← WordPress Vulnerabilities
WordPress security by component

Ninja Forms

Ninja Forms is a WordPress component with 66 published CVE records in this archive. The latest tracked vulnerability was published Jul 24, 2026; the highest CVE/CNA score is 9.8.

Plugin slug: ninja-forms

CVE-2026-15663: Ninja Forms import metadata keys permit SQL injection

Ninja Forms through 3.14.9 lets an administrator import a crafted form whose attacker-controlled settings object contains malicious metadata keys. The normal import listener reads the uploaded file and the nf_batch_process action accepts the decoded import data after manage_options and nonce checks. Those keys can reach SQL assembled by _save_setting() in Model.php and the batch importer's insert_form_meta() while only the metadata values are escaped, allowing additional SQL to be appended to existing database queries. This record received deeper review despite its 4.9 score because the primitive is SQL injection.

PublishedJul 24, 2026
Known safe version3.14.10
Safe version
Jul 24, 2026 CVE-2026-15663
Ninja Forms import metadata keys permit SQL injection
Ninja Forms through 3.14.9 lets an administrator import a crafted form whose attacker-controlled settings object contains malicious metadata keys. The normal import listener reads the uploaded file and the nf_batch_process action accepts the decoded import data after manage_options and nonce checks. Those keys can reach SQL assembled by _save_setting() in Model.php and the batch importer's insert_form_meta() while only the metadata values are escaped, allowing additional SQL to be appended to existing database queries. This record received deeper review despite its 4.9 score because the primitive is SQL injection.
3.14.10
CVE4.9
NVDPending
Jul 21, 2026 CVE-2026-65052
Ninja Forms: A security weakness
Ninja Forms is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is < 3.14.9.
3.14.9
CVE8.7
NVDPending
Jul 21, 2026 CVE-2026-65051
Ninja Forms: A security weakness
Ninja Forms is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is < 3.14.9.
3.14.9
CVE6.9
NVDPending
Jul 21, 2026 CVE-2026-65050
Ninja Forms: A security weakness
Ninja Forms is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is < 3.14.9.
3.14.9
CVE7.1
NVDPending
Jul 21, 2026 CVE-2026-65049
Ninja Forms: A security weakness
Ninja Forms is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is < 3.14.9.
3.14.9
CVE8.4
NVDPending
Jul 21, 2026 CVE-2026-65048
Ninja Forms: Cross-site scripting
Ninja Forms is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is 3.10.4 to < 3.14.9.
3.14.9
CVE9.3
NVDPending
Feb 10, 2026 CVE-2026-2268
Ninja Forms: Sensitive information exposure
Ninja Forms is affected by sensitive information exposure. The vulnerable path is reachable without authentication. Successful exploitation can disclose data that should not be available to the caller.
See mitigation notes
CVE7.5
NVDPending
Jan 02, 2026 CVE-2025-14072
Ninja Forms: A security weakness
Ninja Forms is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.3
NVDPending
Dec 17, 2025 CVE-2025-11924
Ninja Forms – The Contact Form Builder That Grows With You: A security weakness
Ninja Forms – The Contact Form Builder That Grows With You is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE7.5
NVDPending
Sep 27, 2025 CVE-2025-10499
Ninja Forms – The Contact Form Builder That Grows With You: Cross-site request forgery
Ninja Forms – The Contact Form Builder That Grows With You is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE4.3
NVDPending
Sep 27, 2025 CVE-2025-10498
Ninja Forms – The Contact Form Builder That Grows With You: Cross-site request forgery
Ninja Forms – The Contact Form Builder That Grows With You is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE4.3
NVD5.4
Sep 18, 2025 CVE-2025-9083
Ninja Forms: Code execution
Ninja Forms is affected by code execution. The vulnerable path is reachable without authentication. Successful exploitation can run attacker-controlled code in the WordPress hosting account.
See mitigation notes
CVE9.8
NVDPending
Jun 27, 2025 CVE-2025-5398
Ninja Forms – The Contact Form Builder That Grows With You: Cross-site scripting
Ninja Forms – The Contact Form Builder That Grows With You is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
May 19, 2025 CVE-2025-2561
Ninja Forms: Cross-site scripting
Ninja Forms is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE4.8
NVDPending
May 19, 2025 CVE-2025-2560
Ninja Forms: Cross-site scripting
Ninja Forms is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE4.8
NVDPending
May 19, 2025 CVE-2025-2524
Ninja Forms: Cross-site scripting
Ninja Forms is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE4.8
