← WordPress Vulnerabilities
WordPress security by component

Ninja Forms

Ninja Forms builds customizable WordPress forms using a visual form builder with fields, submissions, and form management tools.

Ninja Forms (ninja-forms) is a WordPress plugin with 74 published CVE records in this archive. The latest tracked vulnerability was published Sep 22, 2026; the highest published CVSS base score is 9.8.

Plugin slug: ninja-forms

CVE-2026-94504: Ninja Forms legacy textarea rendering exposes administrators to stored script

An anonymous non-rich-text textarea submission is stored and rendered without safe HTML encoding by the legacy submission editor in Ninja Forms 3.15.3. Attacker-controlled text can escape the textarea context and execute in the WordPress administrative origin when an Administrator opens the attacker-known direct submission URL. The exact field key and URL are not disclosed. Authoritative affected range: <= 3.15.3. Confirmed remediation: 3.15.4.

PublishedSep 22, 2026
Known safe version3.15.4
Published vulnerabilities for ninja-forms
Safe version
Sep 22, 2026 CVE-2026-94504
Ninja Forms legacy textarea rendering exposes administrators to stored script
An anonymous non-rich-text textarea submission is stored and rendered without safe HTML encoding by the legacy submission editor in Ninja Forms 3.15.3. Attacker-controlled text can escape the textarea context and execute in the WordPress administrative origin when an Administrator opens the attacker-known direct submission URL. The exact field key and URL are not disclosed. Authoritative affected range: <= 3.15.3. Confirmed remediation: 3.15.4.
3.15.4
CVE7.2
NVDPending
Sep 22, 2026 CVE-2026-92438
Ninja Forms submissions store script for administrative review
An unauthenticated visitor submits malicious field values through a public form. Unescaped output on the administrative submission-edit screen then executes script in the browser of the privileged user reviewing that submission. The export identifies version 3.15.3 but does not disclose the particular field, rendering function or exact edit URL. Authoritative affected range: 3.15.3 to < 3.15.4. Confirmed remediation: 3.15.4.
3.15.4
CVE8.8
NVDPending
Sep 22, 2026 CVE-2026-91827
Ninja Forms CSV export deserializes public submission values
An unauthenticated visitor supplies serialized input through a public form. The value is later deserialized when an administrator exports submissions to CSV. Harmful file operations or code execution require a suitable object gadget chain in another installed component; the export does not identify one or disclose the input field or deserialization function. Administrator export is an explicit prerequisite. Authoritative affected range: 3.15.3 to < 3.15.4. Confirmed remediation: 3.15.4.
3.15.4
CVE7.5
NVDPending
Sep 09, 2026 CVE-2026-11363
Ninja Forms deserializes untrusted action settings during form import
Ninja Forms through 3.14.6 deserializes untrusted input during form import. An Administrator or higher-privileged user can import a crafted form; WPN_Helper::build_nf_cache() immediately calls $action->get_settings(), triggering PHP object injection without a further action. The advisory identifies no usable POP chain in Ninja Forms itself. File deletion, sensitive-data retrieval, or code execution depends on a suitable chain in another installed plugin or theme.
3.14.7
CVE6.6
NVDPending
Sep 06, 2026 CVE-2026-80437
Ninja Forms permits unauthenticated shortcode execution through submitted values
Ninja Forms from 3.14.10 through versions before 3.15.2 substitutes request-derived values into content that it later processes for shortcodes. An unauthenticated submitter can therefore execute any shortcode registered on the site, with the resulting access or state changes determined by the available shortcodes.
3.15.2
CVE4.8
NVDPending
Sep 05, 2026 CVE-2026-19769
Ninja Forms File Uploads permits unauthenticated same-origin script upload
Ninja Forms through 3.15.1, when the File Uploads add-on is active, mishandles an unmatched Repeater child type. An unauthenticated form submitter can route an unwhitelisted child entry into the upload handler and write attacker-supplied HTML containing JavaScript to a web-server-writable location, including the site root, where it runs from the site's origin.
See mitigation notes
CVE7.2
NVDPending
Sep 04, 2026 CVE-2026-80438
Ninja Forms treats a delegated plugin capability as site administration
Ninja Forms versions 3.14.0 through 3.15.1 accept a Ninja Forms-specific capability as equivalent to full site administration. A user explicitly granted that non-default capability can read settings and stored submissions, overwrite plugin configuration, and create or modify arbitrary posts and pages.
3.15.2
CVE5.9
NVDPending
Aug 06, 2026 CVE-2026-15256
