plugin

Ninja Forms Vulnerabilities

182 known security issues reported for the Ninja Forms WordPress plugin. Most recent disclosed Jul 23, 2026.

4 critical 19 high 56 medium

Running Ninja Forms on your site? Check whether your installed version is affected.

Scan your site free

Ninja Forms <= 3.14.9 - Authenticated (Administrator+) SQL Injection via Import File 'settings' Key

medium

The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to generic SQL Injection via Import File 'settings' Key in all versions up to, and including, 3.14.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query....

CVSS:
4.9
Affected:
up to 3.14.9
Fixed in:
3.14.10
Disclosed:
Jul 23, 2026

CVE-2026-15663 on NVD →

Ninja Forms <= 3.14.1 - Missing Authorization to Unauthenticated Sensitive Information Disclosure via token/refresh REST Endpoint

high

The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to unauthorized access of data due to a missing authorization check on the 'ninja-forms-views/token/refresh' REST callback in all versions up to, and including, 3.14.1. This makes it possible for unauthenticated attackers...

CVSS:
7.5
Affected:
up to 3.14.1
Fixed in:
3.14.2
Disclosed:
Jun 30, 2026

CVE-2026-1239 on NVD →

Ninja Forms - Authenticated (Contributor+) Sensitive Information Disclosure via Block Editor Token vulnerability

medium

Authenticated (Contributor+) Sensitive Information Disclosure via Block Editor Token vulnerability

CVSS:
6.5
Affected:
up to 3.14.1
Fixed in:
3.14.2
Disclosed:
Mar 28, 2026

Ninja Forms <= 3.14.1 - Authenticated (Contributor+) Sensitive Information Disclosure via Block Editor Token

medium

The Ninja Forms - The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.14.1 via a callback function for the admin_enqueue_scripts action handler in blocks/bootstrap.php. This makes it possible for authenticated attacker...

CVSS:
6.5
Affected:
up to 3.14.1
Fixed in:
3.14.2
Disclosed:
Mar 27, 2026

CVE-2026-1307 on NVD →

Ninja Forms <= 3.14.0 - Unauthenticated Information Disclosure in nf_ajax_submit AJAX Action

high

The Ninja Forms plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.14.0. This is due to the unsafe application of the `ninja_forms_merge_tags` filter to user-supplied input within repeater fields, which allows the resolution of `{post_meta:KEY}` merge tags witho...

CVSS:
7.5
Affected:
up to 3.14.0
Fixed in:
3.14.1
Disclosed:
Feb 9, 2026

CVE-2026-2268 on NVD →

Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 3.13.3

unknown

[en] The Ninja Forms WordPress plugin before 3.13.3 allows unauthenticated attackers to generate valid access tokens via the REST API which can then be used to read form submissions.

Affected:
up to 3.13.3
Fixed in:
3.13.3
Disclosed:
Jan 2, 2026

CVE-2025-14072 on NVD →

Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 3.13.3

unknown

[en] The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 3.13.2. This is due to the plugin not properly verifying that a user is authorized before the `ninja-forms-views` REST endpoints return form metada...

Affected:
up to 3.13.3
Fixed in:
3.13.3
Disclosed:
Dec 17, 2025

CVE-2025-11924 on NVD →

Ninja Forms – The Contact Form Builder That Grows With You <= 3.13.2 - Insecure Direct Object Reference to Unauthenticated Sensitive Information Exposure via Unscoped Bearer Token

high

The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 3.13.2. This is due to the plugin not properly verifying that a user is authorized before the `ninja-forms-views` REST endpoints return form metadata an...

CVSS:
7.5
Affected:
up to 3.13.2
Fixed in:
3.13.3
Disclosed:
Dec 16, 2025

CVE-2025-11924 on NVD →

Ninja Forms <= 3.13.2 - Missing Authorization to Unauthenticated Submission Disclosure

high

The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the /ninja-forms-views/token/refresh function in all versions up to, and including, 3.13.2. This makes it possible for unauthenticated attackers to genera...

CVSS:
7.5
Affected:
up to 3.13.2
Fixed in:
3.13.3
Disclosed:
Dec 12, 2025

CVE-2025-14072 on NVD →

Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 3.12.1

unknown

[en] The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.12.0. This is due to missing or incorrect nonce validation when exporting CSV files. This makes it possible for unauthenticated attackers to delete tho...

Affected:
up to 3.12.1
Fixed in:
3.12.1
Disclosed:
Sep 27, 2025

CVE-2025-10498 on NVD →

Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 3.12.1

unknown

[en] The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.12.0. This is due to missing or incorrect nonce validation on the maybe_opt_in() function. This makes it possible for unauthenticated attackers to...

Affected:
up to 3.12.1
Fixed in:
3.12.1
Disclosed:
Sep 27, 2025

CVE-2025-10499 on NVD →

Ninja Forms – The Contact Form Builder That Grows With You <= 3.12.0 - Cross-Site Request Forgery to Plugin Settings Update

medium

The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.12.0. This is due to missing or incorrect nonce validation on the maybe_opt_in() function. This makes it possible for unauthenticated attackers to opt a...

CVSS:
4.3
Affected:
up to 3.12.0
Fixed in:
3.12.1
Disclosed:
Sep 26, 2025

CVE-2025-10499 on NVD →

Ninja Forms – The Contact Form Builder That Grows With You <= 3.12.0 - Cross-Site Request Forgery to Limited File Deletion

medium

The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.12.0. This is due to missing or incorrect nonce validation when exporting CSV files. This makes it possible for unauthenticated attackers to delete those fi...

CVSS:
4.3
Affected:
up to 3.12.0
Fixed in:
3.12.1
Disclosed:
Sep 26, 2025

CVE-2025-10498 on NVD →

Ninja Forms <= 3.11.0 - Unauthenticated PHP Object Injection

high

The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.11.0 via deserialization of untrusted input. This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP chain is present in the...

CVSS:
8.1
Affected:
up to 3.11.0
Fixed in:
3.11.1
Disclosed:
Aug 28, 2025

CVE-2025-9083 on NVD →

Ninja Forms <= 3.10.2.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via CSTI

medium

The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the use of a templating engine in all versions up to, and including, 3.10.2.1 due to insufficient output escaping on user data passed through the template. This makes it possible for auth...

CVSS:
6.4
Affected:
up to 3.10.2.1
Fixed in:
3.10.2.2
Disclosed:
Jun 26, 2025

CVE-2025-5398 on NVD →

Ninja Forms – The Contact Form Builder That Grows With You <= 3.10.0 - Authenticated (Admin+) Stored Cross-Site Scripting

medium

The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 3.10.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administra...

CVSS:
4.4
Affected:
up to 3.10.0
Fixed in:
3.10.1
Disclosed:
Apr 28, 2025

CVE-2025-2561 on NVD →

Ninja Forms – The Contact Form Builder That Grows With You <= 3.10.0 - Authenticated (Admin+) Stored Cross-Site Scripting

medium

The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 3.10.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administra...

CVSS:
4.4
Affected:
up to 3.10.0
Fixed in:
3.10.1
Disclosed:
Apr 28, 2025

CVE-2025-2560 on NVD →

Ninja Forms – The Contact Form Builder That Grows With You <= 3.10.0 - Authenticated (Admin+) Stored Cross-Site Scripting

medium

The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 3.10.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administra...

CVSS:
4.4
Affected:
up to 3.10.0
Fixed in:
3.10.1
Disclosed:
Apr 28, 2025

CVE-2025-2524 on NVD →

Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 3.8.25

unknown

[en] The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode in all versions up to, and including, 3.8.24 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for...

Affected:
up to 3.8.25
Fixed in:
3.8.25
Disclosed:
Jan 30, 2025

CVE-2024-13470 on NVD →

Ninja Forms – The Contact Form Builder That Grows With You <= 3.8.24 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

medium

The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode in all versions up to, and including, 3.8.24 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for auth...

CVSS:
6.4
Affected:
up to 3.8.24
Fixed in:
3.8.25
Disclosed:
Jan 29, 2025

CVE-2024-13470 on NVD →

Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 3.8.23

unknown

[en] The The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 3.8.22. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. T...

