.
ninja-formsCVE-2026-15663: Ninja Forms import metadata keys permit SQL injection
Ninja Forms through 3.14.9 lets an administrator import a crafted form whose attacker-controlled settings object contains malicious metadata keys. The normal import listener reads the uploaded file and the nf_batch_process action accepts the decoded import data after manage_options and nonce checks. Those keys can reach SQL assembled by _save_setting() in Model.php and the batch importer's insert_form_meta() while only the metadata values are escaped, allowing additional SQL to be appended to existing database queries. This record received deeper review despite its 4.9 score because the primitive is SQL injection.
| Safe version |
|
||
|---|---|---|---|
| Jul 24, 2026 |
CVE-2026-15663
Ninja Forms import metadata keys permit SQL injection
Ninja Forms through 3.14.9 lets an administrator import a crafted form whose attacker-controlled settings object contains malicious metadata keys. The normal import listener reads the uploaded file and the nf_batch_process action accepts the decoded import data after manage_options and nonce checks. Those keys can reach SQL assembled by _save_setting() in Model.php and the batch importer's insert_form_meta() while only the metadata values are escaped, allowing additional SQL to be appended to existing database queries. This record received deeper review despite its 4.9 score because the primitive is SQL injection.
|
3.14.10 |
CVE4.9
NVDPending
|
| Jul 21, 2026 |
CVE-2026-65052
Ninja Forms: A security weakness
Ninja Forms is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is < 3.14.9.
|
3.14.9 |
CVE8.7
NVDPending
|
| Jul 21, 2026 |
CVE-2026-65051
Ninja Forms: A security weakness
Ninja Forms is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is < 3.14.9.
|
3.14.9 |
CVE6.9
NVDPending
|
| Jul 21, 2026 |
CVE-2026-65050
Ninja Forms: A security weakness
Ninja Forms is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is < 3.14.9.
|
3.14.9 |
CVE7.1
NVDPending
|
| Jul 21, 2026 |
CVE-2026-65049
Ninja Forms: A security weakness
Ninja Forms is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is < 3.14.9.
|
3.14.9 |
CVE8.4
NVDPending
|
| Jul 21, 2026 |
CVE-2026-65048
Ninja Forms: Cross-site scripting
Ninja Forms is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is 3.10.4 to < 3.14.9.
|
3.14.9 |
CVE9.3
NVDPending
|
| Feb 10, 2026 |
CVE-2026-2268
Ninja Forms: Sensitive information exposure
Ninja Forms is affected by sensitive information exposure. The vulnerable path is reachable without authentication. Successful exploitation can disclose data that should not be available to the caller.
|
See mitigation notes |
CVE7.5
NVDPending
|
| Jan 02, 2026 |
CVE-2025-14072
Ninja Forms: A security weakness
Ninja Forms is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE5.3
NVDPending
|
| Dec 17, 2025 |
CVE-2025-11924
Ninja Forms – The Contact Form Builder That Grows With You: A security weakness
Ninja Forms – The Contact Form Builder That Grows With You is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE7.5
NVDPending
|
| Sep 27, 2025 |
CVE-2025-10499
Ninja Forms – The Contact Form Builder That Grows With You: Cross-site request forgery
Ninja Forms – The Contact Form Builder That Grows With You is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
|
See mitigation notes |
CVE4.3
NVDPending
|
| Sep 27, 2025 |
CVE-2025-10498
Ninja Forms – The Contact Form Builder That Grows With You: Cross-site request forgery
Ninja Forms – The Contact Form Builder That Grows With You is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
|
See mitigation notes |
CVE4.3
NVD5.4
|
| Sep 18, 2025 |
CVE-2025-9083
Ninja Forms: Code execution
Ninja Forms is affected by code execution. The vulnerable path is reachable without authentication. Successful exploitation can run attacker-controlled code in the WordPress hosting account.
