Ninja Forms <= 3.14.9 - Authenticated (Administrator+) SQL Injection via Import File 'settings' Key
medium
The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to generic SQL Injection via Import File 'settings' Key in all versions up to, and including, 3.14.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query....
- CVSS:
- 4.9
- Affected:
- up to 3.14.9
- Fixed in:
- 3.14.10
- Disclosed:
- Jul 23, 2026
CVE-2026-15663 on NVD →
Ninja Forms <= 3.14.1 - Missing Authorization to Unauthenticated Sensitive Information Disclosure via token/refresh REST Endpoint
high
The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to unauthorized access of data due to a missing authorization check on the 'ninja-forms-views/token/refresh' REST callback in all versions up to, and including, 3.14.1. This makes it possible for unauthenticated attackers...
- CVSS:
- 7.5
- Affected:
- up to 3.14.1
- Fixed in:
- 3.14.2
- Disclosed:
- Jun 30, 2026
CVE-2026-1239 on NVD →
Ninja Forms - Authenticated (Contributor+) Sensitive Information Disclosure via Block Editor Token vulnerability
medium
Authenticated (Contributor+) Sensitive Information Disclosure via Block Editor Token vulnerability
- CVSS:
- 6.5
- Affected:
- up to 3.14.1
- Fixed in:
- 3.14.2
- Disclosed:
- Mar 28, 2026
Ninja Forms <= 3.14.1 - Authenticated (Contributor+) Sensitive Information Disclosure via Block Editor Token
medium
The Ninja Forms - The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.14.1 via a callback function for the admin_enqueue_scripts action handler in blocks/bootstrap.php. This makes it possible for authenticated attacker...
- CVSS:
- 6.5
- Affected:
- up to 3.14.1
- Fixed in:
- 3.14.2
- Disclosed:
- Mar 27, 2026
CVE-2026-1307 on NVD →
Ninja Forms <= 3.14.0 - Unauthenticated Information Disclosure in nf_ajax_submit AJAX Action
high
The Ninja Forms plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.14.0. This is due to the unsafe application of the `ninja_forms_merge_tags` filter to user-supplied input within repeater fields, which allows the resolution of `{post_meta:KEY}` merge tags witho...
- CVSS:
- 7.5
- Affected:
- up to 3.14.0
- Fixed in:
- 3.14.1
- Disclosed:
- Feb 9, 2026
CVE-2026-2268 on NVD →
Ninja Forms – The Contact Form Builder That Grows With You [ninja-forms] < 3.13.3
unknown
[en] The Ninja Forms WordPress plugin before 3.13.3 allows unauthenticated attackers to generate valid access tokens via the REST API which can then be used to read form submissions.
- Affected:
- up to 3.13.3
- Fixed in:
- 3.13.3
- Disclosed:
- Jan 2, 2026
CVE-2025-14072 on NVD →
Ninja Forms – The Contact Form Builder That Grows With You [ninja-forms] < 3.13.3
unknown
[en] The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 3.13.2. This is due to the plugin not properly verifying that a user is authorized before the `ninja-forms-views` REST endpoints return form metada...
- Affected:
- up to 3.13.3
- Fixed in:
- 3.13.3
- Disclosed:
- Dec 17, 2025
CVE-2025-11924 on NVD →
Ninja Forms – The Contact Form Builder That Grows With You <= 3.13.2 - Insecure Direct Object Reference to Unauthenticated Sensitive Information Exposure via Unscoped Bearer Token
high
The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 3.13.2. This is due to the plugin not properly verifying that a user is authorized before the `ninja-forms-views` REST endpoints return form metadata an...
- CVSS:
- 7.5
- Affected:
- up to 3.13.2
- Fixed in:
- 3.13.3
- Disclosed:
- Dec 16, 2025
CVE-2025-11924 on NVD →
Ninja Forms <= 3.13.2 - Missing Authorization to Unauthenticated Submission Disclosure
high
The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the /ninja-forms-views/token/refresh function in all versions up to, and including, 3.13.2. This makes it possible for unauthenticated attackers to genera...
- CVSS:
- 7.5
- Affected:
- up to 3.13.2
- Fixed in:
- 3.13.3
- Disclosed:
- Dec 12, 2025
CVE-2025-14072 on NVD →
Ninja Forms – The Contact Form Builder That Grows With You [ninja-forms] < 3.12.1
unknown
[en] The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.12.0. This is due to missing or incorrect nonce validation when exporting CSV files. This makes it possible for unauthenticated attackers to delete tho...
- Affected:
- up to 3.12.1
- Fixed in:
- 3.12.1
- Disclosed:
- Sep 27, 2025
CVE-2025-10498 on NVD →
Ninja Forms – The Contact Form Builder That Grows With You [ninja-forms] < 3.12.1
unknown
[en] The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.12.0. This is due to missing or incorrect nonce validation on the maybe_opt_in() function. This makes it possible for unauthenticated attackers to...
- Affected:
- up to 3.12.1
- Fixed in:
- 3.12.1
- Disclosed:
- Sep 27, 2025
CVE-2025-10499 on NVD →
Ninja Forms – The Contact Form Builder That Grows With You <= 3.12.0 - Cross-Site Request Forgery to Plugin Settings Update
medium
The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.12.0. This is due to missing or incorrect nonce validation on the maybe_opt_in() function. This makes it possible for unauthenticated attackers to opt a...
- CVSS:
- 4.3
- Affected:
- up to 3.12.0
- Fixed in:
- 3.12.1
- Disclosed:
- Sep 26, 2025
CVE-2025-10499 on NVD →
Ninja Forms – The Contact Form Builder That Grows With You <= 3.12.0 - Cross-Site Request Forgery to Limited File Deletion
medium
The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.12.0. This is due to missing or incorrect nonce validation when exporting CSV files. This makes it possible for unauthenticated attackers to delete those fi...
- CVSS:
- 4.3
- Affected:
- up to 3.12.0
- Fixed in:
- 3.12.1
- Disclosed:
- Sep 26, 2025
CVE-2025-10498 on NVD →
Ninja Forms <= 3.11.0 - Unauthenticated PHP Object Injection
high
The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.11.0 via deserialization of untrusted input. This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP chain is present in the...
- CVSS:
- 8.1
- Affected:
- up to 3.11.0
- Fixed in:
- 3.11.1
- Disclosed:
- Aug 28, 2025
CVE-2025-9083 on NVD →
Ninja Forms <= 3.10.2.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via CSTI
medium
The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the use of a templating engine in all versions up to, and including, 3.10.2.1 due to insufficient output escaping on user data passed through the template. This makes it possible for auth...
- CVSS:
- 6.4
- Affected:
- up to 3.10.2.1
- Fixed in:
- 3.10.2.2
- Disclosed:
- Jun 26, 2025
CVE-2025-5398 on NVD →
Ninja Forms – The Contact Form Builder That Grows With You <= 3.10.0 - Authenticated (Admin+) Stored Cross-Site Scripting
medium
The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 3.10.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administra...
- CVSS:
- 4.4
- Affected:
- up to 3.10.0
- Fixed in:
- 3.10.1
- Disclosed:
- Apr 28, 2025
CVE-2025-2561 on NVD →
Ninja Forms – The Contact Form Builder That Grows With You <= 3.10.0 - Authenticated (Admin+) Stored Cross-Site Scripting
medium
The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 3.10.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administra...
- CVSS:
- 4.4
- Affected:
- up to 3.10.0
- Fixed in:
- 3.10.1
- Disclosed:
- Apr 28, 2025
CVE-2025-2560 on NVD →
Ninja Forms – The Contact Form Builder That Grows With You <= 3.10.0 - Authenticated (Admin+) Stored Cross-Site Scripting
medium
The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 3.10.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administra...
- CVSS:
- 4.4
- Affected:
- up to 3.10.0
- Fixed in:
- 3.10.1
- Disclosed:
- Apr 28, 2025
CVE-2025-2524 on NVD →
Ninja Forms – The Contact Form Builder That Grows With You [ninja-forms] < 3.8.25
unknown
[en] The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode in all versions up to, and including, 3.8.24 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for...
- Affected:
- up to 3.8.25
- Fixed in:
- 3.8.25
- Disclosed:
- Jan 30, 2025
CVE-2024-13470 on NVD →
Ninja Forms – The Contact Form Builder That Grows With You <= 3.8.24 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
medium
The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode in all versions up to, and including, 3.8.24 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for auth...
- CVSS:
- 6.4
- Affected:
- up to 3.8.24
- Fixed in:
- 3.8.25
- Disclosed:
- Jan 29, 2025
CVE-2024-13470 on NVD →
Ninja Forms – The Contact Form Builder That Grows With You [ninja-forms] < 3.8.23
unknown
[en] The The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 3.8.22. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. T...
- Affected:
- up to 3.8.23
- Fixed in:
- 3.8.23
- Disclosed:
- Dec 29, 2024
CVE-2024-12238 on NVD →
Ninja Forms – The Contact Form Builder That Grows With You <= 3.8.22 - Authenticated (Subscriber+) Arbitrary Shortcode Execution
medium
The The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 3.8.22. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This m...
- CVSS:
- 6.3
- Affected:
- up to 3.8.22
- Fixed in:
- 3.8.23
- Disclosed:
- Dec 28, 2024
CVE-2024-12238 on NVD →
Ninja Forms – The Contact Form Builder That Grows With You [ninja-forms] < 3.8.20
unknown
[en] The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the calculations parameter in all versions up to, and including, 3.8.19 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attacke...