Affected:
up to 3.8.23
Fixed in:
3.8.23
Disclosed:
Dec 29, 2024

CVE-2024-12238 on NVD →

Ninja Forms – The Contact Form Builder That Grows With You <= 3.8.22 - Authenticated (Subscriber+) Arbitrary Shortcode Execution

medium

The The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 3.8.22. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This m...

CVSS:
6.3
Affected:
up to 3.8.22
Fixed in:
3.8.23
Disclosed:
Dec 28, 2024

CVE-2024-12238 on NVD →

Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 3.8.20

unknown

[en] The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the calculations parameter in all versions up to, and including, 3.8.19 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attacke...

Affected:
up to 3.8.20
Fixed in:
3.8.20
Disclosed:
Dec 12, 2024

CVE-2024-11052 on NVD →

Ninja Forms – The Contact Form Builder That Grows With You <= 3.8.19 - Unauthenticated Stored Cross-Site Scripting via Form Calculations

high

The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the calculations parameter in all versions up to, and including, 3.8.19 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to...

CVSS:
7.2
Affected:
up to 3.8.19
Fixed in:
3.8.20
Disclosed:
Dec 11, 2024

CVE-2024-11052 on NVD →

Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 3.8.18

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Saturday Drive Ninja Forms allows Stored XSS.This issue affects Ninja Forms: from n/a through 3.8.16.

Affected:
up to 3.8.18
Fixed in:
3.8.18
Disclosed:
Nov 19, 2024

CVE-2024-50514 on NVD →

Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 3.8.18

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Saturday Drive Ninja Forms allows Stored XSS.This issue affects Ninja Forms: from n/a through 3.8.16.

Affected:
up to 3.8.18
Fixed in:
3.8.18
Disclosed:
Nov 19, 2024

CVE-2024-50515 on NVD →

Ninja Forms – The Contact Form Builder That Grows With You <= 3.8.17 - Authenticated (Admin+) Stored Cross-Site Scripting

medium

The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 3.8.17 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administra...

CVSS:
4.4
Affected:
up to 3.8.17
Fixed in:
3.8.18
Disclosed:
Oct 28, 2024

CVE-2024-50515 on NVD →

Ninja Forms – The Contact Form Builder That Grows With You <= 3.8.17 - Authenticated (Admin+) Stored Cross-Site Scripting

medium

The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 3.8.17 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administra...

CVSS:
4.4
Affected:
up to 3.8.17
Fixed in:
3.8.18
Disclosed:
Oct 28, 2024

CVE-2024-50514 on NVD →

Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 3.8.16

unknown

[en] The Ninja Forms Contact Form plugin for WordPress is vulnerable to Reflected Self-Based Cross-Site Scripting via the 'Referer' header in all versions up to, and including, 3.8.15 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web...

Affected:
up to 3.8.16
Fixed in:
3.8.16
Disclosed:
Sep 25, 2024

CVE-2024-3866 on NVD →

Ninja Forms Contact Form <= 3.8.15 - Reflected Self-Based Cross-Site Scripting via Referer

medium

The Ninja Forms Contact Form plugin for WordPress is vulnerable to Reflected Self-Based Cross-Site Scripting via the 'Referer' header in all versions up to, and including, 3.8.15 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scri...

CVSS:
4.7
Affected:
up to 3.8.15
Fixed in:
3.8.16
Disclosed:
Sep 24, 2024

CVE-2024-3866 on NVD →

Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 3.8.12

unknown

[en] Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Saturday Drive Ninja Forms allows Stored XSS.This issue affects Ninja Forms: from n/a through 3.8.11.

Affected:
up to 3.8.12
Fixed in:
3.8.12
Disclosed:
Sep 17, 2024

CVE-2024-43999 on NVD →

Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] >= 3.8.6 - <= 3.8.10

unknown

<p>WordPress Ninja Forms Plugin 3.8.6-3.8.10 is vulnerable to Cross Site Scripting (XSS)</p><p>Software: Ninja Forms</p><p>Link: https://wordpress.org/plugins/ninja-forms/#developers</p><p>Affected Version 3.8.6-3.8.10</p><p>Fixed in version 3.8.11 </p>

Affected:
3.8.6 – 3.8.10
Fixed in:
3.8.10
Disclosed:
Sep 3, 2024

Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 3.8.11

unknown

[en] The Ninja Forms WordPress plugin before 3.8.11 does not escape an URL before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

Affected:
up to 3.8.11
Fixed in:
3.8.11
Disclosed:
Sep 2, 2024

CVE-2024-7354 on NVD →

Ninja Forms <= 3.8.11 - Authenticated (Administrator+) Stored Cross-Site Scripting

medium

The Ninja Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.8.11 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access and above, to inject arbitrary web scripts in pages t...

CVSS:
4.4
Affected:
up to 3.8.11
Fixed in:
3.8.12
Disclosed:
Aug 28, 2024

CVE-2024-43999 on NVD →

Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 3.8.7

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in Saturday Drive Ninja Forms allows Cross Site Request Forgery.This issue affects Ninja Forms: from n/a through 3.8.6.

Affected:
up to 3.8.7
Fixed in:
3.8.7
Disclosed:
Aug 26, 2024

CVE-2024-39628 on NVD →

Ninja Forms – The Contact Form Builder That Grows With You <= 3.8.10 - Reflected Cross-Site Scripting

medium

The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in versions 3.8.6 to 3.8.10. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in...

CVSS:
6.1
Affected:
3.8.6 – 3.8.10
Fixed in:
3.8.11
Disclosed:
Aug 12, 2024

CVE-2024-7354 on NVD →

Ninja Forms <= 3.8.6 - Cross-Site Request Forgery

medium

The Ninja Forms plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.8.6. This is due to missing or incorrect nonce validation on the submit_listener() function. This makes it possible for unauthenticated attackers to update license details via a forged request granted th...

CVSS:
4.3
Affected:
up to 3.8.6
Fixed in:
3.8.7
Disclosed:
Jul 24, 2024

CVE-2024-39628 on NVD →

Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 3.8.5

unknown

[en] Improper Control of Generation of Code ('Code Injection') vulnerability in Saturday Drive Ninja Forms allows Code Injection.This issue affects Ninja Forms: from n/a through 3.8.4.

Affected:
up to 3.8.5
Fixed in:
3.8.5
Disclosed:
Jul 9, 2024

CVE-2024-37934 on NVD →

Ninja Forms <= 3.8.4 - Authenticated (Subscriber+) Arbitrary Shortcode Execution

medium

The The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 3.8.4. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This ma...

CVSS:
4.3
Affected:
up to 3.8.4
Fixed in:
3.8.5
Disclosed:
Jul 4, 2024

CVE-2024-37934 on NVD →

Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 3.6.26

unknown

[en] Missing Authorization vulnerability in Saturday Drive Ninja Forms.This issue affects Ninja Forms: from n/a through 3.6.25.

Affected:
up to 3.6.26
Fixed in:
3.6.26
Disclosed:
Jun 19, 2024

CVE-2023-38386 on NVD →

Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 3.6.26

unknown

[en] Missing Authorization vulnerability in Saturday Drive Ninja Forms.This issue affects Ninja Forms: from n/a through 3.6.25.

Affected:
up to 3.6.26
Fixed in:
3.6.26
Disclosed:
Jun 19, 2024

CVE-2023-38393 on NVD →

Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 3.6.25

unknown

[en] Improper Input Validation vulnerability in Saturday Drive Ninja Forms Contact Form.This issue affects Ninja Forms Contact Form : from n/a through 3.6.24.

Affected:
up to 3.6.25
Fixed in:
3.6.25
Disclosed:
Apr 17, 2024

CVE-2023-36505 on NVD →

Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 3.8.1

unknown

[en] Ninja Forms prior to 3.8.1 contains a cross-site scripting vulnerability in custom fields for labels. If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user who is accessing to the website using the product.

Affected:
up to 3.8.1
Fixed in:
3.8.1
Disclosed:
Apr 11, 2024

CVE-2024-29220 on NVD →

Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 3.8.1

unknown

[en] Ninja Forms prior to 3.8.1 contains a cross-site scripting vulnerability in submit processing. If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user who is accessing to the website using the product.