|
See mitigation notes |
CVE9.8
NVDPending
|
| Jun 27, 2025 |
CVE-2025-5398
Ninja Forms – The Contact Form Builder That Grows With You: Cross-site scripting
Ninja Forms – The Contact Form Builder That Grows With You is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVD5.4
|
| May 19, 2025 |
CVE-2025-2561
Ninja Forms: Cross-site scripting
Ninja Forms is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE4.8
NVDPending
|
| May 19, 2025 |
CVE-2025-2560
Ninja Forms: Cross-site scripting
Ninja Forms is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE4.8
NVDPending
|
| May 19, 2025 |
CVE-2025-2524
Ninja Forms: Cross-site scripting
Ninja Forms is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE4.8
NVDPending
|
| Jan 30, 2025 |
CVE-2024-13470
Ninja Forms – The Contact Form Builder That Grows With You: Cross-site scripting
Ninja Forms – The Contact Form Builder That Grows With You is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVD5.4
|
| Dec 29, 2024 |
CVE-2024-12238
The Ninja Forms – The Contact Form Builder That Grows With You: A security weakness
The Ninja Forms – The Contact Form Builder That Grows With You is affected by a security weakness. Exploitation requires at least subscriber-level access. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE6.3
NVDPending
|
| Dec 12, 2024 |
CVE-2024-11052
Ninja Forms – The Contact Form Builder That Grows With You: Cross-site scripting
Ninja Forms – The Contact Form Builder That Grows With You is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE7.2
NVD6.1
|
| Nov 19, 2024 |
CVE-2024-50515
Ninja Forms: Cross-site scripting
Ninja Forms is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE5.9
NVD4.8
|
| Nov 19, 2024 |
CVE-2024-50514
Ninja Forms: Cross-site scripting
Ninja Forms is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE5.9
NVD4.8
|
| Sep 25, 2024 |
CVE-2024-3866
Ninja Forms Contact Form: Cross-site scripting
Ninja Forms Contact Form is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE4.7
NVD6.1
|
| Sep 18, 2024 |
CVE-2024-43999
Ninja Forms: Cross-site scripting
Ninja Forms is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE5.9
NVD4.8
|
| Sep 02, 2024 |
CVE-2024-7354
Ninja Forms: Cross-site scripting
Ninja Forms is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.1
NVD6.1
|
| Aug 26, 2024 |
CVE-2024-39628
Ninja Forms: Cross-site request forgery
Ninja Forms is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
|
See mitigation notes |
CVE5.4
NVD8.8
|
| Jul 09, 2024 |
CVE-2024-37934
Ninja Forms: Code execution
Ninja Forms is affected by code execution. Exposure depends on how the affected operation is made reachable by the site. Successful exploitation can run attacker-controlled code in the WordPress hosting account.
|
See mitigation notes |
CVE5.4
NVD9.8
|
| Jun 19, 2024 |
CVE-2023-38393
Ninja Forms: A security weakness
Ninja Forms is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE7.6
NVD8.8
|
| Jun 19, 2024 |
CVE-2023-38386
Ninja Forms: A security weakness
Ninja Forms is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE7.6
NVD9.8
|
| Apr 17, 2024 |
CVE-2023-36505
Ninja Forms Contact Form: A security weakness
Ninja Forms Contact Form is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE6.8
NVD7.2
|
| Apr 11, 2024 |
CVE-2024-29220
Ninja Forms: Cross-site scripting
Ninja Forms is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.1
NVDPending
|
| Apr 11, 2024 |
CVE-2024-26019
Ninja Forms: Cross-site scripting
Ninja Forms is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE5.4
NVDPending
|
| Apr 11, 2024 |
CVE-2024-25572
Ninja Forms: Cross-site request forgery
Ninja Forms is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
|
See mitigation notes |
CVE8.8
NVDPending
|
| Mar 29, 2024 |
CVE-2024-2113
Ninja Forms Contact Form – The Drag and Drop Form Builder for: Cross-site request forgery
Ninja Forms Contact Form – The Drag and Drop Form Builder for is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
|
See mitigation notes |
CVE4.3
NVD4.3
|
| Mar 29, 2024 |
CVE-2024-2108
Ninja Forms Contact Form – The Drag and Drop Form Builder for: Cross-site scripting
Ninja Forms Contact Form – The Drag and Drop Form Builder for is affected by cross-site scripting. Exploitation requires at least author-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE4.6
NVD5.4
|
| Feb 02, 2024 |
CVE-2024-0685
Ninja Forms Contact Form – The Drag and Drop Form Builder for: SQL injection
Ninja Forms Contact Form – The Drag and Drop Form Builder for is affected by SQL injection. The vulnerable path is reachable without authentication. A successful request can alter database queries and expose or modify WordPress data.
|
See mitigation notes |
CVE5.9
NVD9.8
|
| Dec 07, 2023 |
CVE-2023-35909
Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress: A security weakness
Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE5.3
NVD5.3
|
| Nov 06, 2023 |
CVE-2023-5530
Ninja Forms Contact Form: Cross-site scripting
Ninja Forms Contact Form is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE4.8
NVD4.8
|
| Jul 27, 2023 |
CVE-2023-37979
Ninja Forms: Cross-site scripting
Ninja Forms is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE7.1
NVD6.1
|
| May 15, 2023 |
CVE-2023-1835
Ninja Forms Contact Form: Cross-site scripting
Ninja Forms Contact Form is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.1
NVD6.1
|
| Sep 26, 2022 |
CVE-2022-2903
Ninja Forms Contact Form: Code execution
Ninja Forms Contact Form is affected by code execution. Exposure depends on how the affected operation is made reachable by the site. Successful exploitation can run attacker-controlled code in the WordPress hosting account.