- Affected:
- up to 3.8.20
- Fixed in:
- 3.8.20
- Disclosed:
- Dec 12, 2024
CVE-2024-11052 on NVD →
Ninja Forms – The Contact Form Builder That Grows With You <= 3.8.19 - Unauthenticated Stored Cross-Site Scripting via Form Calculations
high
The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the calculations parameter in all versions up to, and including, 3.8.19 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to...
- CVSS:
- 7.2
- Affected:
- up to 3.8.19
- Fixed in:
- 3.8.20
- Disclosed:
- Dec 11, 2024
CVE-2024-11052 on NVD →
Ninja Forms – The Contact Form Builder That Grows With You [ninja-forms] < 3.8.18
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Saturday Drive Ninja Forms allows Stored XSS.This issue affects Ninja Forms: from n/a through 3.8.16.
- Affected:
- up to 3.8.18
- Fixed in:
- 3.8.18
- Disclosed:
- Nov 19, 2024
CVE-2024-50514 on NVD →
Ninja Forms – The Contact Form Builder That Grows With You [ninja-forms] < 3.8.18
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Saturday Drive Ninja Forms allows Stored XSS.This issue affects Ninja Forms: from n/a through 3.8.16.
- Affected:
- up to 3.8.18
- Fixed in:
- 3.8.18
- Disclosed:
- Nov 19, 2024
CVE-2024-50515 on NVD →
Ninja Forms – The Contact Form Builder That Grows With You <= 3.8.17 - Authenticated (Admin+) Stored Cross-Site Scripting
medium
The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 3.8.17 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administra...
- CVSS:
- 4.4
- Affected:
- up to 3.8.17
- Fixed in:
- 3.8.18
- Disclosed:
- Oct 28, 2024
CVE-2024-50515 on NVD →
Ninja Forms – The Contact Form Builder That Grows With You <= 3.8.17 - Authenticated (Admin+) Stored Cross-Site Scripting
medium
The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 3.8.17 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administra...
- CVSS:
- 4.4
- Affected:
- up to 3.8.17
- Fixed in:
- 3.8.18
- Disclosed:
- Oct 28, 2024
CVE-2024-50514 on NVD →
Ninja Forms – The Contact Form Builder That Grows With You [ninja-forms] < 3.8.16
unknown
[en] The Ninja Forms Contact Form plugin for WordPress is vulnerable to Reflected Self-Based Cross-Site Scripting via the 'Referer' header in all versions up to, and including, 3.8.15 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web...
- Affected:
- up to 3.8.16
- Fixed in:
- 3.8.16
- Disclosed:
- Sep 25, 2024
CVE-2024-3866 on NVD →
Ninja Forms Contact Form <= 3.8.15 - Reflected Self-Based Cross-Site Scripting via Referer
medium
The Ninja Forms Contact Form plugin for WordPress is vulnerable to Reflected Self-Based Cross-Site Scripting via the 'Referer' header in all versions up to, and including, 3.8.15 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scri...
- CVSS:
- 4.7
- Affected:
- up to 3.8.15
- Fixed in:
- 3.8.16
- Disclosed:
- Sep 24, 2024
CVE-2024-3866 on NVD →
Ninja Forms – The Contact Form Builder That Grows With You [ninja-forms] < 3.8.12
unknown
[en] Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Saturday Drive Ninja Forms allows Stored XSS.This issue affects Ninja Forms: from n/a through 3.8.11.
- Affected:
- up to 3.8.12
- Fixed in:
- 3.8.12
- Disclosed:
- Sep 17, 2024
CVE-2024-43999 on NVD →
Ninja Forms – The Contact Form Builder That Grows With You [ninja-forms] >= 3.8.6 - <= 3.8.10
unknown
<p>WordPress Ninja Forms Plugin 3.8.6-3.8.10 is vulnerable to Cross Site Scripting (XSS)</p><p>Software: Ninja Forms</p><p>Link: https://wordpress.org/plugins/ninja-forms/#developers</p><p>Affected Version 3.8.6-3.8.10</p><p>Fixed in version 3.8.11 </p>
- Affected:
- 3.8.6 – 3.8.10
- Fixed in:
- 3.8.10
- Disclosed:
- Sep 3, 2024
Ninja Forms – The Contact Form Builder That Grows With You [ninja-forms] < 3.8.11
unknown
[en] The Ninja Forms WordPress plugin before 3.8.11 does not escape an URL before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
- Affected:
- up to 3.8.11
- Fixed in:
- 3.8.11
- Disclosed:
- Sep 2, 2024
CVE-2024-7354 on NVD →
Ninja Forms <= 3.8.11 - Authenticated (Administrator+) Stored Cross-Site Scripting
medium
The Ninja Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.8.11 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access and above, to inject arbitrary web scripts in pages t...
- CVSS:
- 4.4
- Affected:
- up to 3.8.11
- Fixed in:
- 3.8.12
- Disclosed:
- Aug 28, 2024
CVE-2024-43999 on NVD →
Ninja Forms – The Contact Form Builder That Grows With You [ninja-forms] < 3.8.7
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in Saturday Drive Ninja Forms allows Cross Site Request Forgery.This issue affects Ninja Forms: from n/a through 3.8.6.
- Affected:
- up to 3.8.7
- Fixed in:
- 3.8.7
- Disclosed:
- Aug 26, 2024
CVE-2024-39628 on NVD →
Ninja Forms – The Contact Form Builder That Grows With You <= 3.8.10 - Reflected Cross-Site Scripting
medium
The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in versions 3.8.6 to 3.8.10. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in...
- CVSS:
- 6.1
- Affected:
- 3.8.6 – 3.8.10
- Fixed in:
- 3.8.11
- Disclosed:
- Aug 12, 2024
CVE-2024-7354 on NVD →
Ninja Forms <= 3.8.6 - Cross-Site Request Forgery
medium
The Ninja Forms plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.8.6. This is due to missing or incorrect nonce validation on the submit_listener() function. This makes it possible for unauthenticated attackers to update license details via a forged request granted th...
- CVSS:
- 4.3
- Affected:
- up to 3.8.6
- Fixed in:
- 3.8.7
- Disclosed:
- Jul 24, 2024
CVE-2024-39628 on NVD →
Ninja Forms – The Contact Form Builder That Grows With You [ninja-forms] < 3.8.5
unknown
[en] Improper Control of Generation of Code ('Code Injection') vulnerability in Saturday Drive Ninja Forms allows Code Injection.This issue affects Ninja Forms: from n/a through 3.8.4.
- Affected:
- up to 3.8.5
- Fixed in:
- 3.8.5
- Disclosed:
- Jul 9, 2024
CVE-2024-37934 on NVD →
Ninja Forms <= 3.8.4 - Authenticated (Subscriber+) Arbitrary Shortcode Execution
medium
The The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 3.8.4. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This ma...
- CVSS:
- 4.3
- Affected:
- up to 3.8.4
- Fixed in:
- 3.8.5
- Disclosed:
- Jul 4, 2024
CVE-2024-37934 on NVD →
Ninja Forms – The Contact Form Builder That Grows With You [ninja-forms] < 3.6.26
unknown
[en] Missing Authorization vulnerability in Saturday Drive Ninja Forms.This issue affects Ninja Forms: from n/a through 3.6.25.
- Affected:
- up to 3.6.26
- Fixed in:
- 3.6.26
- Disclosed:
- Jun 19, 2024
CVE-2023-38386 on NVD →
Ninja Forms – The Contact Form Builder That Grows With You [ninja-forms] < 3.6.26
unknown
[en] Missing Authorization vulnerability in Saturday Drive Ninja Forms.This issue affects Ninja Forms: from n/a through 3.6.25.
- Affected:
- up to 3.6.26
- Fixed in:
- 3.6.26
- Disclosed:
- Jun 19, 2024
CVE-2023-38393 on NVD →
Ninja Forms – The Contact Form Builder That Grows With You [ninja-forms] < 3.6.25
unknown
[en] Improper Input Validation vulnerability in Saturday Drive Ninja Forms Contact Form.This issue affects Ninja Forms Contact Form : from n/a through 3.6.24.
- Affected:
- up to 3.6.25
- Fixed in:
- 3.6.25
- Disclosed:
- Apr 17, 2024
CVE-2023-36505 on NVD →
Ninja Forms – The Contact Form Builder That Grows With You [ninja-forms] < 3.8.1
unknown
[en] Ninja Forms prior to 3.8.1 contains a cross-site scripting vulnerability in custom fields for labels. If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user who is accessing to the website using the product.
- Affected:
- up to 3.8.1
- Fixed in:
- 3.8.1
- Disclosed:
- Apr 11, 2024
CVE-2024-29220 on NVD →
Ninja Forms – The Contact Form Builder That Grows With You [ninja-forms] < 3.8.1
unknown
[en] Ninja Forms prior to 3.8.1 contains a cross-site scripting vulnerability in submit processing. If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user who is accessing to the website using the product.
- Affected:
- up to 3.8.1
- Fixed in:
- 3.8.1
- Disclosed:
- Apr 11, 2024
CVE-2024-26019 on NVD →
Ninja Forms – The Contact Form Builder That Grows With You [ninja-forms] < 3.8.1
unknown
[en] Cross-site request forgery (CSRF) vulnerability exists in Ninja Forms prior to 3.4.31. If a website administrator views a malicious page while logging in, unintended operations may be performed.