Affected:
up to 3.8.1
Fixed in:
3.8.1
Disclosed:
Apr 11, 2024

CVE-2024-26019 on NVD →

Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 3.8.1

unknown

[en] Cross-site request forgery (CSRF) vulnerability exists in Ninja Forms prior to 3.4.31. If a website administrator views a malicious page while logging in, unintended operations may be performed.

Affected:
up to 3.8.1
Fixed in:
3.8.1
Disclosed:
Apr 11, 2024

CVE-2024-25572 on NVD →

Ninja Forms – The Contact Form Builder That Grows With You <= 3.8.0 - Authenticated (Admin+) Stored Cross-Site Scripting

medium

The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Stored Cross-Site Scripting via form fields in all versions up to, and including, 3.8.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-...

CVSS:
4.4
Affected:
up to 3.8.0
Fixed in:
3.8.1
Disclosed:
Apr 8, 2024

CVE-2024-26019 on NVD →

Ninja Forms – The Contact Form Builder That Grows With You <= 3.8.0 - Authenticated (Admin+) Stored Cross-Site Scripting

medium

The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Stored Cross-Site Scripting via a form field in all versions up to, and including, 3.8.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator...

CVSS:
4.4
Affected:
up to 3.8.0
Fixed in:
3.8.1
Disclosed:
Apr 8, 2024

CVE-2024-29220 on NVD →

Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 3.8.1

unknown

[en] The Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an image title embedded into a form in all versions up to, and including, 3.8.0 due to insufficient input sanitization and output escaping. This makes it possible for au...

Affected:
up to 3.8.1
Fixed in:
3.8.1
Disclosed:
Mar 29, 2024

CVE-2024-2108 on NVD →

Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 3.8.1

unknown

[en] The Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.8.0. This is due to missing or incorrect nonce validation on the nf_download_all_subs AJAX action. This makes it possible for unauthen...

Affected:
up to 3.8.1
Fixed in:
3.8.1
Disclosed:
Mar 29, 2024

CVE-2024-2113 on NVD →

Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress <= 3.8.0 - Authenticated (Author+) Stored Cross-Site Scripting

medium

The Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an image title embedded into a form in all versions up to, and including, 3.8.0 due to insufficient input sanitization and output escaping. This makes it possible for authent...

CVSS:
4.6
Affected:
up to 3.8.0
Fixed in:
3.8.1
Disclosed:
Mar 28, 2024

CVE-2024-2108 on NVD →

Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress <= 3.8.0 - Cross-Site Request Forgery to Publicly Accessible Form Submission Export

medium

The Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.8.0. This is due to missing or incorrect nonce validation on the nf_download_all_subs AJAX action. This makes it possible for unauthenticat...

CVSS:
4.3
Affected:
up to 3.8.0
Fixed in:
3.8.1
Disclosed:
Mar 28, 2024

CVE-2024-2113 on NVD →

Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 3.7.2

unknown

[en] The Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to Second Order SQL Injection via the email address value submitted through forms in all versions up to, and including, 3.7.1 due to insufficient escaping on the user supplied parameter and lack of suffic...

Affected:
up to 3.7.2
Fixed in:
3.7.2
Disclosed:
Feb 2, 2024

CVE-2024-0685 on NVD →

Ninja Forms Contact Form <= 3.7.1 - Unauthenticated Second Order SQL Injection

medium

The Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to Second Order SQL Injection via the email address value submitted through forms in all versions up to, and including, 3.7.1 due to insufficient escaping on the user supplied parameter and lack of sufficient...

CVSS:
5.9
Affected:
up to 3.7.1
Fixed in:
3.7.2
Disclosed:
Feb 1, 2024

CVE-2024-0685 on NVD →

Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 3.6.26

unknown

[en] Uncontrolled Resource Consumption vulnerability in Saturday Drive Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress leading to DoS.This issue affects Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress: from n/a through 3.6.25.

Affected:
up to 3.6.26
Fixed in:
3.6.26
Disclosed:
Dec 7, 2023

CVE-2023-35909 on NVD →

Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 3.6.34

unknown

[en] The Ninja Forms Contact Form WordPress plugin before 3.6.34 does not sanitize and escape its label fields, which could allow high privilege users such as admin to perform Stored XSS attacks. Only users with the unfiltered_html capability can perform this, and such users are already allowed to use JS in posts/comme...

Affected:
up to 3.6.34
Fixed in:
3.6.34
Disclosed:
Nov 6, 2023

CVE-2023-5530 on NVD →

Ninja Forms Contact Form <= 3.6.33 - Authenticated (Admin+) Stored Cross-Site Scripting

medium

The Ninja Forms Contact Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 3.6.33 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, t...

CVSS:
4.4
Affected:
up to 3.6.33
Fixed in:
3.6.34
Disclosed:
Oct 16, 2023

CVE-2023-5530 on NVD →

Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 3.6.26

unknown

[en] The Ninja Forms WordPress Ninja Forms Contact Form WordPress plugin before 3.6.26 was affected by a HTML Injection security vulnerability.

Affected:
up to 3.6.26
Fixed in:
3.6.26
Disclosed:
Aug 30, 2023

CVE-2023-4109 on NVD →

Ninja Forms <= 3.6.25 - Authenticated (Administrator+) Stored HTML Injection

medium

The Ninja Forms plugin for WordPress is vulnerable to Stored HTML Injection in versions up to, and including, 3.6.25 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with administrator access to inject arbitrary HTML content in pages that will execute whenev...

CVSS:
4.4
Affected:
up to 3.6.25
Fixed in:
3.6.26
Disclosed:
Aug 7, 2023

CVE-2023-4109 on NVD →

Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 3.6.26

unknown

[en] Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Saturday Drive Ninja Forms Contact Form plugin <= 3.6.25 versions.

Affected:
up to 3.6.26
Fixed in:
3.6.26
Disclosed:
Jul 27, 2023

CVE-2023-37979 on NVD →

Ninja Forms <= 3.6.25 - Reflected Cross-Site Scripting via 'data'

medium

The Ninja Forms plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘data’ parameter in versions up to, and including, 3.6.25 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if...

CVSS:
6.1
Affected:
up to 3.6.25
Fixed in:
3.6.26
Disclosed:
Jul 25, 2023

CVE-2023-37979 on NVD →

Ninja Forms <= 3.6.25 - Missing Authorization to Contributor+ Form Submission Export

medium

The Ninja Forms plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the export_listen() function in versions up to, and including, 3.6.25. This makes it possible for authenticated attackers, with contributor-level access and above, to export form submissions via a prop...

CVSS:
5.3
Affected:
up to 3.6.25
Fixed in:
3.6.26
Disclosed:
Jul 25, 2023

CVE-2023-38386 on NVD →

Ninja Forms <= 3.6.25 - Missing Authorization to Form Submission Export

medium

The Ninja Forms plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the processing() function in versions up to, and including, 3.6.25. This makes it possible for authenticated attackers, with subscriber-level access and above, to export form submissions via the nf_dow...

CVSS:
4.3
Affected:
up to 3.6.25
Fixed in:
3.6.26
Disclosed:
Jul 25, 2023

CVE-2023-38393 on NVD →

Ninja Forms <= 3.6.25 - Denial of Service via Large Form Submissions

medium

The Ninja Forms plugin for WordPress is vulnerable to denial of service in versions up to, and including, 3.6.25. This is due to insufficient controls on form submissions. This makes it possible for unauthenticated attackers to craft form submissions with excessive extra data that may exceed the capacity of the databas...

CVSS:
5.3
Affected:
up to 3.6.25
Fixed in:
3.6.26
Disclosed:
Jul 7, 2023

CVE-2023-35909 on NVD →

Ninja Forms <= 3.6.24 - Authenticated (Admin+) Arbitrary File Deletion

medium

The Ninja Forms plugin for WordPress is vulnerable to arbitrary file deletions in versions up to, and including, 3.6.24. This is due to insufficient restriction on the file path that can be supplied during file deletion. This makes it possible for authenticated attackers, with administrative-level access, to delete arb...