Ninja Forms permits unauthenticated shortcode execution through query-string defaults
Ninja Forms before 3.14.10 allows query-string data used to pre-populate a form field's default value to be processed as shortcode markup. When a configured form is embedded publicly, an unauthenticated attacker can place a registered shortcode in that query value and cause WordPress to execute it while rendering the form. Impact depends on registered shortcodes and may include data disclosure or side effects. The query parameter, field setting, rendering endpoint and PHP function are not disclosed.
3.14.10
CVE4.8
NVDPending
Jul 24, 2026 CVE-2026-15663
Ninja Forms import metadata keys permit SQL injection
Ninja Forms through 3.14.9 lets an administrator import a crafted form whose attacker-controlled settings object contains malicious metadata keys. The normal import listener reads the uploaded file and the nf_batch_process action accepts the decoded import data after manage_options and nonce checks. Those keys can reach SQL assembled by _save_setting() in Model.php and the batch importer's insert_form_meta() while only the metadata values are escaped, allowing additional SQL to be appended to existing database queries. This record received deeper review despite its 4.9 score because the primitive is SQL injection.
3.14.10
CVE4.9
NVDPending
Jul 21, 2026 CVE-2026-65052
Ninja Forms: A security weakness
Ninja Forms is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is < 3.14.9.
3.14.9
CVE8.7
NVDPending
Jul 21, 2026 CVE-2026-65051
Ninja Forms: A security weakness
Ninja Forms is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is < 3.14.9.
3.14.9
CVE6.9
NVDPending
Jul 21, 2026 CVE-2026-65050
Ninja Forms: A security weakness
Ninja Forms is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is < 3.14.9.
3.14.9
CVE7.1
NVDPending
Jul 21, 2026 CVE-2026-65049
Ninja Forms: A security weakness
Ninja Forms is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is < 3.14.9.
3.14.9
CVE8.4
NVDPending
Jul 21, 2026 CVE-2026-65048
Ninja Forms: Cross-site scripting
Ninja Forms is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is 3.10.4 to < 3.14.9.
3.14.9
CVE9.3
NVDPending
Feb 10, 2026 CVE-2026-2268
Ninja Forms: Sensitive information exposure
Ninja Forms is affected by sensitive information exposure. The vulnerable path is reachable without authentication. Successful exploitation can disclose data that should not be available to the caller.
See mitigation notes
CVE7.5
NVDPending
Jan 02, 2026 CVE-2025-14072
Ninja Forms: A security weakness
Ninja Forms is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.3
NVDPending
Dec 17, 2025 CVE-2025-11924
Ninja Forms – The Contact Form Builder That Grows With You: Broken access control
Ninja Forms – The Contact Form Builder That Grows With You is affected by broken access control. The vulnerable path is reachable without authentication. A successful request can reach data or an operation that should be restricted to another user or a more privileged role.
See mitigation notes
CVE7.5
NVDPending
Sep 27, 2025 CVE-2025-10499
Ninja Forms – The Contact Form Builder That Grows With You: Cross-site request forgery
Ninja Forms – The Contact Form Builder That Grows With You is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE4.3
NVDPending
Sep 27, 2025 CVE-2025-10498
Ninja Forms – The Contact Form Builder That Grows With You: Cross-site request forgery
Ninja Forms – The Contact Form Builder That Grows With You is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE4.3
NVD5.4
Sep 18, 2025 CVE-2025-9083
Ninja Forms: Code execution
Ninja Forms is affected by code execution. The vulnerable path is reachable without authentication. Successful exploitation can run attacker-controlled code in the WordPress hosting account.
See mitigation notes
CVE9.8
NVDPending
Jun 27, 2025 CVE-2025-5398
Ninja Forms – The Contact Form Builder That Grows With You: Cross-site scripting
Ninja Forms – The Contact Form Builder That Grows With You is affected by cross-site scripting. Exploitation requires an authenticated contributor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
May 19, 2025 CVE-2025-2561
Ninja Forms: Cross-site scripting
Ninja Forms is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE4.8
NVDPending
May 19, 2025 CVE-2025-2560
Ninja Forms: Cross-site scripting
Ninja Forms is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE4.8
NVDPending
May 19, 2025 CVE-2025-2524
Ninja Forms: Cross-site scripting
Ninja Forms is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE4.8
NVDPending
Jan 30, 2025 CVE-2024-13470
Ninja Forms – The Contact Form Builder That Grows With You: Cross-site scripting
Ninja Forms – The Contact Form Builder That Grows With You is affected by cross-site scripting. Exploitation requires an authenticated contributor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