- Affected:
- up to 3.8.1
- Fixed in:
- 3.8.1
- Disclosed:
- Apr 11, 2024
CVE-2024-25572 on NVD →
Ninja Forms – The Contact Form Builder That Grows With You <= 3.8.0 - Authenticated (Admin+) Stored Cross-Site Scripting
medium
The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Stored Cross-Site Scripting via form fields in all versions up to, and including, 3.8.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-...
- CVSS:
- 4.4
- Affected:
- up to 3.8.0
- Fixed in:
- 3.8.1
- Disclosed:
- Apr 8, 2024
CVE-2024-26019 on NVD →
Ninja Forms – The Contact Form Builder That Grows With You <= 3.8.0 - Authenticated (Admin+) Stored Cross-Site Scripting
medium
The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Stored Cross-Site Scripting via a form field in all versions up to, and including, 3.8.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator...
- CVSS:
- 4.4
- Affected:
- up to 3.8.0
- Fixed in:
- 3.8.1
- Disclosed:
- Apr 8, 2024
CVE-2024-29220 on NVD →
Ninja Forms – The Contact Form Builder That Grows With You [ninja-forms] < 3.8.1
unknown
[en] The Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an image title embedded into a form in all versions up to, and including, 3.8.0 due to insufficient input sanitization and output escaping. This makes it possible for au...
- Affected:
- up to 3.8.1
- Fixed in:
- 3.8.1
- Disclosed:
- Mar 29, 2024
CVE-2024-2108 on NVD →
Ninja Forms – The Contact Form Builder That Grows With You [ninja-forms] < 3.8.1
unknown
[en] The Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.8.0. This is due to missing or incorrect nonce validation on the nf_download_all_subs AJAX action. This makes it possible for unauthen...
- Affected:
- up to 3.8.1
- Fixed in:
- 3.8.1
- Disclosed:
- Mar 29, 2024
CVE-2024-2113 on NVD →
Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress <= 3.8.0 - Authenticated (Author+) Stored Cross-Site Scripting
medium
The Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an image title embedded into a form in all versions up to, and including, 3.8.0 due to insufficient input sanitization and output escaping. This makes it possible for authent...
- CVSS:
- 4.6
- Affected:
- up to 3.8.0
- Fixed in:
- 3.8.1
- Disclosed:
- Mar 28, 2024
CVE-2024-2108 on NVD →
Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress <= 3.8.0 - Cross-Site Request Forgery to Publicly Accessible Form Submission Export
medium
The Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.8.0. This is due to missing or incorrect nonce validation on the nf_download_all_subs AJAX action. This makes it possible for unauthenticat...
- CVSS:
- 4.3
- Affected:
- up to 3.8.0
- Fixed in:
- 3.8.1
- Disclosed:
- Mar 28, 2024
CVE-2024-2113 on NVD →
Ninja Forms – The Contact Form Builder That Grows With You [ninja-forms] < 3.7.2
unknown
[en] The Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to Second Order SQL Injection via the email address value submitted through forms in all versions up to, and including, 3.7.1 due to insufficient escaping on the user supplied parameter and lack of suffic...
- Affected:
- up to 3.7.2
- Fixed in:
- 3.7.2
- Disclosed:
- Feb 2, 2024
CVE-2024-0685 on NVD →
Ninja Forms Contact Form <= 3.7.1 - Unauthenticated Second Order SQL Injection
medium
The Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to Second Order SQL Injection via the email address value submitted through forms in all versions up to, and including, 3.7.1 due to insufficient escaping on the user supplied parameter and lack of sufficient...
- CVSS:
- 5.9
- Affected:
- up to 3.7.1
- Fixed in:
- 3.7.2
- Disclosed:
- Feb 1, 2024
CVE-2024-0685 on NVD →
Ninja Forms – The Contact Form Builder That Grows With You [ninja-forms] < 3.6.26
unknown
[en] Uncontrolled Resource Consumption vulnerability in Saturday Drive Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress leading to DoS.This issue affects Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress: from n/a through 3.6.25.
- Affected:
- up to 3.6.26
- Fixed in:
- 3.6.26
- Disclosed:
- Dec 7, 2023
CVE-2023-35909 on NVD →
Ninja Forms – The Contact Form Builder That Grows With You [ninja-forms] < 3.6.34
unknown
[en] The Ninja Forms Contact Form WordPress plugin before 3.6.34 does not sanitize and escape its label fields, which could allow high privilege users such as admin to perform Stored XSS attacks. Only users with the unfiltered_html capability can perform this, and such users are already allowed to use JS in posts/comme...
- Affected:
- up to 3.6.34
- Fixed in:
- 3.6.34
- Disclosed:
- Nov 6, 2023
CVE-2023-5530 on NVD →
Ninja Forms Contact Form <= 3.6.33 - Authenticated (Admin+) Stored Cross-Site Scripting
medium
The Ninja Forms Contact Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 3.6.33 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, t...
- CVSS:
- 4.4
- Affected:
- up to 3.6.33
- Fixed in:
- 3.6.34
- Disclosed:
- Oct 16, 2023
CVE-2023-5530 on NVD →
Ninja Forms – The Contact Form Builder That Grows With You [ninja-forms] < 3.6.26
unknown
[en] The Ninja Forms WordPress Ninja Forms Contact Form WordPress plugin before 3.6.26 was affected by a HTML Injection security vulnerability.
- Affected:
- up to 3.6.26
- Fixed in:
- 3.6.26
- Disclosed:
- Aug 30, 2023
CVE-2023-4109 on NVD →
Ninja Forms <= 3.6.25 - Authenticated (Administrator+) Stored HTML Injection
medium
The Ninja Forms plugin for WordPress is vulnerable to Stored HTML Injection in versions up to, and including, 3.6.25 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with administrator access to inject arbitrary HTML content in pages that will execute whenev...
- CVSS:
- 4.4
- Affected:
- up to 3.6.25
- Fixed in:
- 3.6.26
- Disclosed:
- Aug 7, 2023
CVE-2023-4109 on NVD →
Ninja Forms – The Contact Form Builder That Grows With You [ninja-forms] < 3.6.26
unknown
[en] Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Saturday Drive Ninja Forms Contact Form plugin <= 3.6.25 versions.
- Affected:
- up to 3.6.26
- Fixed in:
- 3.6.26
- Disclosed:
- Jul 27, 2023
CVE-2023-37979 on NVD →
Ninja Forms <= 3.6.25 - Reflected Cross-Site Scripting via 'data'
medium
The Ninja Forms plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘data’ parameter in versions up to, and including, 3.6.25 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if...
- CVSS:
- 6.1
- Affected:
- up to 3.6.25
- Fixed in:
- 3.6.26
- Disclosed:
- Jul 25, 2023
CVE-2023-37979 on NVD →
Ninja Forms <= 3.6.25 - Missing Authorization to Contributor+ Form Submission Export
medium
The Ninja Forms plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the export_listen() function in versions up to, and including, 3.6.25. This makes it possible for authenticated attackers, with contributor-level access and above, to export form submissions via a prop...
- CVSS:
- 5.3
- Affected:
- up to 3.6.25
- Fixed in:
- 3.6.26
- Disclosed:
- Jul 25, 2023
CVE-2023-38386 on NVD →
Ninja Forms <= 3.6.25 - Missing Authorization to Form Submission Export
medium
The Ninja Forms plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the processing() function in versions up to, and including, 3.6.25. This makes it possible for authenticated attackers, with subscriber-level access and above, to export form submissions via the nf_dow...
- CVSS:
- 4.3
- Affected:
- up to 3.6.25
- Fixed in:
- 3.6.26
- Disclosed:
- Jul 25, 2023
CVE-2023-38393 on NVD →
Ninja Forms <= 3.6.25 - Denial of Service via Large Form Submissions
medium
The Ninja Forms plugin for WordPress is vulnerable to denial of service in versions up to, and including, 3.6.25. This is due to insufficient controls on form submissions. This makes it possible for unauthenticated attackers to craft form submissions with excessive extra data that may exceed the capacity of the databas...
- CVSS:
- 5.3
- Affected:
- up to 3.6.25
- Fixed in:
- 3.6.26
- Disclosed:
- Jul 7, 2023
CVE-2023-35909 on NVD →
Ninja Forms <= 3.6.24 - Authenticated (Admin+) Arbitrary File Deletion
medium
The Ninja Forms plugin for WordPress is vulnerable to arbitrary file deletions in versions up to, and including, 3.6.24. This is due to insufficient restriction on the file path that can be supplied during file deletion. This makes it possible for authenticated attackers, with administrative-level access, to delete arb...
- CVSS:
- 6.5
- Affected:
- up to 3.6.24
- Fixed in:
- 3.6.25
- Disclosed:
- Jun 22, 2023
CVE-2023-36505 on NVD →
Ninja Forms – The Contact Form Builder That Grows With You [ninja-forms] < 3.6.22
unknown
[en] The Ninja Forms Contact Form WordPress plugin before 3.6.22 does not properly escape user input before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
- Affected:
- up to 3.6.22
- Fixed in:
- 3.6.22
- Disclosed:
- May 15, 2023
CVE-2023-1835 on NVD →
Ninja Forms Contact Form <= 3.6.21 - Reflected Cross-Site Scripting via 'title'
medium
The Ninja Forms Contact Form plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'title' parameter in versions up to, and including, 3.6.21 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages t...