CVSS:
6.5
Affected:
up to 3.6.24
Fixed in:
3.6.25
Disclosed:
Jun 22, 2023

CVE-2023-36505 on NVD →

Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 3.6.22

unknown

[en] The Ninja Forms Contact Form WordPress plugin before 3.6.22 does not properly escape user input before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

Affected:
up to 3.6.22
Fixed in:
3.6.22
Disclosed:
May 15, 2023

CVE-2023-1835 on NVD →

Ninja Forms Contact Form <= 3.6.21 - Reflected Cross-Site Scripting via 'title'

medium

The Ninja Forms Contact Form plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'title' parameter in versions up to, and including, 3.6.21 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages t...

CVSS:
6.1
Affected:
up to 3.6.21
Fixed in:
3.6.22
Disclosed:
Apr 24, 2023

CVE-2023-1835 on NVD →

Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 3.6.13

unknown

[en] The Ninja Forms Contact Form WordPress plugin before 3.6.13 unserialises the content of an imported file, which could lead to PHP object injections issues when an admin import (intentionally or not) a malicious file and a suitable gadget chain is present on the blog.

Affected:
up to 3.6.13
Fixed in:
3.6.13
Disclosed:
Sep 26, 2022

CVE-2022-2903 on NVD →

Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress <= 3.6.12 - Authenticated (Administrator+) PHP Objection Injection

high

The Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 3.6.12 via deserialization of untrusted input. This allows administrator-level attackers to inject a PHP Object. No POP chain is present in the vulner...

CVSS:
7.2
Affected:
up to 3.6.12
Fixed in:
3.6.13
Disclosed:
Sep 5, 2022

CVE-2022-2903 on NVD →

Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 3.6.10

unknown

[en] The Ninja Forms Contact Form WordPress plugin before 3.6.10 does not sanitise and escape field labels, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

Affected:
up to 3.6.10
Fixed in:
3.6.10
Disclosed:
Jul 4, 2022

CVE-2021-25056 on NVD →

Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 3.6.11

unknown

[en] The Ninja Forms Contact Form WordPress plugin before 3.6.10 does not sanitize and escape some imported data, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

Affected:
up to 3.6.11
Fixed in:
3.6.11
Disclosed:
Jul 4, 2022

CVE-2021-25066 on NVD →

Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 3.6.10

unknown

[en] Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Saturday Drive's Ninja Forms Contact Form plugin <= 3.6.9 at WordPress via "label".

Affected:
up to 3.6.10
Fixed in:
3.6.10
Disclosed:
Jun 16, 2022

CVE-2021-36827 on NVD →

Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress <= 3.6.10 - Code Injection

critical

The Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to code injection in versions up to, and including 3.6.10 due to insufficient validation on Merge Tags that makes it possible to call arbitrary Ninja Form classes. This could lead to a variety of actions, howe...

CVSS:
9.8
Affected:
up to 3.0.34.1, 3.1 – 3.1.9, 3.2 – 3.2.27, 3.3 – 3.3.21.3, 3.4 – 3.4.34.1, 3.5 – 3.5.8.3, 3.6 – 3.6.10
Fixed in:
3.0.34.2
Disclosed:
Jun 15, 2022

Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] <= 3.6.10

unknown

Unauthenticated PHP Object Injection vulnerability discovered in WordPress Ninja Forms plugin (versions <= 3.6.10). Update the WordPress Ninja Forms plugin to the latest available version (at least 3.6.11).

Affected:
up to 3.6.10
Fixed in:
3.6.10
Disclosed:
Jun 15, 2022

Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 3.6.11

unknown

The Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to code injection in versions up to, and including 3.6.10 due to insufficient validation on Merge Tags that makes it possible to call arbitrary Ninja Form classes. This could lead to a variety of actions, howe...

Affected:
up to 3.6.11
Fixed in:
3.6.11
Disclosed:
Jun 15, 2022

Ninja Forms Contact Form <= 3.6.9 - Cross-Site Scripting via field label

medium

The Ninja Forms Contact Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via field labels in versions up to, and including, 3.6.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with administrative level permissions and above to inject...

CVSS:
4.8
Affected:
up to 3.6.9
Fixed in:
3.6.10
Disclosed:
Jun 13, 2022

CVE-2021-25056 on NVD →

Ninja Ninja Forms Contact Form <= 3.6.10 - Authenticated (Admin+) Stored Cross-Site Scripting via import

medium

The Ninja Forms Contact Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters found in an import in versions up to, and including, 3.6.10 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with administrative level permi...

CVSS:
5.5
Affected:
up to 3.6.10
Fixed in:
3.6.11
Disclosed:
Jun 10, 2022

CVE-2021-25066 on NVD →

Ninja Forms Contact Form <= 3.6.9 - Authenticated (Admin+) Cross-Site Scripting via label

medium

The Ninja Forms Contact Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'label' parameter in versions up to, and including, 3.6.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with administrative level permissions and above...

CVSS:
5.5
Affected:
up to 3.6.9
Fixed in:
3.6.10
Disclosed:
Jun 7, 2022

CVE-2021-36827 on NVD →

Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress <= 3.6.9 - Cross-Site Request Forgery to Field Import and PHP Object Injection

high

The Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including 3.6.9, due to missing nonce validation on the import_fields_listener() function that makes it possible for unauthenticated attackers to import new...

CVSS:
8.8
Affected:
up to 3.6.9
Fixed in:
3.6.10
Disclosed:
Jun 7, 2022

Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 3.6.10

unknown

The Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including 3.6.9, due to missing nonce validation on the import_fields_listener() function that makes it possible for unauthenticated attackers to import new...

Affected:
up to 3.6.10
Fixed in:
3.6.10
Disclosed:
Jun 7, 2022

Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress <= 3.6.7 - Email Address Disclosure

medium

The Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to Sensitive Data Exposure in versions up to, and including, 3.6.7. This can allow unauthenticated attackers to extract sensitive data including other users' email addresses which can be used to help perform f...

CVSS:
5.3
Affected:
up to 3.6.7
Fixed in:
3.6.8
Disclosed:
Mar 22, 2022

Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 3.6.8

unknown

Unauthenticated Email Address Disclosure vulnerability discovered by Agence Web Coheractio in WordPress Ninja Forms plugin (versions <= 3.6.7).

Affected:
up to 3.6.8
Fixed in:
3.6.8
Disclosed:
Mar 22, 2022

Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 3.6.8

unknown

The Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to Sensitive Data Exposure in versions up to, and including, 3.6.7. This can allow unauthenticated attackers to extract sensitive data including other users' email addresses which can be used to help perform f...

Affected:
up to 3.6.8
Fixed in:
3.6.8
Disclosed:
Mar 22, 2022

Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 3.6.4

unknown

[en] The Ninja Forms Contact Form WordPress plugin before 3.6.4 does not escape keys of the fields POST parameter, which could allow high privilege users to perform SQL injections attacks

Affected:
up to 3.6.4
Fixed in:
3.6.4
Disclosed:
Nov 29, 2021

CVE-2021-24889 on NVD →

Ninja Forms Contact Form <= 3.6.3 - Authenticated SQL Injection

high

The Ninja Forms Contact Form WordPress plugin before 3.6.4 does not escape keys of the fields POST parameter, which could allow high privilege users to perform SQL injections attacks

CVSS:
7.2
Affected:
up to 3.6.4
Fixed in:
3.6.4
Disclosed:
Oct 26, 2021

CVE-2021-24889 on NVD →

Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 3.6.8

unknown

[en] The Ninja Forms Contact Form WordPress plugin before 3.5.8.2 does not sanitise and escape the custom class name of the form field created, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

Affected:
up to 3.6.8
Fixed in:
3.6.8
Disclosed:
Oct 25, 2021

CVE-2021-24381 on NVD →

Ninja Forms <= 3.5.8.1 - Cross-Site Scripting

medium

The Ninja Forms Contact Form WordPress plugin before 3.5.8.2 does not sanitise and escape the custom class name of the form field created, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

CVSS:
4.8
Affected:
up to 3.5.8.2
Fixed in:
3.5.8.2
Disclosed:
Sep 27, 2021

CVE-2021-24381 on NVD →

Ninja Forms <= 3.5.7 - Unprotected REST-API to Sensitive Information Disclosure

medium

The Ninja Forms WordPress plugin is vulnerable to sensitive information disclosure via the bulk_export_submissions function found in the ~/includes/Routes/Submissions.php file, in versions up to and including 3.5.7. This allows authenticated attackers to export all Ninja Forms submissions data via the /ninja-forms-subm...