Dec 29, 2024 CVE-2024-12238
The Ninja Forms – The Contact Form Builder That Grows With You: A security weakness
The Ninja Forms – The Contact Form Builder That Grows With You is affected by a security weakness. Exploitation requires an authenticated subscriber account. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE6.3
NVDPending
Dec 12, 2024 CVE-2024-11052
Ninja Forms – The Contact Form Builder That Grows With You: Cross-site scripting
Ninja Forms – The Contact Form Builder That Grows With You is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE7.2
NVD6.1
Nov 19, 2024 CVE-2024-50515
Ninja Forms: Cross-site scripting
Ninja Forms is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE5.9
NVD4.8
Nov 19, 2024 CVE-2024-50514
Ninja Forms: Cross-site scripting
Ninja Forms is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE5.9
NVD4.8
Sep 25, 2024 CVE-2024-3866
Ninja Forms Contact Form: Cross-site scripting
Ninja Forms Contact Form is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE4.7
NVD6.1
Sep 18, 2024 CVE-2024-43999
Ninja Forms: Cross-site scripting
Ninja Forms is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE5.9
NVD4.8
Sep 02, 2024 CVE-2024-7354
Ninja Forms: Cross-site scripting
Ninja Forms is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.1
NVD6.1
Aug 26, 2024 CVE-2024-39628
Ninja Forms: Cross-site request forgery
Ninja Forms is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE5.4
NVD8.8
Jul 09, 2024 CVE-2024-37934
Ninja Forms: Code execution
Ninja Forms is affected by code execution. Exposure depends on how the affected operation is made reachable by the site. Successful exploitation can run attacker-controlled code in the WordPress hosting account.
See mitigation notes
CVE5.4
NVD9.8
Jun 19, 2024 CVE-2023-38393
Ninja Forms: A security weakness
Ninja Forms is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE7.6
NVD8.8
Jun 19, 2024 CVE-2023-38386
Ninja Forms: A security weakness
Ninja Forms is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE7.6
NVD9.8
Apr 17, 2024 CVE-2023-36505
Ninja Forms Contact Form: A security weakness
Ninja Forms Contact Form is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE6.8
NVD7.2
Apr 11, 2024 CVE-2024-29220
Ninja Forms: Cross-site scripting
Ninja Forms is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.1
NVDPending
Apr 11, 2024 CVE-2024-26019
Ninja Forms: Cross-site scripting
Ninja Forms is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE5.4
NVDPending
Apr 11, 2024 CVE-2024-25572
Ninja Forms: Cross-site request forgery
Ninja Forms is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE8.8
NVDPending
Mar 29, 2024 CVE-2024-2113
Ninja Forms Contact Form – The Drag and Drop Form Builder for: Cross-site request forgery
Ninja Forms Contact Form – The Drag and Drop Form Builder for is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE4.3
NVD4.3
Mar 29, 2024 CVE-2024-2108
Ninja Forms Contact Form – The Drag and Drop Form Builder for: Cross-site scripting
Ninja Forms Contact Form – The Drag and Drop Form Builder for is affected by cross-site scripting. Exploitation requires an authenticated author account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE4.6
NVD5.4
Feb 02, 2024 CVE-2024-0685
Ninja Forms Contact Form – The Drag and Drop Form Builder for: SQL injection
Ninja Forms Contact Form – The Drag and Drop Form Builder for is affected by SQL injection. The vulnerable path is reachable without authentication. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE5.9
NVD9.8
Dec 07, 2023 CVE-2023-35909
Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress: Denial of service
Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress is affected by denial of service. Exposure depends on how the affected operation is made reachable by the site. A successful request can exhaust or disrupt the affected operation and make site functionality unavailable.
See mitigation notes
CVE5.3
NVD5.3
Nov 06, 2023 CVE-2023-5530
Ninja Forms Contact Form: Cross-site scripting
Ninja Forms Contact Form is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVEPending
NVD4.8
Jul 27, 2023 CVE-2023-37979
Ninja Forms: Cross-site scripting
Ninja Forms is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE7.1
NVD6.1
May 15, 2023 CVE-2023-1835
Ninja Forms Contact Form: Cross-site scripting
Ninja Forms Contact Form is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.1
NVD6.1
Sep 26, 2022 CVE-2022-2903
Ninja Forms Contact Form: Code execution
Ninja Forms Contact Form is affected by code execution. Exposure depends on how the affected operation is made reachable by the site. Successful exploitation can run attacker-controlled code in the WordPress hosting account.
See mitigation notes
CVE7.2
NVD7.2