|
See mitigation notes |
CVE7.2
NVD7.2
|
| Jul 04, 2022 |
CVE-2021-25066
Ninja Forms Contact Form: Cross-site scripting
Ninja Forms Contact Form is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE4.8
NVD4.8
|
| Jul 04, 2022 |
CVE-2021-25056
Ninja Forms Contact Form: Cross-site scripting
Ninja Forms Contact Form is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE4.8
NVD4.8
|
| Jun 16, 2022 |
CVE-2021-36827
Ninja Forms Contact Form: Cross-site scripting
Ninja Forms Contact Form is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE4.8
NVD4.8
|
| Nov 29, 2021 |
CVE-2021-24889
Ninja Forms Contact Form: SQL injection
Ninja Forms Contact Form is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
|
See mitigation notes |
CVE7.2
NVD7.2
|
| Sep 22, 2021 |
CVE-2021-34648
Ninja Forms: A security weakness
Ninja Forms is affected by a security weakness. Exploitation requires an authenticated WordPress account. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE6.4
NVD4.3
|
| Sep 22, 2021 |
CVE-2021-34647
Ninja Forms: Sensitive information exposure
Ninja Forms is affected by sensitive information exposure. Exploitation requires an authenticated WordPress account. Successful exploitation can disclose data that should not be available to the caller.
|
See mitigation notes |
CVE6.5
NVD4.0
|
| Apr 05, 2021 |
CVE-2021-24166
wp_ajax_nf_oauth_disconnect from the Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress: A security weakness
wp_ajax_nf_oauth_disconnect from the Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE5.4
NVD5.4
|
| Apr 05, 2021 |
CVE-2021-24165
Ninja Forms Contact Form: An open redirect
Ninja Forms Contact Form is affected by an open redirect. Exposure depends on how the affected operation is made reachable by the site. A crafted link can redirect visitors from the trusted site to an attacker-controlled destination.
|
See mitigation notes |
CVE6.1
NVD6.1
|
| Apr 05, 2021 |
CVE-2021-24164
Ninja Forms Contact Form: A security weakness
Ninja Forms Contact Form is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE4.3
NVD4.3
|
| Apr 05, 2021 |
CVE-2021-24163
SendWP Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress: A security weakness
SendWP Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE8.8
NVD8.8
|
| Jan 06, 2021 |
CVE-2020-36175
Ninja Forms: A security weakness
Ninja Forms is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE5.3
NVD5.3
|
| Jan 06, 2021 |
CVE-2020-36174
Ninja Forms: Cross-site request forgery
Ninja Forms is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
|
See mitigation notes |
CVE6.5
NVD6.5
|
| Jan 06, 2021 |
CVE-2020-36173
Ninja Forms: A security weakness
Ninja Forms is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE5.3
NVD5.3
|
| Apr 29, 2020 |
CVE-2020-12462
Ninja Forms: Cross-site scripting
Ninja Forms is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.1
NVD6.1
|
| Feb 14, 2020 |
CVE-2020-8594
Ninja Forms: Cross-site scripting
Ninja Forms is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE5.4
NVD5.4
|
| Aug 22, 2019 |
CVE-2018-20981
Ninja Forms: A security weakness
Ninja Forms is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE9.1
NVD9.1
|
| Aug 22, 2019 |
CVE-2018-20980
Ninja Forms: A security weakness
Ninja Forms is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE7.5
NVD7.5
|
| Aug 22, 2019 |
CVE-2017-18574
Ninja Forms: A security weakness
Ninja Forms is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE6.1
NVD6.1
|
| Aug 14, 2019 |
CVE-2019-15025
Ninja Forms: SQL injection
Ninja Forms is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
|
See mitigation notes |
CVE9.8
NVD9.8
|
| Dec 03, 2018 |
CVE-2018-19796
Ninja Forms: An open redirect
Ninja Forms is affected by an open redirect. Exposure depends on how the affected operation is made reachable by the site. A crafted link can redirect visitors from the trusted site to an attacker-controlled destination.
|
See mitigation notes |
CVE6.1
NVD6.1
|
| Nov 15, 2018 |
CVE-2018-19287
Ninja Forms: Cross-site scripting
Ninja Forms is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.1
NVD6.1
|
| Sep 01, 2018 |
CVE-2018-16308
Ninja Forms: A security weakness
Ninja Forms is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE8.6
NVD8.6
|
| Feb 21, 2018 |
CVE-2018-7280
Ninja Forms: Cross-site scripting
Ninja Forms is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.1
NVD6.1
|
| May 14, 2016 |
CVE-2016-1209
Ninja Forms: Code execution
Ninja Forms is affected by code execution. Exposure depends on how the affected operation is made reachable by the site. Successful exploitation can run attacker-controlled code in the WordPress hosting account.
|
See mitigation notes |
CVE9.8
NVD9.8
|
| Mar 05, 2015 |
CVE-2015-2220
Ninja Forms: Cross-site scripting
Ninja Forms is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE4.3
NVD4.3
|
| Mar 05, 2015 |
CVE-2014-9688
Ninja Forms: A security weakness
Ninja Forms is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE7.5
NVD7.5
|