CVSS:
6.5
Affected:
up to 3.5.7
Fixed in:
3.5.8
Disclosed:
Sep 22, 2021

CVE-2021-34647 on NVD →

Ninja Forms <= 3.5.7 - Unprotected REST-API to Email Injection

medium

The Ninja Forms WordPress plugin is vulnerable to arbitrary email sending via the trigger_email_action function found in the ~/includes/Routes/Submissions.php file, in versions up to and including 3.5.7. This allows authenticated attackers to send arbitrary emails from the affected server via the /ninja-forms-submissio...

CVSS:
6.4
Affected:
up to 3.5.7
Fixed in:
3.5.8
Disclosed:
Sep 22, 2021

CVE-2021-34648 on NVD →

Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 3.5.8

unknown

[en] The Ninja Forms WordPress plugin is vulnerable to sensitive information disclosure via the bulk_export_submissions function found in the ~/includes/Routes/Submissions.php file, in versions up to and including 3.5.7. This allows authenticated attackers to export all Ninja Forms submissions data via the /ninja-forms...

Affected:
up to 3.5.8
Fixed in:
3.5.8
Disclosed:
Sep 22, 2021

CVE-2021-34647 on NVD →

Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 3.5.8

unknown

[en] The Ninja Forms WordPress plugin is vulnerable to arbitrary email sending via the trigger_email_action function found in the ~/includes/Routes/Submissions.php file, in versions up to and including 3.5.7. This allows authenticated attackers to send arbitrary emails from the affected server via the /ninja-forms-subm...

Affected:
up to 3.5.8
Fixed in:
3.5.8
Disclosed:
Sep 22, 2021

CVE-2021-34648 on NVD →

Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 3.4.34

unknown

[en] In the Ninja Forms Contact Form WordPress plugin before 3.4.34, the wp_ajax_nf_oauth_connect AJAX action was vulnerable to open redirect due to the use of a user supplied redirect parameter and no protection in place.

Affected:
up to 3.4.34
Fixed in:
3.4.34
Disclosed:
Apr 5, 2021

CVE-2021-24165 on NVD →

Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 3.4.34

unknown

[en] The AJAX action, wp_ajax_ninja_forms_sendwp_remote_install_handler, did not have a capability check on it, nor did it have any nonce protection, therefore making it possible for low-level users, such as subscribers, to install and activate the SendWP Ninja Forms Contact Form – The Drag and Drop Form Builder for Wo...

Affected:
up to 3.4.34
Fixed in:
3.4.34
Disclosed:
Apr 5, 2021

CVE-2021-24163 on NVD →

Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 3.4.34.1

unknown

[en] In the Ninja Forms Contact Form WordPress plugin before 3.4.34.1, low-level users, such as subscribers, were able to trigger the action, wp_ajax_nf_oauth, and retrieve the connection url needed to establish a connection. They could also retrieve the client_id for an already established OAuth connection.

Affected:
up to 3.4.34.1
Fixed in:
3.4.34.1
Disclosed:
Apr 5, 2021

CVE-2021-24164 on NVD →

Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 3.4.34

unknown

[en] The wp_ajax_nf_oauth_disconnect from the Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress WordPress plugin before 3.4.34 had no nonce protection making it possible for attackers to craft a request to disconnect a site's OAuth connection.

Affected:
up to 3.4.34
Fixed in:
3.4.34
Disclosed:
Apr 5, 2021

CVE-2021-24166 on NVD →

Ninja Forms Contact Form <= 3.4.33 - Authenticated SendWP Plugin Installation and Client Secret Key Disclosure

high

The AJAX action, wp_ajax_ninja_forms_sendwp_remote_install_handler, did not have a capability check on it, nor did it have any nonce protection, therefore making it possible for low-level users, such as subscribers, to install and activate the SendWP Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPre...

CVSS:
8.8
Affected:
up to 3.4.34
Fixed in:
3.4.34
Disclosed:
Feb 16, 2021

CVE-2021-24163 on NVD →

Ninja Forms Contact Form <= 3.4.33 - Administrator Open Redirect

medium

In the Ninja Forms Contact Form WordPress plugin before 3.4.34, the wp_ajax_nf_oauth_connect AJAX action was vulnerable to open redirect due to the use of a user supplied redirect parameter and no protection in place.

CVSS:
6.1
Affected:
up to 3.4.34
Fixed in:
3.4.34
Disclosed:
Feb 16, 2021

CVE-2021-24165 on NVD →

Ninja Forms Contact Form <= 3.4.33 - Cross-Site Request Forgery to OAuth Service Disconnection

medium

The wp_ajax_nf_oauth_disconnect from the Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress WordPress plugin before 3.4.34 had no nonce protection making it possible for attackers to craft a request to disconnect a site's OAuth connection.

CVSS:
5.4
Affected:
up to 3.4.34
Fixed in:
3.4.34
Disclosed:
Feb 16, 2021

CVE-2021-24166 on NVD →

Ninja Forms <= 3.4.34 - Authenticated OAuth Connection Key Disclosure

medium

In the Ninja Forms Contact Form WordPress plugin before 3.4.34.1, low-level users, such as subscribers, were able to trigger the action, wp_ajax_nf_oauth, and retrieve the connection url needed to establish a connection. They could also retrieve the client_id for an already established OAuth connection.

CVSS:
4.3
Affected:
up to 3.4.34.1
Fixed in:
3.4.34.1
Disclosed:
Feb 16, 2021

CVE-2021-24164 on NVD →

Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 3.4.34

unknown

Cross-Site Request Forgery (CSRF) vulnerability found by Chloe Chamberland in WordPress Ninja Forms Contact Form plugin (versions <= 3.4.33).

Affected:
up to 3.4.34
Fixed in:
3.4.34
Disclosed:
Feb 16, 2021

Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 3.4.34

unknown

Administrator Open Redirect vulnerability found by Chloe Chamberland in WordPress Ninja Forms Contact Form plugin (versions <= 3.4.33).

Affected:
up to 3.4.34
Fixed in:
3.4.34
Disclosed:
Feb 16, 2021

Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 3.4.34

unknown

Authenticated OAuth Connection Key Disclosure vulnerability found by Chloe Chamberland in WordPress Ninja Forms Contact Form plugin (versions <= 3.4.33).

Affected:
up to 3.4.34
Fixed in:
3.4.34
Disclosed:
Feb 16, 2021

Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 3.4.34

unknown

Authenticated SendWP Plugin Installation and Client Secret Key Disclosure vulnerability found by Chloe Chamberland in WordPress Ninja Forms Contact Form plugin (versions <= 3.4.33).

Affected:
up to 3.4.34
Fixed in:
3.4.34
Disclosed:
Feb 16, 2021

Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 3.4.28

unknown

[en] The Ninja Forms plugin before 3.4.28 for WordPress lacks escaping for submissions-table fields.

Affected:
up to 3.4.28
Fixed in:
3.4.28
Disclosed:
Jan 6, 2021

CVE-2020-36173 on NVD →

Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 3.4.27.1

unknown

[en] The Ninja Forms plugin before 3.4.27.1 for WordPress allows CSRF via services integration.

Affected:
up to 3.4.27.1
Fixed in:
3.4.27.1
Disclosed:
Jan 6, 2021

CVE-2020-36174 on NVD →

Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 3.4.27.1

unknown

[en] The Ninja Forms plugin before 3.4.27.1 for WordPress allows attackers to bypass validation via the email field.

Affected:
up to 3.4.27.1
Fixed in:
3.4.27.1
Disclosed:
Jan 6, 2021

CVE-2020-36175 on NVD →

Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress <= 3.4.27 - Cross-Site Request Forgery to Plugin Installation

high

The Ninja Forms plugin before 3.4.27.1 for WordPress allows CSRF via services integration. This makes it possible for attackers to install arbitrary plugins.