NVDPending
Jan 30, 2025 CVE-2024-13470
Ninja Forms – The Contact Form Builder That Grows With You: Cross-site scripting
Ninja Forms – The Contact Form Builder That Grows With You is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
Dec 29, 2024 CVE-2024-12238
The Ninja Forms – The Contact Form Builder That Grows With You: A security weakness
The Ninja Forms – The Contact Form Builder That Grows With You is affected by a security weakness. Exploitation requires at least subscriber-level access. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE6.3
NVDPending
Dec 12, 2024 CVE-2024-11052
Ninja Forms – The Contact Form Builder That Grows With You: Cross-site scripting
Ninja Forms – The Contact Form Builder That Grows With You is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE7.2
NVD6.1
Nov 19, 2024 CVE-2024-50515
Ninja Forms: Cross-site scripting
Ninja Forms is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE5.9
NVD4.8
Nov 19, 2024 CVE-2024-50514
Ninja Forms: Cross-site scripting
Ninja Forms is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE5.9
NVD4.8
Sep 25, 2024 CVE-2024-3866
Ninja Forms Contact Form: Cross-site scripting
Ninja Forms Contact Form is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE4.7
NVD6.1
Sep 18, 2024 CVE-2024-43999
Ninja Forms: Cross-site scripting
Ninja Forms is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE5.9
NVD4.8
Sep 02, 2024 CVE-2024-7354
Ninja Forms: Cross-site scripting
Ninja Forms is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.1
NVD6.1
Aug 26, 2024 CVE-2024-39628
Ninja Forms: Cross-site request forgery
Ninja Forms is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE5.4
NVD8.8
Jul 09, 2024 CVE-2024-37934
Ninja Forms: Code execution
Ninja Forms is affected by code execution. Exposure depends on how the affected operation is made reachable by the site. Successful exploitation can run attacker-controlled code in the WordPress hosting account.
See mitigation notes
CVE5.4
NVD9.8
Jun 19, 2024 CVE-2023-38393
Ninja Forms: A security weakness
Ninja Forms is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE7.6
NVD8.8
Jun 19, 2024 CVE-2023-38386
Ninja Forms: A security weakness
Ninja Forms is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE7.6
NVD9.8
Apr 17, 2024 CVE-2023-36505
Ninja Forms Contact Form: A security weakness
Ninja Forms Contact Form is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE6.8
NVD7.2
Apr 11, 2024 CVE-2024-29220
Ninja Forms: Cross-site scripting
Ninja Forms is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.1
NVDPending
Apr 11, 2024 CVE-2024-26019
Ninja Forms: Cross-site scripting
Ninja Forms is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE5.4
NVDPending
Apr 11, 2024 CVE-2024-25572
Ninja Forms: Cross-site request forgery
Ninja Forms is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE8.8
NVDPending
Mar 29, 2024 CVE-2024-2113
Ninja Forms Contact Form – The Drag and Drop Form Builder for: Cross-site request forgery
Ninja Forms Contact Form – The Drag and Drop Form Builder for is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE4.3
NVD4.3
Mar 29, 2024 CVE-2024-2108
Ninja Forms Contact Form – The Drag and Drop Form Builder for: Cross-site scripting
Ninja Forms Contact Form – The Drag and Drop Form Builder for is affected by cross-site scripting. Exploitation requires at least author-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE4.6
NVD5.4
Feb 02, 2024 CVE-2024-0685
Ninja Forms Contact Form – The Drag and Drop Form Builder for: SQL injection
Ninja Forms Contact Form – The Drag and Drop Form Builder for is affected by SQL injection. The vulnerable path is reachable without authentication. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE5.9
NVD9.8
Dec 07, 2023 CVE-2023-35909
Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress: A security weakness
Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.3
NVD5.3
Nov 06, 2023 CVE-2023-5530
Ninja Forms Contact Form: Cross-site scripting
Ninja Forms Contact Form is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE4.8
NVD4.8
Jul 27, 2023 CVE-2023-37979
Ninja Forms: Cross-site scripting
Ninja Forms is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE7.1
NVD6.1
May 15, 2023 CVE-2023-1835
Ninja Forms Contact Form: Cross-site scripting
Ninja Forms Contact Form is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.1
NVD6.1
Sep 26, 2022 CVE-2022-2903
Ninja Forms Contact Form: Code execution
Ninja Forms Contact Form is affected by code execution. Exposure depends on how the affected operation is made reachable by the site. Successful exploitation can run attacker-controlled code in the WordPress hosting account.
See mitigation notes
CVE7.2