- CVSS:
- 6.1
- Affected:
- up to 3.6.21
- Fixed in:
- 3.6.22
- Disclosed:
- Apr 24, 2023
CVE-2023-1835 on NVD →
Ninja Forms – The Contact Form Builder That Grows With You [ninja-forms] < 3.6.13
unknown
[en] The Ninja Forms Contact Form WordPress plugin before 3.6.13 unserialises the content of an imported file, which could lead to PHP object injections issues when an admin import (intentionally or not) a malicious file and a suitable gadget chain is present on the blog.
- Affected:
- up to 3.6.13
- Fixed in:
- 3.6.13
- Disclosed:
- Sep 26, 2022
CVE-2022-2903 on NVD →
Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress <= 3.6.12 - Authenticated (Administrator+) PHP Objection Injection
high
The Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 3.6.12 via deserialization of untrusted input. This allows administrator-level attackers to inject a PHP Object. No POP chain is present in the vulner...
- CVSS:
- 7.2
- Affected:
- up to 3.6.12
- Fixed in:
- 3.6.13
- Disclosed:
- Sep 5, 2022
CVE-2022-2903 on NVD →
Ninja Forms – The Contact Form Builder That Grows With You [ninja-forms] < 3.6.10
unknown
[en] The Ninja Forms Contact Form WordPress plugin before 3.6.10 does not sanitise and escape field labels, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.
- Affected:
- up to 3.6.10
- Fixed in:
- 3.6.10
- Disclosed:
- Jul 4, 2022
CVE-2021-25056 on NVD →
Ninja Forms – The Contact Form Builder That Grows With You [ninja-forms] < 3.6.11
unknown
[en] The Ninja Forms Contact Form WordPress plugin before 3.6.10 does not sanitize and escape some imported data, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.
- Affected:
- up to 3.6.11
- Fixed in:
- 3.6.11
- Disclosed:
- Jul 4, 2022
CVE-2021-25066 on NVD →
Ninja Forms – The Contact Form Builder That Grows With You [ninja-forms] < 3.6.10
unknown
[en] Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Saturday Drive's Ninja Forms Contact Form plugin <= 3.6.9 at WordPress via "label".
- Affected:
- up to 3.6.10
- Fixed in:
- 3.6.10
- Disclosed:
- Jun 16, 2022
CVE-2021-36827 on NVD →
Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress <= 3.6.10 - Code Injection
critical
The Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to code injection in versions up to, and including 3.6.10 due to insufficient validation on Merge Tags that makes it possible to call arbitrary Ninja Form classes. This could lead to a variety of actions, howe...
- CVSS:
- 9.8
- Affected:
- up to 3.0.34.1, 3.1 – 3.1.9, 3.2 – 3.2.27, 3.3 – 3.3.21.3, 3.4 – 3.4.34.1, 3.5 – 3.5.8.3, 3.6 – 3.6.10
- Fixed in:
- 3.0.34.2
- Disclosed:
- Jun 15, 2022
Ninja Forms – The Contact Form Builder That Grows With You [ninja-forms] <= 3.6.10
unknown
Unauthenticated PHP Object Injection vulnerability discovered in WordPress Ninja Forms plugin (versions <= 3.6.10).
Update the WordPress Ninja Forms plugin to the latest available version (at least 3.6.11).
- Affected:
- up to 3.6.10
- Fixed in:
- 3.6.10
- Disclosed:
- Jun 15, 2022
Ninja Forms – The Contact Form Builder That Grows With You [ninja-forms] < 3.6.11
unknown
The Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to code injection in versions up to, and including 3.6.10 due to insufficient validation on Merge Tags that makes it possible to call arbitrary Ninja Form classes. This could lead to a variety of actions, howe...
- Affected:
- up to 3.6.11
- Fixed in:
- 3.6.11
- Disclosed:
- Jun 15, 2022
Ninja Forms Contact Form <= 3.6.9 - Cross-Site Scripting via field label
medium
The Ninja Forms Contact Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via field labels in versions up to, and including, 3.6.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with administrative level permissions and above to inject...
- CVSS:
- 4.8
- Affected:
- up to 3.6.9
- Fixed in:
- 3.6.10
- Disclosed:
- Jun 13, 2022
CVE-2021-25056 on NVD →
Ninja Ninja Forms Contact Form <= 3.6.10 - Authenticated (Admin+) Stored Cross-Site Scripting via import
medium
The Ninja Forms Contact Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters found in an import in versions up to, and including, 3.6.10 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with administrative level permi...
- CVSS:
- 5.5
- Affected:
- up to 3.6.10
- Fixed in:
- 3.6.11
- Disclosed:
- Jun 10, 2022
CVE-2021-25066 on NVD →
Ninja Forms Contact Form <= 3.6.9 - Authenticated (Admin+) Cross-Site Scripting via label
medium
The Ninja Forms Contact Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'label' parameter in versions up to, and including, 3.6.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with administrative level permissions and above...
- CVSS:
- 5.5
- Affected:
- up to 3.6.9
- Fixed in:
- 3.6.10
- Disclosed:
- Jun 7, 2022
CVE-2021-36827 on NVD →
Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress <= 3.6.9 - Cross-Site Request Forgery to Field Import and PHP Object Injection
high
The Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including 3.6.9, due to missing nonce validation on the import_fields_listener() function that makes it possible for unauthenticated attackers to import new...
- CVSS:
- 8.8
- Affected:
- up to 3.6.9
- Fixed in:
- 3.6.10
- Disclosed:
- Jun 7, 2022
Ninja Forms – The Contact Form Builder That Grows With You [ninja-forms] < 3.6.10
unknown
The Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including 3.6.9, due to missing nonce validation on the import_fields_listener() function that makes it possible for unauthenticated attackers to import new...
- Affected:
- up to 3.6.10
- Fixed in:
- 3.6.10
- Disclosed:
- Jun 7, 2022
Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress <= 3.6.7 - Email Address Disclosure
medium
The Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to Sensitive Data Exposure in versions up to, and including, 3.6.7. This can allow unauthenticated attackers to extract sensitive data including other users' email addresses which can be used to help perform f...
- CVSS:
- 5.3
- Affected:
- up to 3.6.7
- Fixed in:
- 3.6.8
- Disclosed:
- Mar 22, 2022
Ninja Forms – The Contact Form Builder That Grows With You [ninja-forms] < 3.6.8
unknown
Unauthenticated Email Address Disclosure vulnerability discovered by Agence Web Coheractio in WordPress Ninja Forms plugin (versions <= 3.6.7).
- Affected:
- up to 3.6.8
- Fixed in:
- 3.6.8
- Disclosed:
- Mar 22, 2022
Ninja Forms – The Contact Form Builder That Grows With You [ninja-forms] < 3.6.8
unknown
The Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to Sensitive Data Exposure in versions up to, and including, 3.6.7. This can allow unauthenticated attackers to extract sensitive data including other users' email addresses which can be used to help perform f...
- Affected:
- up to 3.6.8
- Fixed in:
- 3.6.8
- Disclosed:
- Mar 22, 2022
Ninja Forms – The Contact Form Builder That Grows With You [ninja-forms] < 3.6.4
unknown
[en] The Ninja Forms Contact Form WordPress plugin before 3.6.4 does not escape keys of the fields POST parameter, which could allow high privilege users to perform SQL injections attacks
- Affected:
- up to 3.6.4
- Fixed in:
- 3.6.4
- Disclosed:
- Nov 29, 2021
CVE-2021-24889 on NVD →
Ninja Forms Contact Form <= 3.6.3 - Authenticated SQL Injection
high
The Ninja Forms Contact Form WordPress plugin before 3.6.4 does not escape keys of the fields POST parameter, which could allow high privilege users to perform SQL injections attacks
- CVSS:
- 7.2
- Affected:
- up to 3.6.4
- Fixed in:
- 3.6.4
- Disclosed:
- Oct 26, 2021
CVE-2021-24889 on NVD →
Ninja Forms – The Contact Form Builder That Grows With You [ninja-forms] < 3.6.8
unknown
[en] The Ninja Forms Contact Form WordPress plugin before 3.5.8.2 does not sanitise and escape the custom class name of the form field created, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.
- Affected:
- up to 3.6.8
- Fixed in:
- 3.6.8
- Disclosed:
- Oct 25, 2021
CVE-2021-24381 on NVD →
Ninja Forms <= 3.5.8.1 - Cross-Site Scripting
medium
The Ninja Forms Contact Form WordPress plugin before 3.5.8.2 does not sanitise and escape the custom class name of the form field created, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.
- CVSS:
- 4.8
- Affected:
- up to 3.5.8.2
- Fixed in:
- 3.5.8.2
- Disclosed:
- Sep 27, 2021
CVE-2021-24381 on NVD →
Ninja Forms <= 3.5.7 - Unprotected REST-API to Sensitive Information Disclosure
medium
The Ninja Forms WordPress plugin is vulnerable to sensitive information disclosure via the bulk_export_submissions function found in the ~/includes/Routes/Submissions.php file, in versions up to and including 3.5.7. This allows authenticated attackers to export all Ninja Forms submissions data via the /ninja-forms-subm...
- CVSS:
- 6.5
- Affected:
- up to 3.5.7
- Fixed in:
- 3.5.8
- Disclosed:
- Sep 22, 2021
CVE-2021-34647 on NVD →
Ninja Forms <= 3.5.7 - Unprotected REST-API to Email Injection
medium
The Ninja Forms WordPress plugin is vulnerable to arbitrary email sending via the trigger_email_action function found in the ~/includes/Routes/Submissions.php file, in versions up to and including 3.5.7. This allows authenticated attackers to send arbitrary emails from the affected server via the /ninja-forms-submissio...