CVSS:
8.8
Affected:
up to 3.4.27
Fixed in:
3.4.27.1
Disclosed:
Sep 22, 2020

CVE-2020-36174 on NVD →

Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress <= 3.4.27 - Validation Bypass via Email Field

medium

The Ninja Forms plugin before 3.4.27.1 for WordPress allows attackers to bypass validation via the email field.

CVSS:
5.3
Affected:
up to 3.4.27
Fixed in:
3.4.27.1
Disclosed:
Sep 22, 2020

CVE-2020-36175 on NVD →

Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 3.4.27.1

unknown

Cross-Site Request Forgery (CSRF) leading to Arbitrary Plugin Installation vulnerability found by Slavco Mihajloski in WordPress Ninja Forms plugin (versions <= 3.4.27).

Affected:
up to 3.4.27.1
Fixed in:
3.4.27.1
Disclosed:
Sep 22, 2020

Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress <= 3.4.27.1 - Stored Cross-Site Scripting

medium

The Ninja Forms plugin before 3.4.28 for WordPress lacks escaping for submissions-table fields.

CVSS:
6.5
Affected:
up to 3.4.27.1
Fixed in:
3.4.28
Disclosed:
Sep 20, 2020

CVE-2020-36173 on NVD →

Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 3.4.24.2

unknown

[en] The ninja-forms plugin before 3.4.24.2 for WordPress allows CSRF with resultant XSS.

Affected:
up to 3.4.24.2
Fixed in:
3.4.24.2
Disclosed:
Apr 29, 2020

CVE-2020-12462 on NVD →

Ninja Forms Contact Form <= 3.4.24.1 - Cross-Site Request Forgery leading to Stored Cross-Site Scripting

medium

The Ninja Forms plugin before 3.4.24.2 for WordPress allows CSRF with resultant XSS.

CVSS:
6.1
Affected:
up to 3.4.24.2
Fixed in:
3.4.24.2
Disclosed:
Apr 28, 2020

CVE-2020-12462 on NVD →

Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 3.4.23

unknown

[en] The Ninja Forms plugin 3.4.22 for WordPress has Multiple Stored XSS vulnerabilities via ninja_forms[recaptcha_site_key], ninja_forms[recaptcha_secret_key], ninja_forms[recaptcha_lang], or ninja_forms[date_format].

Affected:
up to 3.4.23
Fixed in:
3.4.23
Disclosed:
Feb 14, 2020

CVE-2020-8594 on NVD →

Ninja Forms Contact Form <= 3.4.22 - Stored Cross-Site Scripting

medium

The Ninja Forms plugin 3.4.22 for WordPress has Multiple Stored XSS vulnerabilities via ninja_forms[recaptcha_site_key], ninja_forms[recaptcha_secret_key], ninja_forms[recaptcha_lang], or ninja_forms[date_format].

CVSS:
6.4
Affected:
up to 3.4.23
Fixed in:
3.4.23
Disclosed:
Feb 3, 2020

CVE-2020-8594 on NVD →

Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 3.3.9

unknown

[en] The ninja-forms plugin before 3.3.9 for WordPress has insufficient restrictions on submission-data retrieval during Export Personal Data requests.

Affected:
up to 3.3.9
Fixed in:
3.3.9
Disclosed:
Aug 22, 2019

CVE-2018-20981 on NVD →

Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 3.2.15

unknown

[en] The ninja-forms plugin before 3.2.15 for WordPress has parameter tampering.

Affected:
up to 3.2.15
Fixed in:
3.2.15
Disclosed:
Aug 22, 2019

CVE-2018-20980 on NVD →

Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 3.0.31

unknown

[en] The ninja-forms plugin before 3.0.31 for WordPress has insufficient HTML escaping in the builder.

Affected:
up to 3.0.31
Fixed in:
3.0.31
Disclosed:
Aug 22, 2019

CVE-2017-18574 on NVD →

Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 3.3.21.2

unknown

[en] The ninja-forms plugin before 3.3.21.2 for WordPress has SQL injection in the search filter on the submissions page.

Affected:
up to 3.3.21.2
Fixed in:
3.3.21.2
Disclosed:
Aug 14, 2019

CVE-2019-15025 on NVD →

Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 3.3.21.3

unknown

Cross-Site Scripting (XSS) vulnerability found in WordPress Ninja Forms plugin (versions <= 3.3.21).

Affected:
up to 3.3.21.3
Fixed in:
3.3.21.3
Disclosed:
Jun 25, 2019

Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 3.3.21.3

unknown

SQL injection (SQLi) vulnerability found in WordPress Ninja Forms plugin (versions <= 3.3.21).

Affected:
up to 3.3.21.3
Fixed in:
3.3.21.3
Disclosed:
Jun 25, 2019

Ninja Forms Contact Form <= 3.3.21.1 - SQL Injection

critical

The ninja-forms plugin before 3.3.21.2 for WordPress has SQL injection in the search filter on the submissions page.

CVSS:
9.8
Affected:
up to 3.3.21.1
Fixed in:
3.3.21.2
Disclosed:
Jan 7, 2019

CVE-2019-15025 on NVD →

Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 3.3.19.1

unknown

[en] An open redirect in the Ninja Forms plugin before 3.3.19.1 for WordPress allows Remote Attackers to redirect a user via the lib/StepProcessing/step-processing.php (aka submissions download page) redirect parameter.

Affected:
up to 3.3.19.1
Fixed in:
3.3.19.1
Disclosed:
Dec 3, 2018

CVE-2018-19796 on NVD →

Ninja Forms Contact Form <= 3.3.19 - Authenticated Open Redirect

medium

An open redirect in the Ninja Forms plugin before 3.3.19.1 for WordPress allows Remote Attackers to redirect a user via the lib/StepProcessing/step-processing.php (aka submissions download page) redirect parameter.

CVSS:
4.7
Affected:
up to 3.3.19
Fixed in:
3.3.19.1
Disclosed:
Dec 1, 2018

CVE-2018-19796 on NVD →

Ninja Forms Contact Form <= 3.3.17 - Cross-Site Scripting via begin_date, end_date, or form_id Parameter

medium

XSS in the Ninja Forms plugin before 3.3.18 for WordPress allows Remote Attackers to execute JavaScript via the includes/Admin/Menus/Submissions.php (aka submissions page) begin_date, end_date, or form_id parameter.

CVSS:
6.1
Affected:
up to 3.3.18
Fixed in:
3.3.18
Disclosed:
Nov 15, 2018

CVE-2018-19287 on NVD →

Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 3.3.18

unknown

[en] XSS in the Ninja Forms plugin before 3.3.18 for WordPress allows Remote Attackers to execute JavaScript via the includes/Admin/Menus/Submissions.php (aka submissions page) begin_date, end_date, or form_id parameter.

Affected:
up to 3.3.18
Fixed in:
3.3.18
Disclosed:
Nov 15, 2018

CVE-2018-19287 on NVD →

Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 3.3.14

unknown

[en] The Ninja Forms plugin before 3.3.14.1 for WordPress allows CSV injection.

Affected:
up to 3.3.14
Fixed in:
3.3.14
Disclosed:
Sep 1, 2018

CVE-2018-16308 on NVD →

Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 3.3.14

unknown

CSV Injection vulnerability fund by Mostafa Gharzi in WordPress Ninja Forms plugin (versions <= 3.3.13).

Affected:
up to 3.3.14
Fixed in:
3.3.14
Disclosed:
Aug 28, 2018

Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 3.3.14

unknown

Cross-Site Scripting (XSS) vulnerability found in WordPress Ninja Forms plugin (versions <= 3.3.13).

Affected:
up to 3.3.14
Fixed in:
3.3.14
Disclosed:
Aug 28, 2018

Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress <= 3.3.13 - Cross-Site Scripting

high

The Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to Cross-Site Scripting via the form input function in versions up to, and including, 3.3.13 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrar...

CVSS:
8.3
Affected:
up to 3.3.14
Fixed in:
3.3.14
Disclosed:
Aug 27, 2018

Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 3.3.14

unknown

The Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to Cross-Site Scripting via the form input function in versions up to, and including, 3.3.13 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrar...