Jul 04, 2022 CVE-2021-25066
Ninja Forms Contact Form: Cross-site scripting
Ninja Forms Contact Form is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVEPending
NVD4.8
Jul 04, 2022 CVE-2021-25056
Ninja Forms Contact Form: Cross-site scripting
Ninja Forms Contact Form is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVEPending
NVD4.8
Jun 16, 2022 CVE-2021-36827
Ninja Forms Contact Form: Cross-site scripting
Ninja Forms Contact Form is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE4.8
NVD4.8
Nov 29, 2021 CVE-2021-24889
Ninja Forms Contact Form: SQL injection
Ninja Forms Contact Form is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVEPending
NVD7.2
Sep 22, 2021 CVE-2021-34648
Ninja Forms: A security weakness
Ninja Forms is affected by a security weakness. Exploitation requires an authenticated WordPress account. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE6.4
NVD4.3
Sep 22, 2021 CVE-2021-34647
Ninja Forms: Sensitive information exposure
Ninja Forms is affected by sensitive information exposure. Exploitation requires an authenticated WordPress account. Successful exploitation can disclose data that should not be available to the caller.
See mitigation notes
CVE6.5
NVD4.0
Apr 05, 2021 CVE-2021-24166
wp_ajax_nf_oauth_disconnect from the Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress: A security weakness
wp_ajax_nf_oauth_disconnect from the Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVEPending
NVD5.4
Apr 05, 2021 CVE-2021-24165
Ninja Forms Contact Form: An open redirect
Ninja Forms Contact Form is affected by an open redirect. Exposure depends on how the affected operation is made reachable by the site. A crafted link can redirect visitors from the trusted site to an attacker-controlled destination.
See mitigation notes
CVEPending
NVD6.1
Apr 05, 2021 CVE-2021-24164
Ninja Forms Contact Form: A security weakness
Ninja Forms Contact Form is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVEPending
NVD4.3
Apr 05, 2021 CVE-2021-24163
SendWP Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress: A security weakness
SendWP Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVEPending
NVD8.8
Jan 06, 2021 CVE-2020-36175
Ninja Forms: A security weakness
Ninja Forms is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVEPending
NVD5.3
Jan 06, 2021 CVE-2020-36174
Ninja Forms: Cross-site request forgery
Ninja Forms is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVEPending
NVD6.5
Jan 06, 2021 CVE-2020-36173
Ninja Forms: A security weakness
Ninja Forms is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVEPending
NVD5.3
Apr 29, 2020 CVE-2020-12462
Ninja Forms: Cross-site scripting
Ninja Forms is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVEPending
NVD6.1
Feb 14, 2020 CVE-2020-8594
Ninja Forms: Cross-site scripting
Ninja Forms is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVEPending
NVD5.4
Aug 22, 2019 CVE-2018-20981
Ninja Forms: A security weakness
Ninja Forms is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVEPending
NVD9.1
Aug 22, 2019 CVE-2018-20980
Ninja Forms: A security weakness
Ninja Forms is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVEPending
NVD7.5
Aug 22, 2019 CVE-2017-18574
Ninja Forms: A security weakness
Ninja Forms is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVEPending
NVD6.1
Aug 14, 2019 CVE-2019-15025
Ninja Forms: SQL injection
Ninja Forms is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVEPending
NVD9.8
Dec 03, 2018 CVE-2018-19796
Ninja Forms: An open redirect
Ninja Forms is affected by an open redirect. Exposure depends on how the affected operation is made reachable by the site. A crafted link can redirect visitors from the trusted site to an attacker-controlled destination.
See mitigation notes
CVEPending
NVD6.1
Nov 15, 2018 CVE-2018-19287
Ninja Forms: Cross-site scripting
Ninja Forms is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVEPending
NVD6.1
Sep 01, 2018 CVE-2018-16308
Ninja Forms: A security weakness
Ninja Forms is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVEPending
NVD8.6
Feb 21, 2018 CVE-2018-7280
Ninja Forms: Cross-site scripting
Ninja Forms is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVEPending
NVD6.1
May 14, 2016 CVE-2016-1209
Ninja Forms: Code execution
Ninja Forms is affected by code execution. Exposure depends on how the affected operation is made reachable by the site. Successful exploitation can run attacker-controlled code in the WordPress hosting account.
See mitigation notes
CVEPending
NVD9.8
Mar 05, 2015 CVE-2015-2220
Ninja Forms: Cross-site scripting
Ninja Forms is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVEPending
NVD4.3
Mar 05, 2015 CVE-2014-9688
Ninja Forms: A security weakness
Ninja Forms is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVEPending
NVD7.5