- CVSS:
- 6.4
- Affected:
- up to 3.5.7
- Fixed in:
- 3.5.8
- Disclosed:
- Sep 22, 2021
CVE-2021-34648 on NVD →
Ninja Forms – The Contact Form Builder That Grows With You [ninja-forms] < 3.5.8
unknown
[en] The Ninja Forms WordPress plugin is vulnerable to sensitive information disclosure via the bulk_export_submissions function found in the ~/includes/Routes/Submissions.php file, in versions up to and including 3.5.7. This allows authenticated attackers to export all Ninja Forms submissions data via the /ninja-forms...
- Affected:
- up to 3.5.8
- Fixed in:
- 3.5.8
- Disclosed:
- Sep 22, 2021
CVE-2021-34647 on NVD →
Ninja Forms – The Contact Form Builder That Grows With You [ninja-forms] < 3.5.8
unknown
[en] The Ninja Forms WordPress plugin is vulnerable to arbitrary email sending via the trigger_email_action function found in the ~/includes/Routes/Submissions.php file, in versions up to and including 3.5.7. This allows authenticated attackers to send arbitrary emails from the affected server via the /ninja-forms-subm...
- Affected:
- up to 3.5.8
- Fixed in:
- 3.5.8
- Disclosed:
- Sep 22, 2021
CVE-2021-34648 on NVD →
Ninja Forms – The Contact Form Builder That Grows With You [ninja-forms] < 3.4.34
unknown
[en] In the Ninja Forms Contact Form WordPress plugin before 3.4.34, the wp_ajax_nf_oauth_connect AJAX action was vulnerable to open redirect due to the use of a user supplied redirect parameter and no protection in place.
- Affected:
- up to 3.4.34
- Fixed in:
- 3.4.34
- Disclosed:
- Apr 5, 2021
CVE-2021-24165 on NVD →
Ninja Forms – The Contact Form Builder That Grows With You [ninja-forms] < 3.4.34
unknown
[en] The AJAX action, wp_ajax_ninja_forms_sendwp_remote_install_handler, did not have a capability check on it, nor did it have any nonce protection, therefore making it possible for low-level users, such as subscribers, to install and activate the SendWP Ninja Forms Contact Form – The Drag and Drop Form Builder for Wo...
- Affected:
- up to 3.4.34
- Fixed in:
- 3.4.34
- Disclosed:
- Apr 5, 2021
CVE-2021-24163 on NVD →
Ninja Forms – The Contact Form Builder That Grows With You [ninja-forms] < 3.4.34.1
unknown
[en] In the Ninja Forms Contact Form WordPress plugin before 3.4.34.1, low-level users, such as subscribers, were able to trigger the action, wp_ajax_nf_oauth, and retrieve the connection url needed to establish a connection. They could also retrieve the client_id for an already established OAuth connection.
- Affected:
- up to 3.4.34.1
- Fixed in:
- 3.4.34.1
- Disclosed:
- Apr 5, 2021
CVE-2021-24164 on NVD →
Ninja Forms – The Contact Form Builder That Grows With You [ninja-forms] < 3.4.34
unknown
[en] The wp_ajax_nf_oauth_disconnect from the Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress WordPress plugin before 3.4.34 had no nonce protection making it possible for attackers to craft a request to disconnect a site's OAuth connection.
- Affected:
- up to 3.4.34
- Fixed in:
- 3.4.34
- Disclosed:
- Apr 5, 2021
CVE-2021-24166 on NVD →
Ninja Forms Contact Form <= 3.4.33 - Authenticated SendWP Plugin Installation and Client Secret Key Disclosure
high
The AJAX action, wp_ajax_ninja_forms_sendwp_remote_install_handler, did not have a capability check on it, nor did it have any nonce protection, therefore making it possible for low-level users, such as subscribers, to install and activate the SendWP Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPre...
- CVSS:
- 8.8
- Affected:
- up to 3.4.34
- Fixed in:
- 3.4.34
- Disclosed:
- Feb 16, 2021
CVE-2021-24163 on NVD →
Ninja Forms Contact Form <= 3.4.33 - Administrator Open Redirect
medium
In the Ninja Forms Contact Form WordPress plugin before 3.4.34, the wp_ajax_nf_oauth_connect AJAX action was vulnerable to open redirect due to the use of a user supplied redirect parameter and no protection in place.
- CVSS:
- 6.1
- Affected:
- up to 3.4.34
- Fixed in:
- 3.4.34
- Disclosed:
- Feb 16, 2021
CVE-2021-24165 on NVD →
Ninja Forms Contact Form <= 3.4.33 - Cross-Site Request Forgery to OAuth Service Disconnection
medium
The wp_ajax_nf_oauth_disconnect from the Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress WordPress plugin before 3.4.34 had no nonce protection making it possible for attackers to craft a request to disconnect a site's OAuth connection.
- CVSS:
- 5.4
- Affected:
- up to 3.4.34
- Fixed in:
- 3.4.34
- Disclosed:
- Feb 16, 2021
CVE-2021-24166 on NVD →
Ninja Forms <= 3.4.34 - Authenticated OAuth Connection Key Disclosure
medium
In the Ninja Forms Contact Form WordPress plugin before 3.4.34.1, low-level users, such as subscribers, were able to trigger the action, wp_ajax_nf_oauth, and retrieve the connection url needed to establish a connection. They could also retrieve the client_id for an already established OAuth connection.
- CVSS:
- 4.3
- Affected:
- up to 3.4.34.1
- Fixed in:
- 3.4.34.1
- Disclosed:
- Feb 16, 2021
CVE-2021-24164 on NVD →
Ninja Forms – The Contact Form Builder That Grows With You [ninja-forms] < 3.4.34
unknown
Cross-Site Request Forgery (CSRF) vulnerability found by Chloe Chamberland in WordPress Ninja Forms Contact Form plugin (versions <= 3.4.33).
- Affected:
- up to 3.4.34
- Fixed in:
- 3.4.34
- Disclosed:
- Feb 16, 2021
Ninja Forms – The Contact Form Builder That Grows With You [ninja-forms] < 3.4.34
unknown
Administrator Open Redirect vulnerability found by Chloe Chamberland in WordPress Ninja Forms Contact Form plugin (versions <= 3.4.33).
- Affected:
- up to 3.4.34
- Fixed in:
- 3.4.34
- Disclosed:
- Feb 16, 2021
Ninja Forms – The Contact Form Builder That Grows With You [ninja-forms] < 3.4.34
unknown
Authenticated OAuth Connection Key Disclosure vulnerability found by Chloe Chamberland in WordPress Ninja Forms Contact Form plugin (versions <= 3.4.33).
- Affected:
- up to 3.4.34
- Fixed in:
- 3.4.34
- Disclosed:
- Feb 16, 2021
Ninja Forms – The Contact Form Builder That Grows With You [ninja-forms] < 3.4.34
unknown
Authenticated SendWP Plugin Installation and Client Secret Key Disclosure vulnerability found by Chloe Chamberland in WordPress Ninja Forms Contact Form plugin (versions <= 3.4.33).
- Affected:
- up to 3.4.34
- Fixed in:
- 3.4.34
- Disclosed:
- Feb 16, 2021
Ninja Forms – The Contact Form Builder That Grows With You [ninja-forms] < 3.4.28
unknown
[en] The Ninja Forms plugin before 3.4.28 for WordPress lacks escaping for submissions-table fields.
- Affected:
- up to 3.4.28
- Fixed in:
- 3.4.28
- Disclosed:
- Jan 6, 2021
CVE-2020-36173 on NVD →
Ninja Forms – The Contact Form Builder That Grows With You [ninja-forms] < 3.4.27.1
unknown
[en] The Ninja Forms plugin before 3.4.27.1 for WordPress allows CSRF via services integration.
- Affected:
- up to 3.4.27.1
- Fixed in:
- 3.4.27.1
- Disclosed:
- Jan 6, 2021
CVE-2020-36174 on NVD →
Ninja Forms – The Contact Form Builder That Grows With You [ninja-forms] < 3.4.27.1
unknown
[en] The Ninja Forms plugin before 3.4.27.1 for WordPress allows attackers to bypass validation via the email field.
- Affected:
- up to 3.4.27.1
- Fixed in:
- 3.4.27.1
- Disclosed:
- Jan 6, 2021
CVE-2020-36175 on NVD →
Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress <= 3.4.27 - Cross-Site Request Forgery to Plugin Installation
high
The Ninja Forms plugin before 3.4.27.1 for WordPress allows CSRF via services integration. This makes it possible for attackers to install arbitrary plugins.
- CVSS:
- 8.8
- Affected:
- up to 3.4.27
- Fixed in:
- 3.4.27.1
- Disclosed:
- Sep 22, 2020
CVE-2020-36174 on NVD →
Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress <= 3.4.27 - Validation Bypass via Email Field
medium
The Ninja Forms plugin before 3.4.27.1 for WordPress allows attackers to bypass validation via the email field.
- CVSS:
- 5.3
- Affected:
- up to 3.4.27
- Fixed in:
- 3.4.27.1
- Disclosed:
- Sep 22, 2020
CVE-2020-36175 on NVD →
Ninja Forms – The Contact Form Builder That Grows With You [ninja-forms] < 3.4.27.1
unknown
Cross-Site Request Forgery (CSRF) leading to Arbitrary Plugin Installation vulnerability found by Slavco Mihajloski in WordPress Ninja Forms plugin (versions <= 3.4.27).
