Ninja Forms
by WordPress
Source repositories
CVEs (66)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2016-1209 | Cri | 0.72 | 9.8 | 0.62 | May 14, 2016 | The Ninja Forms plugin before 2.9.42.1 for WordPress allows remote attackers to conduct PHP object injection attacks via crafted serialized values in a POST request. | ||
| CVE-2025-9083 | Cri | 0.64 | 9.8 | 0.01 | Sep 18, 2025 | The Ninja Forms WordPress plugin before 3.11.1 unserializes user input via form field, which could allow Unauthenticated users to perform PHP Object Injection when a suitable gadget is present on the blog. | ||
| CVE-2019-15025 | Cri | 0.64 | 9.8 | 0.02 | Aug 14, 2019 | The ninja-forms plugin before 3.3.21.2 for WordPress has SQL injection in the search filter on the submissions page. | ||
| CVE-2018-20981 | Cri | 0.59 | 9.1 | 0.02 | Aug 22, 2019 | The ninja-forms plugin before 3.3.9 for WordPress has insufficient restrictions on submission-data retrieval during Export Personal Data requests. | ||
| CVE-2026-92438 | Hig | 0.57 | 8.8 | 0.00 | Sep 22, 2026 | The Ninja Forms WordPress plugin 3.15.3 does not escape submitted form field values before outputting them on the submission edit screen in the admin area, which could allow unauthenticated users to submit values through a public form that then execute in the browser of any… | ||
| CVE-2024-25572 | Hig | 0.57 | 8.8 | 0.00 | Apr 11, 2024 | Cross-site request forgery (CSRF) vulnerability exists in Ninja Forms prior to 3.4.31. If a website administrator views a malicious page while logging in, unintended operations may be performed. | ||
| CVE-2018-16308 | Hig | 0.56 | 8.6 | 0.02 | Sep 1, 2018 | The Ninja Forms plugin before 3.3.14.1 for WordPress allows CSV injection. | ||
| CVE-2019-10869 | Hig | 0.53 | 8.1 | 0.08 | May 7, 2019 | Path Traversal and Unrestricted File Upload exists in the Ninja Forms plugin before 3.0.23 for WordPress (when the Uploads add-on is activated). This allows an attacker to traverse the file system to access files and execute code via the includes/fields/upload.php (aka… | ||
| CVE-2026-91827 | Hig | 0.49 | 7.5 | 0.00 | Sep 22, 2026 | The Ninja Forms WordPress plugin 3.15.3 does not prevent user-submitted form field values from being deserialised when an administrator later exports form submissions to CSV, allowing unauthenticated attackers to perform PHP Object Injection; if a suitable POP chain is present… | ||
| CVE-2023-38393 | Hig | 0.49 | 7.6 | 0.01 | Jun 19, 2024 | Missing Authorization vulnerability in Saturday Drive Ninja Forms.This issue affects Ninja Forms: from n/a through 3.6.25. | ||
| CVE-2023-38386 | Hig | 0.49 | 7.6 | 0.01 | Jun 19, 2024 | Missing Authorization vulnerability in Saturday Drive Ninja Forms.This issue affects Ninja Forms: from n/a through 3.6.25. | ||
| CVE-2018-20980 | Hig | 0.49 | 7.5 | 0.01 | Aug 22, 2019 | The ninja-forms plugin before 3.2.15 for WordPress has parameter tampering. | ||
| CVE-2026-94504 | Hig | 0.47 | 7.2 | 0.00 | Sep 22, 2026 | Ninja Forms 3.15.3 stores an anonymous non-RTE textarea value and renders it without safe HTML encoding in the legacy submission editor. An attacker can break out of the textarea with stored script. When an Administrator opens the attacker-known direct submission URL, the script… | ||
| CVE-2024-11052 | Hig | 0.47 | 7.2 | 0.00 | Dec 12, 2024 | The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the calculations parameter in all versions up to, and including, 3.8.19 due to insufficient input sanitization and output escaping. This makes… | ||
| CVE-2024-1596 | Hig | 0.47 | 7.2 | 0.00 | Sep 7, 2024 | The Ninja Forms - File Uploads plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an uploaded file (e.g. RTX file) in all versions up to, and including, 3.3.16 due to insufficient input sanitization and output escaping. This makes it possible for… | ||
| CVE-2026-102385 | Hig | 0.46 | 7.1 | 0.00 | Sep 30, 2026 | Unauthenticated Cross Site Scripting (XSS) in Ninja Forms <= 3.15.3 versions. | ||
| CVE-2026-95515 | Hig | 0.46 | 7.1 | 0.00 | Sep 23, 2026 | Unauthenticated Cross Site Scripting (XSS) in Ninja Forms <= 3.15.3 versions. | ||
| CVE-2026-11363 | Med | 0.43 | 6.6 | 0.01 | Sep 9, 2026 | The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.14.6 via deserialization of untrusted input . This makes it possible for authenticated attackers, with… | ||
| CVE-2026-87870 | Med | 0.42 | 6.4 | 0.00 | Sep 10, 2026 | The Ninja Forms - Scheduled Exports plugin for WordPress is vulnerable to Stored Cross-Site Scripting via REST API Parameters (interval, format, emailTo) in all versions up to, and including, 3.0.3 due to insufficient input sanitization and output escaping. This makes it… | ||
| CVE-2026-2268 | Hig | 0.42 | 7.5 | 0.00 | Feb 10, 2026 | The Ninja Forms plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.14.0. This is due to the unsafe application of the `ninja_forms_merge_tags` filter to user-supplied input within repeater fields, which allows the… |
- risk 0.72cvss 9.8epss 0.62
The Ninja Forms plugin before 2.9.42.1 for WordPress allows remote attackers to conduct PHP object injection attacks via crafted serialized values in a POST request.