Affected:
up to 3.3.14
Fixed in:
3.3.14
Disclosed:
Aug 27, 2018

Ninja Forms Contact Form <= 3.3.13 - CSV Injection

high

The Ninja Forms plugin before 3.3.14.1 for WordPress allows CSV injection.

CVSS:
8.6
Affected:
up to 3.3.13
Fixed in:
3.3.14
Disclosed:
Aug 19, 2018

CVE-2018-16308 on NVD →

Ninja Forms <= 3.3.8 - Insufficient Restrictions during Export Personal Data requests

critical

The ninja-forms plugin before 3.3.9 for WordPress has insufficient restrictions on submission-data retrieval during Export Personal Data requests.

CVSS:
9.1
Affected:
up to 3.3.8
Fixed in:
3.3.9
Disclosed:
Jul 6, 2018

CVE-2018-20981 on NVD →

Ninja Forms Contact Form <= 3.2.14 - Parameter Tampering

high

The ninja-forms plugin before 3.2.15 for WordPress has parameter tampering.

CVSS:
7.5
Affected:
up to 3.2.15
Fixed in:
3.2.15
Disclosed:
Feb 26, 2018

CVE-2018-20980 on NVD →

Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 3.2.14

unknown

[en] The Ninja Forms plugin before 3.2.14 for WordPress has XSS.

Affected:
up to 3.2.14
Fixed in:
3.2.14
Disclosed:
Feb 21, 2018

CVE-2018-7280 on NVD →

Ninja Forms Contact Form <= 3.2.13 - Cross-Site Scripting

medium

The Ninja Forms plugin before 3.2.14 for WordPress has XSS.

CVSS:
6.1
Affected:
up to 3.2.14
Fixed in:
3.2.14
Disclosed:
Feb 20, 2018

CVE-2018-7280 on NVD →

Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress <= 3.0.31 - Arbitrary Wordpress Shortcode Injection

medium

The Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to Arbitrary Wordpress Shortcode Injection in versions up to, and including, 3.0.31. This makes it possible for unauthenticated attackers to preview un-published forms and could possibly be used to leverage fu...

CVSS:
5.3
Affected:
up to 3.0.31
Fixed in:
3.0.32
Disclosed:
Apr 17, 2017

Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 3.0.32

unknown

The Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to Arbitrary Wordpress Shortcode Injection in versions up to, and including, 3.0.31. This makes it possible for unauthenticated attackers to preview un-published forms and could possibly be used to leverage fu...

Affected:
up to 3.0.32
Fixed in:
3.0.32
Disclosed:
Apr 17, 2017

Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress <= 3.0.30 - HTML Injection

medium

The ninja-forms plugin before 3.0.31 for WordPress has insufficient HTML escaping in the builder.

CVSS:
6.1
Affected:
up to 3.0.31
Fixed in:
3.0.31
Disclosed:
Mar 7, 2017

CVE-2017-18574 on NVD →

Ninja Forms Contact Form <= 2.9.55.1 - Authenticated SQL Injection

high

The Ninja Forms Contact Form plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 2.9.55.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for Subscriber-level attackers to append additiona...

CVSS:
8.8
Affected:
up to 2.9.55.2
Fixed in:
2.9.55.2
Disclosed:
Aug 16, 2016

Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 2.9.55.2

unknown

There is a bug in this plugin. It could leak the site’s usernames and hashed passwords. Update the plugin.

Affected:
up to 2.9.55.2
Fixed in:
2.9.55.2
Disclosed:
Aug 16, 2016

Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 2.9.55.2

unknown

The Ninja Forms Contact Form plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 2.9.55.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for Subscriber-level attackers to append additiona...

Affected:
up to 2.9.55.2
Fixed in:
2.9.55.2
Disclosed:
Aug 16, 2016

Ninja Forms Contact Form <= 2.9.51 - Multiple Reflected Cross-Site Scripting

medium

The Ninja Forms Contact Form plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via multiple parameters in versions before 2.9.52 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if th...

CVSS:
6.1
Affected:
up to 2.9.52
Fixed in:
2.9.52
Disclosed:
Jul 19, 2016

Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 2.9.52

unknown

Because of this vulnerability, attackers can inject malicious JavaScript code into the application. Update this plugin.

Affected:
up to 2.9.52
Fixed in:
2.9.52
Disclosed:
Jul 19, 2016

Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 2.9.52

unknown

The Ninja Forms Contact Form plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via multiple parameters in versions before 2.9.52 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if th...

Affected:
up to 2.9.52
Fixed in:
2.9.52
Disclosed:
Jul 19, 2016

Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] >= 2.9.36 - <= 2.9.42

unknown

[en] The Ninja Forms plugin before 2.9.42.1 for WordPress allows remote attackers to conduct PHP object injection attacks via crafted serialized values in a POST request.

Affected:
2.9.36 – 2.9.42
Fixed in:
2.9.42
Disclosed:
May 14, 2016

CVE-2016-1209 on NVD →

Ninja Forms Contact Form 2.9.36 - 2.9.42 - PHP Object Injection

high

The Ninja Forms plugin before 2.9.42.1 for WordPress allows remote attackers to conduct PHP object injection attacks via crafted serialized values in a POST request.

CVSS:
8.1
Affected:
2.9.36 – 2.9.42
Fixed in:
2.9.42.1
Disclosed:
May 13, 2016

CVE-2016-1209 on NVD →

Ninja Forms Contact Form 2.9.36 - 2.9.42 - Unauthenticated Arbitrary File Upload

critical

Versions 2.9.36 to 2.9.42 of the Ninja Forms plugin contain an unauthenticated file upload vulnerability, allowing guests to upload arbitrary PHP code that can be executed in the context of the web server.

CVSS:
9.8
Affected:
2.9.36 – 2.9.42
Fixed in:
2.9.42.1
Disclosed:
May 5, 2016

CVE-2016-1209 on NVD →

Ninja Forms Contact Form <= 2.9.28 - Stored Cross-Site Scripting

high

The Ninja Forms Contact Form plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 2.9.28 due to insufficient input sanitization and output escaping during form submission. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser.

CVSS:
7.2
Affected:
up to 2.9.28
Fixed in:
2.9.29
Disclosed:
Dec 8, 2015

Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 2.9.29

unknown

The Ninja Forms Contact Form plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 2.9.28 due to insufficient input sanitization and output escaping during form submission. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser.

Affected:
up to 2.9.29
Fixed in:
2.9.29
Disclosed:
Dec 8, 2015

Ninja Forms Contact Form <= 2.9.27 - CSV Injection

high

The Ninja Forms Contact Form plugin for WordPress is vulnerable to CSV Injection in versions up to, and including, 2.9.27 via the export() function. This allows authenticated attackers to embed untrusted input into exported CSV files, which can result in code execution when these files are downloaded and opened on a lo...

CVSS:
8.4
Affected:
up to 2.9.27
Fixed in:
2.9.28
Disclosed:
Sep 30, 2015

Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 2.9.28

unknown

There is an unknown vulnerability in this plugin. Upgrade this plugin.

Affected:
up to 2.9.28
Fixed in:
2.9.28
Disclosed:
Sep 30, 2015

Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 2.9.28

unknown

The Ninja Forms Contact Form plugin for WordPress is vulnerable to CSV Injection in versions up to, and including, 2.9.27 via the export() function. This allows authenticated attackers to embed untrusted input into exported CSV files, which can result in code execution when these files are downloaded and opened on a lo...

Affected:
up to 2.9.28
Fixed in:
2.9.28
Disclosed:
Sep 30, 2015

Ninja Forms Contact Form <= 2.9.21 - Reflected Cross-Site Scripting

medium

The Ninja Forms Contact Form plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 2.9.21 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers to inject arbitrary web scripts in pages that execute if they can succ...

CVSS:
5.4
Affected:
up to 2.9.21
Fixed in:
2.9.22
Disclosed:
Aug 4, 2015

Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 2.9.22

unknown

Because of this vulnerability, the attackers can inject arbitrary JavaScript or HTML code. Update the plugin.

Affected:
up to 2.9.22
Fixed in:
2.9.22
Disclosed:
Aug 4, 2015

Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 2.9.22

unknown

The Ninja Forms Contact Form plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 2.9.21 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers to inject arbitrary web scripts in pages that execute if they can succ...