- Affected:
- up to 3.4.27.1
- Fixed in:
- 3.4.27.1
- Disclosed:
- Sep 22, 2020
Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress <= 3.4.27.1 - Stored Cross-Site Scripting
medium
The Ninja Forms plugin before 3.4.28 for WordPress lacks escaping for submissions-table fields.
- CVSS:
- 6.5
- Affected:
- up to 3.4.27.1
- Fixed in:
- 3.4.28
- Disclosed:
- Sep 20, 2020
CVE-2020-36173 on NVD →
Ninja Forms – The Contact Form Builder That Grows With You [ninja-forms] < 3.4.24.2
unknown
[en] The ninja-forms plugin before 3.4.24.2 for WordPress allows CSRF with resultant XSS.
- Affected:
- up to 3.4.24.2
- Fixed in:
- 3.4.24.2
- Disclosed:
- Apr 29, 2020
CVE-2020-12462 on NVD →
Ninja Forms Contact Form <= 3.4.24.1 - Cross-Site Request Forgery leading to Stored Cross-Site Scripting
medium
The Ninja Forms plugin before 3.4.24.2 for WordPress allows CSRF with resultant XSS.
- CVSS:
- 6.1
- Affected:
- up to 3.4.24.2
- Fixed in:
- 3.4.24.2
- Disclosed:
- Apr 28, 2020
CVE-2020-12462 on NVD →
Ninja Forms – The Contact Form Builder That Grows With You [ninja-forms] < 3.4.23
unknown
[en] The Ninja Forms plugin 3.4.22 for WordPress has Multiple Stored XSS vulnerabilities via ninja_forms[recaptcha_site_key], ninja_forms[recaptcha_secret_key], ninja_forms[recaptcha_lang], or ninja_forms[date_format].
- Affected:
- up to 3.4.23
- Fixed in:
- 3.4.23
- Disclosed:
- Feb 14, 2020
CVE-2020-8594 on NVD →
Ninja Forms Contact Form <= 3.4.22 - Stored Cross-Site Scripting
medium
The Ninja Forms plugin 3.4.22 for WordPress has Multiple Stored XSS vulnerabilities via ninja_forms[recaptcha_site_key], ninja_forms[recaptcha_secret_key], ninja_forms[recaptcha_lang], or ninja_forms[date_format].
- CVSS:
- 6.4
- Affected:
- up to 3.4.23
- Fixed in:
- 3.4.23
- Disclosed:
- Feb 3, 2020
CVE-2020-8594 on NVD →
Ninja Forms – The Contact Form Builder That Grows With You [ninja-forms] < 3.3.9
unknown
[en] The ninja-forms plugin before 3.3.9 for WordPress has insufficient restrictions on submission-data retrieval during Export Personal Data requests.
- Affected:
- up to 3.3.9
- Fixed in:
- 3.3.9
- Disclosed:
- Aug 22, 2019
CVE-2018-20981 on NVD →
Ninja Forms – The Contact Form Builder That Grows With You [ninja-forms] < 3.2.15
unknown
[en] The ninja-forms plugin before 3.2.15 for WordPress has parameter tampering.
- Affected:
- up to 3.2.15
- Fixed in:
- 3.2.15
- Disclosed:
- Aug 22, 2019
CVE-2018-20980 on NVD →
Ninja Forms – The Contact Form Builder That Grows With You [ninja-forms] < 3.0.31
unknown
[en] The ninja-forms plugin before 3.0.31 for WordPress has insufficient HTML escaping in the builder.
- Affected:
- up to 3.0.31
- Fixed in:
- 3.0.31
- Disclosed:
- Aug 22, 2019
CVE-2017-18574 on NVD →
Ninja Forms – The Contact Form Builder That Grows With You [ninja-forms] < 3.3.21.2
unknown
[en] The ninja-forms plugin before 3.3.21.2 for WordPress has SQL injection in the search filter on the submissions page.
- Affected:
- up to 3.3.21.2
- Fixed in:
- 3.3.21.2
- Disclosed:
- Aug 14, 2019
CVE-2019-15025 on NVD →
Ninja Forms – The Contact Form Builder That Grows With You [ninja-forms] < 3.3.21.3
unknown
Cross-Site Scripting (XSS) vulnerability found in WordPress Ninja Forms plugin (versions <= 3.3.21).
- Affected:
- up to 3.3.21.3
- Fixed in:
- 3.3.21.3
- Disclosed:
- Jun 25, 2019
Ninja Forms – The Contact Form Builder That Grows With You [ninja-forms] < 3.3.21.3
unknown
SQL injection (SQLi) vulnerability found in WordPress Ninja Forms plugin (versions <= 3.3.21).
- Affected:
- up to 3.3.21.3
- Fixed in:
- 3.3.21.3
- Disclosed:
- Jun 25, 2019
Ninja Forms Contact Form <= 3.3.21.1 - SQL Injection
critical
The ninja-forms plugin before 3.3.21.2 for WordPress has SQL injection in the search filter on the submissions page.
- CVSS:
- 9.8
- Affected:
- up to 3.3.21.1
- Fixed in:
- 3.3.21.2
- Disclosed:
- Jan 7, 2019
CVE-2019-15025 on NVD →
Ninja Forms – The Contact Form Builder That Grows With You [ninja-forms] < 3.3.19.1
unknown
[en] An open redirect in the Ninja Forms plugin before 3.3.19.1 for WordPress allows Remote Attackers to redirect a user via the lib/StepProcessing/step-processing.php (aka submissions download page) redirect parameter.
- Affected:
- up to 3.3.19.1
- Fixed in:
- 3.3.19.1
- Disclosed:
- Dec 3, 2018
CVE-2018-19796 on NVD →
Ninja Forms Contact Form <= 3.3.19 - Authenticated Open Redirect
medium
An open redirect in the Ninja Forms plugin before 3.3.19.1 for WordPress allows Remote Attackers to redirect a user via the lib/StepProcessing/step-processing.php (aka submissions download page) redirect parameter.
- CVSS:
- 4.7
- Affected:
- up to 3.3.19
- Fixed in:
- 3.3.19.1
- Disclosed:
- Dec 1, 2018
CVE-2018-19796 on NVD →
Ninja Forms Contact Form <= 3.3.17 - Cross-Site Scripting via begin_date, end_date, or form_id Parameter
medium
XSS in the Ninja Forms plugin before 3.3.18 for WordPress allows Remote Attackers to execute JavaScript via the includes/Admin/Menus/Submissions.php (aka submissions page) begin_date, end_date, or form_id parameter.
- CVSS:
- 6.1
- Affected:
- up to 3.3.18
- Fixed in:
- 3.3.18
- Disclosed:
- Nov 15, 2018
CVE-2018-19287 on NVD →
Ninja Forms – The Contact Form Builder That Grows With You [ninja-forms] < 3.3.18
unknown
[en] XSS in the Ninja Forms plugin before 3.3.18 for WordPress allows Remote Attackers to execute JavaScript via the includes/Admin/Menus/Submissions.php (aka submissions page) begin_date, end_date, or form_id parameter.
- Affected:
- up to 3.3.18
- Fixed in:
- 3.3.18
- Disclosed:
- Nov 15, 2018
CVE-2018-19287 on NVD →
Ninja Forms – The Contact Form Builder That Grows With You [ninja-forms] < 3.3.14
unknown
[en] The Ninja Forms plugin before 3.3.14.1 for WordPress allows CSV injection.
- Affected:
- up to 3.3.14
- Fixed in:
- 3.3.14
- Disclosed:
- Sep 1, 2018
CVE-2018-16308 on NVD →
Ninja Forms – The Contact Form Builder That Grows With You [ninja-forms] < 3.3.14
unknown
CSV Injection vulnerability fund by Mostafa Gharzi in WordPress Ninja Forms plugin (versions <= 3.3.13).
- Affected:
- up to 3.3.14
- Fixed in:
- 3.3.14
- Disclosed:
- Aug 28, 2018
Ninja Forms – The Contact Form Builder That Grows With You [ninja-forms] < 3.3.14
unknown
Cross-Site Scripting (XSS) vulnerability found in WordPress Ninja Forms plugin (versions <= 3.3.13).
- Affected:
- up to 3.3.14
- Fixed in:
- 3.3.14
- Disclosed:
- Aug 28, 2018
Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress <= 3.3.13 - Cross-Site Scripting
high
The Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to Cross-Site Scripting via the form input function in versions up to, and including, 3.3.13 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrar...
- CVSS:
- 8.3
- Affected:
- up to 3.3.14
- Fixed in:
- 3.3.14
- Disclosed:
- Aug 27, 2018
Ninja Forms – The Contact Form Builder That Grows With You [ninja-forms] < 3.3.14
unknown
The Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to Cross-Site Scripting via the form input function in versions up to, and including, 3.3.13 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrar...
- Affected:
- up to 3.3.14
- Fixed in:
- 3.3.14
- Disclosed:
- Aug 27, 2018
Ninja Forms Contact Form <= 3.3.13 - CSV Injection
high
The Ninja Forms plugin before 3.3.14.1 for WordPress allows CSV injection.
- CVSS:
- 8.6
- Affected:
- up to 3.3.13
- Fixed in:
- 3.3.14
- Disclosed:
- Aug 19, 2018
CVE-2018-16308 on NVD →
Ninja Forms <= 3.3.8 - Insufficient Restrictions during Export Personal Data requests
critical
The ninja-forms plugin before 3.3.9 for WordPress has insufficient restrictions on submission-data retrieval during Export Personal Data requests.