- risk 0.64cvss 9.8epss 0.01
The Ninja Forms WordPress plugin before 3.11.1 unserializes user input via form field, which could allow Unauthenticated users to perform PHP Object Injection when a suitable gadget is present on the blog.
- risk 0.64cvss 9.8epss 0.02
The ninja-forms plugin before 3.3.21.2 for WordPress has SQL injection in the search filter on the submissions page.
- risk 0.59cvss 9.1epss 0.02
The ninja-forms plugin before 3.3.9 for WordPress has insufficient restrictions on submission-data retrieval during Export Personal Data requests.
- risk 0.57cvss 8.8epss 0.00
The Ninja Forms WordPress plugin 3.15.3 does not escape submitted form field values before outputting them on the submission edit screen in the admin area, which could allow unauthenticated users to submit values through a public form that then execute in the browser of any…
- risk 0.57cvss 8.8epss 0.00
Cross-site request forgery (CSRF) vulnerability exists in Ninja Forms prior to 3.4.31. If a website administrator views a malicious page while logging in, unintended operations may be performed.
- risk 0.56cvss 8.6epss 0.02
The Ninja Forms plugin before 3.3.14.1 for WordPress allows CSV injection.
- risk 0.53cvss 8.1epss 0.08
Path Traversal and Unrestricted File Upload exists in the Ninja Forms plugin before 3.0.23 for WordPress (when the Uploads add-on is activated). This allows an attacker to traverse the file system to access files and execute code via the includes/fields/upload.php (aka…
- risk 0.49cvss 7.5epss 0.00
The Ninja Forms WordPress plugin 3.15.3 does not prevent user-submitted form field values from being deserialised when an administrator later exports form submissions to CSV, allowing unauthenticated attackers to perform PHP Object Injection; if a suitable POP chain is present…
- risk 0.49cvss 7.6epss 0.01
Missing Authorization vulnerability in Saturday Drive Ninja Forms.This issue affects Ninja Forms: from n/a through 3.6.25.
- risk 0.49cvss 7.6epss 0.01
Missing Authorization vulnerability in Saturday Drive Ninja Forms.This issue affects Ninja Forms: from n/a through 3.6.25.
- risk 0.49cvss 7.5epss 0.01
The ninja-forms plugin before 3.2.15 for WordPress has parameter tampering.
- risk 0.47cvss 7.2epss 0.00
Ninja Forms 3.15.3 stores an anonymous non-RTE textarea value and renders it without safe HTML encoding in the legacy submission editor. An attacker can break out of the textarea with stored script. When an Administrator opens the attacker-known direct submission URL, the script…
- risk 0.47cvss 7.2epss 0.00
The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the calculations parameter in all versions up to, and including, 3.8.19 due to insufficient input sanitization and output escaping. This makes…
- risk 0.47cvss 7.2epss 0.00
The Ninja Forms - File Uploads plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an uploaded file (e.g. RTX file) in all versions up to, and including, 3.3.16 due to insufficient input sanitization and output escaping. This makes it possible for…
- risk 0.46cvss 7.1epss 0.00
Unauthenticated Cross Site Scripting (XSS) in Ninja Forms <= 3.15.3 versions.
- risk 0.46cvss 7.1epss 0.00
Unauthenticated Cross Site Scripting (XSS) in Ninja Forms <= 3.15.3 versions.
- risk 0.43cvss 6.6epss 0.01
The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.14.6 via deserialization of untrusted input . This makes it possible for authenticated attackers, with…
- risk 0.42cvss 6.4epss 0.00
The Ninja Forms - Scheduled Exports plugin for WordPress is vulnerable to Stored Cross-Site Scripting via REST API Parameters (interval, format, emailTo) in all versions up to, and including, 3.0.3 due to insufficient input sanitization and output escaping. This makes it…
- risk 0.42cvss 7.5epss 0.00
The Ninja Forms plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.14.0. This is due to the unsafe application of the `ninja_forms_merge_tags` filter to user-supplied input within repeater fields, which allows the…
Page 1 of 4