NVD7.2
Jul 04, 2022 CVE-2021-25066
Ninja Forms Contact Form: Cross-site scripting
Ninja Forms Contact Form is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE4.8
NVD4.8
Jul 04, 2022 CVE-2021-25056
Ninja Forms Contact Form: Cross-site scripting
Ninja Forms Contact Form is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE4.8
NVD4.8
Jun 16, 2022 CVE-2021-36827
Ninja Forms Contact Form: Cross-site scripting
Ninja Forms Contact Form is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE4.8
NVD4.8
Nov 29, 2021 CVE-2021-24889
Ninja Forms Contact Form: SQL injection
Ninja Forms Contact Form is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE7.2
NVD7.2
Sep 22, 2021 CVE-2021-34648
Ninja Forms: A security weakness
Ninja Forms is affected by a security weakness. Exploitation requires an authenticated WordPress account. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE6.4
NVD4.3
Sep 22, 2021 CVE-2021-34647
Ninja Forms: Sensitive information exposure
Ninja Forms is affected by sensitive information exposure. Exploitation requires an authenticated WordPress account. Successful exploitation can disclose data that should not be available to the caller.
See mitigation notes
CVE6.5
NVD4.0
Apr 05, 2021 CVE-2021-24166
wp_ajax_nf_oauth_disconnect from the Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress: A security weakness
wp_ajax_nf_oauth_disconnect from the Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.4
NVD5.4
Apr 05, 2021 CVE-2021-24165
Ninja Forms Contact Form: An open redirect
Ninja Forms Contact Form is affected by an open redirect. Exposure depends on how the affected operation is made reachable by the site. A crafted link can redirect visitors from the trusted site to an attacker-controlled destination.
See mitigation notes
CVE6.1
NVD6.1
Apr 05, 2021 CVE-2021-24164
Ninja Forms Contact Form: A security weakness
Ninja Forms Contact Form is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE4.3
NVD4.3
Apr 05, 2021 CVE-2021-24163
SendWP Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress: A security weakness
SendWP Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE8.8
NVD8.8
Jan 06, 2021 CVE-2020-36175
Ninja Forms: A security weakness
Ninja Forms is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.3
NVD5.3
Jan 06, 2021 CVE-2020-36174
Ninja Forms: Cross-site request forgery
Ninja Forms is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE6.5
NVD6.5
Jan 06, 2021 CVE-2020-36173
Ninja Forms: A security weakness
Ninja Forms is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.3
NVD5.3
Apr 29, 2020 CVE-2020-12462
Ninja Forms: Cross-site scripting
Ninja Forms is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.1
NVD6.1
Feb 14, 2020 CVE-2020-8594
Ninja Forms: Cross-site scripting
Ninja Forms is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE5.4
NVD5.4
Aug 22, 2019 CVE-2018-20981
Ninja Forms: A security weakness
Ninja Forms is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE9.1
NVD9.1
Aug 22, 2019 CVE-2018-20980
Ninja Forms: A security weakness
Ninja Forms is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE7.5
NVD7.5
Aug 22, 2019 CVE-2017-18574
Ninja Forms: A security weakness
Ninja Forms is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE6.1
NVD6.1
Aug 14, 2019 CVE-2019-15025
Ninja Forms: SQL injection
Ninja Forms is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE9.8
NVD9.8
Dec 03, 2018 CVE-2018-19796
Ninja Forms: An open redirect
Ninja Forms is affected by an open redirect. Exposure depends on how the affected operation is made reachable by the site. A crafted link can redirect visitors from the trusted site to an attacker-controlled destination.
See mitigation notes
CVE6.1
NVD6.1
Nov 15, 2018 CVE-2018-19287
Ninja Forms: Cross-site scripting
Ninja Forms is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.1
NVD6.1
Sep 01, 2018 CVE-2018-16308
Ninja Forms: A security weakness
Ninja Forms is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE8.6
NVD8.6
Feb 21, 2018 CVE-2018-7280
Ninja Forms: Cross-site scripting
Ninja Forms is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.1
NVD6.1
May 14, 2016 CVE-2016-1209
Ninja Forms: Code execution
Ninja Forms is affected by code execution. Exposure depends on how the affected operation is made reachable by the site. Successful exploitation can run attacker-controlled code in the WordPress hosting account.
See mitigation notes
CVE9.8
NVD9.8
Mar 05, 2015 CVE-2015-2220
Ninja Forms: Cross-site scripting
Ninja Forms is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE4.3
NVD4.3
Mar 05, 2015 CVE-2014-9688
Ninja Forms: A security weakness
Ninja Forms is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE7.5
NVD7.5