- CVSS:
- 9.1
- Affected:
- up to 3.3.8
- Fixed in:
- 3.3.9
- Disclosed:
- Jul 6, 2018
CVE-2018-20981 on NVD →
Ninja Forms Contact Form <= 3.2.14 - Parameter Tampering
high
The ninja-forms plugin before 3.2.15 for WordPress has parameter tampering.
- CVSS:
- 7.5
- Affected:
- up to 3.2.15
- Fixed in:
- 3.2.15
- Disclosed:
- Feb 26, 2018
CVE-2018-20980 on NVD →
Ninja Forms – The Contact Form Builder That Grows With You [ninja-forms] < 3.2.14
unknown
[en] The Ninja Forms plugin before 3.2.14 for WordPress has XSS.
- Affected:
- up to 3.2.14
- Fixed in:
- 3.2.14
- Disclosed:
- Feb 21, 2018
CVE-2018-7280 on NVD →
Ninja Forms Contact Form <= 3.2.13 - Cross-Site Scripting
medium
The Ninja Forms plugin before 3.2.14 for WordPress has XSS.
- CVSS:
- 6.1
- Affected:
- up to 3.2.14
- Fixed in:
- 3.2.14
- Disclosed:
- Feb 20, 2018
CVE-2018-7280 on NVD →
Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress <= 3.0.31 - Arbitrary Wordpress Shortcode Injection
medium
The Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to Arbitrary Wordpress Shortcode Injection in versions up to, and including, 3.0.31. This makes it possible for unauthenticated attackers to preview un-published forms and could possibly be used to leverage fu...
- CVSS:
- 5.3
- Affected:
- up to 3.0.31
- Fixed in:
- 3.0.32
- Disclosed:
- Apr 17, 2017
Ninja Forms – The Contact Form Builder That Grows With You [ninja-forms] < 3.0.32
unknown
The Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to Arbitrary Wordpress Shortcode Injection in versions up to, and including, 3.0.31. This makes it possible for unauthenticated attackers to preview un-published forms and could possibly be used to leverage fu...
- Affected:
- up to 3.0.32
- Fixed in:
- 3.0.32
- Disclosed:
- Apr 17, 2017
Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress <= 3.0.30 - HTML Injection
medium
The ninja-forms plugin before 3.0.31 for WordPress has insufficient HTML escaping in the builder.
- CVSS:
- 6.1
- Affected:
- up to 3.0.31
- Fixed in:
- 3.0.31
- Disclosed:
- Mar 7, 2017
CVE-2017-18574 on NVD →
Ninja Forms Contact Form <= 2.9.55.1 - Authenticated SQL Injection
high
The Ninja Forms Contact Form plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 2.9.55.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for Subscriber-level attackers to append additiona...
- CVSS:
- 8.8
- Affected:
- up to 2.9.55.2
- Fixed in:
- 2.9.55.2
- Disclosed:
- Aug 16, 2016
Ninja Forms – The Contact Form Builder That Grows With You [ninja-forms] < 2.9.55.2
unknown
There is a bug in this plugin. It could leak the site’s usernames and hashed passwords.
Update the plugin.
- Affected:
- up to 2.9.55.2
- Fixed in:
- 2.9.55.2
- Disclosed:
- Aug 16, 2016
Ninja Forms – The Contact Form Builder That Grows With You [ninja-forms] < 2.9.55.2
unknown
The Ninja Forms Contact Form plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 2.9.55.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for Subscriber-level attackers to append additiona...
- Affected:
- up to 2.9.55.2
- Fixed in:
- 2.9.55.2
- Disclosed:
- Aug 16, 2016
Ninja Forms Contact Form <= 2.9.51 - Multiple Reflected Cross-Site Scripting
medium
The Ninja Forms Contact Form plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via multiple parameters in versions before 2.9.52 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if th...
- CVSS:
- 6.1
- Affected:
- up to 2.9.52
- Fixed in:
- 2.9.52
- Disclosed:
- Jul 19, 2016
Ninja Forms – The Contact Form Builder That Grows With You [ninja-forms] < 2.9.52
unknown
Because of this vulnerability, attackers can inject malicious JavaScript code into the application.
Update this plugin.
- Affected:
- up to 2.9.52
- Fixed in:
- 2.9.52
- Disclosed:
- Jul 19, 2016
Ninja Forms – The Contact Form Builder That Grows With You [ninja-forms] < 2.9.52
unknown
The Ninja Forms Contact Form plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via multiple parameters in versions before 2.9.52 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if th...
- Affected:
- up to 2.9.52
- Fixed in:
- 2.9.52
- Disclosed:
- Jul 19, 2016
Ninja Forms – The Contact Form Builder That Grows With You [ninja-forms] >= 2.9.36 - <= 2.9.42
unknown
[en] The Ninja Forms plugin before 2.9.42.1 for WordPress allows remote attackers to conduct PHP object injection attacks via crafted serialized values in a POST request.
- Affected:
- 2.9.36 – 2.9.42
- Fixed in:
- 2.9.42
- Disclosed:
- May 14, 2016
CVE-2016-1209 on NVD →
Ninja Forms Contact Form 2.9.36 - 2.9.42 - PHP Object Injection
high
The Ninja Forms plugin before 2.9.42.1 for WordPress allows remote attackers to conduct PHP object injection attacks via crafted serialized values in a POST request.
- CVSS:
- 8.1
- Affected:
- 2.9.36 – 2.9.42
- Fixed in:
- 2.9.42.1
- Disclosed:
- May 13, 2016
CVE-2016-1209 on NVD →
Ninja Forms Contact Form 2.9.36 - 2.9.42 - Unauthenticated Arbitrary File Upload
critical
Versions 2.9.36 to 2.9.42 of the Ninja Forms plugin contain an unauthenticated file upload vulnerability, allowing guests to upload arbitrary PHP code that can be executed in the context of the web server.
- CVSS:
- 9.8
- Affected:
- 2.9.36 – 2.9.42
- Fixed in:
- 2.9.42.1
- Disclosed:
- May 5, 2016
CVE-2016-1209 on NVD →
Ninja Forms Contact Form <= 2.9.28 - Stored Cross-Site Scripting
high
The Ninja Forms Contact Form plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 2.9.28 due to insufficient input sanitization and output escaping during form submission. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser.
- CVSS:
- 7.2
- Affected:
- up to 2.9.28
- Fixed in:
- 2.9.29
- Disclosed:
- Dec 8, 2015
Ninja Forms – The Contact Form Builder That Grows With You [ninja-forms] < 2.9.29
unknown
The Ninja Forms Contact Form plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 2.9.28 due to insufficient input sanitization and output escaping during form submission. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser.
- Affected:
- up to 2.9.29
- Fixed in:
- 2.9.29
- Disclosed:
- Dec 8, 2015
Ninja Forms Contact Form <= 2.9.27 - CSV Injection
high
The Ninja Forms Contact Form plugin for WordPress is vulnerable to CSV Injection in versions up to, and including, 2.9.27 via the export() function. This allows authenticated attackers to embed untrusted input into exported CSV files, which can result in code execution when these files are downloaded and opened on a lo...
- CVSS:
- 8.4
- Affected:
- up to 2.9.27
- Fixed in:
- 2.9.28
- Disclosed:
- Sep 30, 2015
Ninja Forms – The Contact Form Builder That Grows With You [ninja-forms] < 2.9.28
unknown
There is an unknown vulnerability in this plugin.
Upgrade this plugin.
- Affected:
- up to 2.9.28
- Fixed in:
- 2.9.28
- Disclosed:
- Sep 30, 2015
Ninja Forms – The Contact Form Builder That Grows With You [ninja-forms] < 2.9.28
unknown
The Ninja Forms Contact Form plugin for WordPress is vulnerable to CSV Injection in versions up to, and including, 2.9.27 via the export() function. This allows authenticated attackers to embed untrusted input into exported CSV files, which can result in code execution when these files are downloaded and opened on a lo...
- Affected:
- up to 2.9.28
- Fixed in:
- 2.9.28
- Disclosed:
- Sep 30, 2015
Ninja Forms Contact Form <= 2.9.21 - Reflected Cross-Site Scripting
medium
The Ninja Forms Contact Form plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 2.9.21 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers to inject arbitrary web scripts in pages that execute if they can succ...
- CVSS:
- 5.4
- Affected:
- up to 2.9.21
- Fixed in:
- 2.9.22
- Disclosed:
- Aug 4, 2015
Ninja Forms – The Contact Form Builder That Grows With You [ninja-forms] < 2.9.22
unknown
Because of this vulnerability, the attackers can inject arbitrary JavaScript or HTML code.
Update the plugin.
- Affected:
- up to 2.9.22
- Fixed in:
- 2.9.22
- Disclosed:
- Aug 4, 2015
Ninja Forms – The Contact Form Builder That Grows With You [ninja-forms] < 2.9.22
unknown
The Ninja Forms Contact Form plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 2.9.21 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers to inject arbitrary web scripts in pages that execute if they can succ...
- Affected:
- up to 2.9.22
- Fixed in:
- 2.9.22
- Disclosed:
- Aug 4, 2015
Ninja Forms Contact Form <= 2.9.18 - Cross-Site Scripting
medium
The Ninja Forms Contact Form plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 2.9.18 due to insufficient input sanitization and output escaping. This makes it possible for unauthorized attackers to inject arbitrary web scripts that execute in a victim's browser.