Affected:
up to 2.9.22
Fixed in:
2.9.22
Disclosed:
Aug 4, 2015

Ninja Forms Contact Form <= 2.9.18 - Cross-Site Scripting

medium

The Ninja Forms Contact Form plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 2.9.18 due to insufficient input sanitization and output escaping. This makes it possible for unauthorized attackers to inject arbitrary web scripts that execute in a victim's browser.

CVSS:
6.1
Affected:
up to 2.9.18
Fixed in:
2.9.19
Disclosed:
Jun 5, 2015

Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 2.9.19

unknown

Because of this vulnerability, the attackers can inject arbitrary JavaScript or HTML code. Update the plugin.

Affected:
up to 2.9.19
Fixed in:
2.9.19
Disclosed:
Jun 5, 2015

Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 2.9.19

unknown

The Ninja Forms Contact Form plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 2.9.18 due to insufficient input sanitization and output escaping. This makes it possible for unauthorized attackers to inject arbitrary web scripts that execute in a victim's browser.

Affected:
up to 2.9.19
Fixed in:
2.9.19
Disclosed:
Jun 5, 2015

Ninja Forms <= 2.9.10 - Reflected Cross-Site Scripting

medium

The Ninja Forms plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 2.9.10 due to insufficient input sanitization and output escaping on add_query_arg and remove_query_arg. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's...

CVSS:
6.1
Affected:
up to 2.9.11
Fixed in:
2.9.11
Disclosed:
Apr 20, 2015

Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 2.9.11

unknown

Because of this vulnerability, the attackers can inject arbitrary JavaScript or HTML code. Upgrade the plugin.

Affected:
up to 2.9.11
Fixed in:
2.9.11
Disclosed:
Apr 20, 2015

Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 2.9.11

unknown

The Ninja Forms plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 2.9.10 due to insufficient input sanitization and output escaping on add_query_arg and remove_query_arg. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's...

Affected:
up to 2.9.11
Fixed in:
2.9.11
Disclosed:
Apr 20, 2015

Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 2.8.10

unknown

[en] Unspecified vulnerability in the Ninja Forms plugin before 2.8.10 for WordPress has unknown impact and remote attack vectors related to admin users.

Affected:
up to 2.8.10
Fixed in:
2.8.10
Disclosed:
Mar 5, 2015

CVE-2014-9688 on NVD →

Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 2.8.9

unknown

[en] Multiple cross-site scripting (XSS) vulnerabilities in the Ninja Forms plugin before 2.8.9 for WordPress allow (1) remote attackers to inject arbitrary web script or HTML via the ninja_forms_field_1 parameter in a ninja_forms_ajax_submit action to wp-admin/admin-ajax.php or (2) remote administrators to inject arbi...

Affected:
up to 2.8.9
Fixed in:
2.8.9
Disclosed:
Mar 5, 2015

CVE-2015-2220 on NVD →

Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress <= 2.8.8 - Reflected Cross-Site Scripting

medium

The Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘ninja_forms_field_1’ parameter in versions up to, and including, 2.8.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated...

CVSS:
6.1
Affected:
up to 2.8.10
Fixed in:
2.8.10
Disclosed:
Dec 2, 2014

CVE-2014-9688 on NVD →

Ninja Forms Contact Form <= 2.8.8 - Stored Cross-Site Scripting

high

Multiple cross-site scripting (XSS) vulnerabilities in the Ninja Forms plugin before 2.8.9 for WordPress allow (1) remote attackers to inject arbitrary web script or HTML via the ninja_forms_field_1 parameter in a ninja_forms_ajax_submit action to wp-admin/admin-ajax.php or (2) remote administrators to inject arbitrary...

CVSS:
7.2
Affected:
up to 2.8.9
Fixed in:
2.8.9
Disclosed:
Nov 20, 2014

CVE-2015-2220 on NVD →

Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress <= 2.8.6 - Reflected Cross-Site Scripting

medium

The Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘update_message’ parameter in versions up to, and including, 2.8.6 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticat...

CVSS:
6.1
Affected:
up to 2.8.6
Fixed in:
2.8.7
Disclosed:
Nov 6, 2014

CVE-2014-8815 on NVD →

Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 2.7.8

unknown

Ninja Forms plugin is prone to an authorization BYPASS vulnerability that allows an attacker to bypass security restrictions and perform unauthorized actions. Update the plugin.

Affected:
up to 2.7.8
Fixed in:
2.7.8
Disclosed:
Sep 8, 2014

Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 2.8.7

unknown

** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.

Affected:
up to 2.8.7
Fixed in:
2.8.7

CVE-2014-8815 on NVD →

Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 3.6.11

unknown

The plugin does not validate merge tags provided in the request, which could allow unauthenticated attackers to call any static method present in the blog. One from the plugin in particular could allow for PHP Object Injection when a suitable gadget is also present on the blog. Attackers have been exploiting such issue...

Affected:
up to 3.6.11
Fixed in:
3.6.11

Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 3.6.8

unknown

The plugin does not delete the temporary files created when exporting submissions, which could allow unauthenticated attackers to download them and get sensitive information such as the email address of users who submitted a form given that the file is publicly accessible, and with a guessable name

Affected:
up to 3.6.8
Fixed in:
3.6.8

Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 3.5.5

unknown

The plugin does not escape generated links before outputting them in attributes, leading to Reflected Cross-Site Scripting

Affected:
up to 3.5.5
Fixed in:
3.5.5

Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 3.3.21.3

unknown

Reflected XSS vulnerability in the administrative dashboard. Blind SQL injection vulnerability in the search filter on the submissions page.

Affected:
up to 3.3.21.3
Fixed in:
3.3.21.3

Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 3.3.14

unknown

The Ninja Forms Contact Form &ndash; The Drag and Drop Form Builder for WordPress WordPress plugin was affected by a Cross-Site Scripting (XSS) in Import Function security vulnerability.

Affected:
up to 3.3.14
Fixed in:
3.3.14

Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 2.9.55.2

unknown

The Ninja Forms Contact Form &ndash; The Drag and Drop Form Builder for WordPress WordPress plugin was affected by an Authenticated SQL Injection security vulnerability.

Affected:
up to 2.9.55.2
Fixed in:
2.9.55.2

Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 2.9.52

unknown

The Ninja Forms Contact Form &ndash; The Drag and Drop Form Builder for WordPress WordPress plugin was affected by a Multiple Authenticated Cross-Site Scripting (XSS) security vulnerability.

Affected:
up to 2.9.52
Fixed in:
2.9.52

Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 2.9.28

unknown

The Ninja Forms Contact Form &ndash; The Drag and Drop Form Builder for WordPress WordPress plugin was affected by a Malicious File Export security vulnerability.

Affected:
up to 2.9.28
Fixed in:
2.9.28

Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 2.9.22

unknown

The Ninja Forms Contact Form &ndash; The Drag and Drop Form Builder for WordPress WordPress plugin was affected by an Authenticated Reflected Cross-Site Scripting (XSS) security vulnerability.

Affected:
up to 2.9.22
Fixed in:
2.9.22

Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 2.9.19

unknown

The Ninja Forms Contact Form &ndash; The Drag and Drop Form Builder for WordPress WordPress plugin was affected by a Cross-Site Scripting (XSS) security vulnerability.

Affected:
up to 2.9.19
Fixed in:
2.9.19

Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 2.9.11

unknown

The Ninja Forms Contact Form &ndash; The Drag and Drop Form Builder for WordPress WordPress plugin was affected by a Cross-Site Scripting (XSS) security vulnerability.

Affected:
up to 2.9.11
Fixed in:
2.9.11

Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 3.10.1

unknown
Affected:
up to 3.10.1
Fixed in:
3.10.1

CVE-2025-2561 on NVD →

Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 3.10.1

unknown
Affected:
up to 3.10.1
Fixed in:
3.10.1

CVE-2025-2560 on NVD →

Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 3.10.1

unknown
Affected:
up to 3.10.1
Fixed in:
3.10.1

CVE-2025-2524 on NVD →

Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 3.10.2.2

unknown
Affected:
up to 3.10.2.2
Fixed in:
3.10.2.2

CVE-2025-5398 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database