- CVSS:
- 6.1
- Affected:
- up to 2.9.18
- Fixed in:
- 2.9.19
- Disclosed:
- Jun 5, 2015
Ninja Forms – The Contact Form Builder That Grows With You [ninja-forms] < 2.9.19
unknown
Because of this vulnerability, the attackers can inject arbitrary JavaScript or HTML code.
Update the plugin.
- Affected:
- up to 2.9.19
- Fixed in:
- 2.9.19
- Disclosed:
- Jun 5, 2015
Ninja Forms – The Contact Form Builder That Grows With You [ninja-forms] < 2.9.19
unknown
The Ninja Forms Contact Form plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 2.9.18 due to insufficient input sanitization and output escaping. This makes it possible for unauthorized attackers to inject arbitrary web scripts that execute in a victim's browser.
- Affected:
- up to 2.9.19
- Fixed in:
- 2.9.19
- Disclosed:
- Jun 5, 2015
Ninja Forms <= 2.9.10 - Reflected Cross-Site Scripting
medium
The Ninja Forms plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 2.9.10 due to insufficient input sanitization and output escaping on add_query_arg and remove_query_arg. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's...
- CVSS:
- 6.1
- Affected:
- up to 2.9.11
- Fixed in:
- 2.9.11
- Disclosed:
- Apr 20, 2015
Ninja Forms – The Contact Form Builder That Grows With You [ninja-forms] < 2.9.11
unknown
Because of this vulnerability, the attackers can inject arbitrary JavaScript or HTML code.
Upgrade the plugin.
- Affected:
- up to 2.9.11
- Fixed in:
- 2.9.11
- Disclosed:
- Apr 20, 2015
Ninja Forms – The Contact Form Builder That Grows With You [ninja-forms] < 2.9.11
unknown
The Ninja Forms plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 2.9.10 due to insufficient input sanitization and output escaping on add_query_arg and remove_query_arg. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's...
- Affected:
- up to 2.9.11
- Fixed in:
- 2.9.11
- Disclosed:
- Apr 20, 2015
Ninja Forms – The Contact Form Builder That Grows With You [ninja-forms] < 2.8.10
unknown
[en] Unspecified vulnerability in the Ninja Forms plugin before 2.8.10 for WordPress has unknown impact and remote attack vectors related to admin users.
- Affected:
- up to 2.8.10
- Fixed in:
- 2.8.10
- Disclosed:
- Mar 5, 2015
CVE-2014-9688 on NVD →
Ninja Forms – The Contact Form Builder That Grows With You [ninja-forms] < 2.8.9
unknown
[en] Multiple cross-site scripting (XSS) vulnerabilities in the Ninja Forms plugin before 2.8.9 for WordPress allow (1) remote attackers to inject arbitrary web script or HTML via the ninja_forms_field_1 parameter in a ninja_forms_ajax_submit action to wp-admin/admin-ajax.php or (2) remote administrators to inject arbi...
- Affected:
- up to 2.8.9
- Fixed in:
- 2.8.9
- Disclosed:
- Mar 5, 2015
CVE-2015-2220 on NVD →
Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress <= 2.8.8 - Reflected Cross-Site Scripting
medium
The Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘ninja_forms_field_1’ parameter in versions up to, and including, 2.8.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated...
- CVSS:
- 6.1
- Affected:
- up to 2.8.10
- Fixed in:
- 2.8.10
- Disclosed:
- Dec 2, 2014
CVE-2014-9688 on NVD →
Ninja Forms Contact Form <= 2.8.8 - Stored Cross-Site Scripting
high
Multiple cross-site scripting (XSS) vulnerabilities in the Ninja Forms plugin before 2.8.9 for WordPress allow (1) remote attackers to inject arbitrary web script or HTML via the ninja_forms_field_1 parameter in a ninja_forms_ajax_submit action to wp-admin/admin-ajax.php or (2) remote administrators to inject arbitrary...
- CVSS:
- 7.2
- Affected:
- up to 2.8.9
- Fixed in:
- 2.8.9
- Disclosed:
- Nov 20, 2014
CVE-2015-2220 on NVD →
Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress <= 2.8.6 - Reflected Cross-Site Scripting
medium
The Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘update_message’ parameter in versions up to, and including, 2.8.6 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticat...
- CVSS:
- 6.1
- Affected:
- up to 2.8.6
- Fixed in:
- 2.8.7
- Disclosed:
- Nov 6, 2014
CVE-2014-8815 on NVD →
Ninja Forms – The Contact Form Builder That Grows With You [ninja-forms] < 2.7.8
unknown
Ninja Forms plugin is prone to an authorization BYPASS vulnerability that allows an attacker to bypass security restrictions and perform unauthorized actions.
Update the plugin.
- Affected:
- up to 2.7.8
- Fixed in:
- 2.7.8
- Disclosed:
- Sep 8, 2014
Ninja Forms – The Contact Form Builder That Grows With You [ninja-forms] < 2.8.7
unknown
** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.
- Affected:
- up to 2.8.7
- Fixed in:
- 2.8.7
CVE-2014-8815 on NVD →
Ninja Forms – The Contact Form Builder That Grows With You [ninja-forms] < 3.6.11
unknown
The plugin does not validate merge tags provided in the request, which could allow unauthenticated attackers to call any static method present in the blog. One from the plugin in particular could allow for PHP Object Injection when a suitable gadget is also present on the blog. Attackers have been exploiting such issue...
- Affected:
- up to 3.6.11
- Fixed in:
- 3.6.11
Ninja Forms – The Contact Form Builder That Grows With You [ninja-forms] < 3.6.8
unknown
The plugin does not delete the temporary files created when exporting submissions, which could allow unauthenticated attackers to download them and get sensitive information such as the email address of users who submitted a form given that the file is publicly accessible, and with a guessable name
- Affected:
- up to 3.6.8
- Fixed in:
- 3.6.8
Ninja Forms – The Contact Form Builder That Grows With You [ninja-forms] < 3.5.5
unknown
The plugin does not escape generated links before outputting them in attributes, leading to Reflected Cross-Site Scripting
- Affected:
- up to 3.5.5
- Fixed in:
- 3.5.5
Ninja Forms – The Contact Form Builder That Grows With You [ninja-forms] < 3.3.21.3
unknown
Reflected XSS vulnerability in the administrative dashboard.
Blind SQL injection vulnerability in the search filter on the submissions page.
- Affected:
- up to 3.3.21.3
- Fixed in:
- 3.3.21.3
Ninja Forms – The Contact Form Builder That Grows With You [ninja-forms] < 3.3.14
unknown
The Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress WordPress plugin was affected by a Cross-Site Scripting (XSS) in Import Function security vulnerability.
- Affected:
- up to 3.3.14
- Fixed in:
- 3.3.14
Ninja Forms – The Contact Form Builder That Grows With You [ninja-forms] < 2.9.55.2
unknown
The Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress WordPress plugin was affected by an Authenticated SQL Injection security vulnerability.
- Affected:
- up to 2.9.55.2
- Fixed in:
- 2.9.55.2
Ninja Forms – The Contact Form Builder That Grows With You [ninja-forms] < 2.9.52
unknown
The Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress WordPress plugin was affected by a Multiple Authenticated Cross-Site Scripting (XSS) security vulnerability.
- Affected:
- up to 2.9.52
- Fixed in:
- 2.9.52
Ninja Forms – The Contact Form Builder That Grows With You [ninja-forms] < 2.9.28
unknown
The Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress WordPress plugin was affected by a Malicious File Export security vulnerability.
- Affected:
- up to 2.9.28
- Fixed in:
- 2.9.28
Ninja Forms – The Contact Form Builder That Grows With You [ninja-forms] < 2.9.22
unknown
The Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress WordPress plugin was affected by an Authenticated Reflected Cross-Site Scripting (XSS) security vulnerability.
- Affected:
- up to 2.9.22
- Fixed in:
- 2.9.22
Ninja Forms – The Contact Form Builder That Grows With You [ninja-forms] < 2.9.19
unknown
The Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress WordPress plugin was affected by a Cross-Site Scripting (XSS) security vulnerability.
- Affected:
- up to 2.9.19
- Fixed in:
- 2.9.19
Ninja Forms – The Contact Form Builder That Grows With You [ninja-forms] < 2.9.11
unknown
The Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress WordPress plugin was affected by a Cross-Site Scripting (XSS) security vulnerability.
- Affected:
- up to 2.9.11
- Fixed in:
- 2.9.11
Ninja Forms – The Contact Form Builder That Grows With You [ninja-forms] < 3.10.1
unknown
- Affected:
- up to 3.10.1
- Fixed in:
- 3.10.1
CVE-2025-2561 on NVD →
Ninja Forms – The Contact Form Builder That Grows With You [ninja-forms] < 3.10.1
unknown
- Affected:
- up to 3.10.1
- Fixed in:
- 3.10.1
CVE-2025-2560 on NVD →
Ninja Forms – The Contact Form Builder That Grows With You [ninja-forms] < 3.10.1
unknown
- Affected:
- up to 3.10.1
- Fixed in:
- 3.10.1
CVE-2025-2524 on NVD →
Ninja Forms – The Contact Form Builder That Grows With You [ninja-forms] < 3.10.2.2
unknown
- Affected:
- up to 3.10.2.2
- Fixed in:
- 3.10.2.2
CVE-2025-5398 on NVD →