Vulnerability index

Browse CVEs

47 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Ninja Forms MEDIUM 6.1
CVE-2021-24165

In the Ninja Forms Contact Form WordPress plugin before 3.4.34, the wp_ajax_nf_oauth_connect AJAX action was vulnerable to open redirect due to the u…

Fix: 3.4.34+
Fix from $1,600 2021-04-05
Ninja Forms MEDIUM 5.4
CVE-2021-24166

The wp_ajax_nf_oauth_disconnect from the Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress WordPress plugin before 3.4.34 had n…

Fix: 3.4.34+
Fix from $1,600 2021-04-05
Ninja Forms MEDIUM 6.5
CVE-2020-36174

The Ninja Forms plugin before 3.4.27.1 for WordPress allows CSRF via services integration.

Fix: 3.4.27.1+
Fix from $1,600 2021-01-06
Ninja Forms MEDIUM 5.3
CVE-2020-36173

The Ninja Forms plugin before 3.4.28 for WordPress lacks escaping for submissions-table fields.

Fix: 3.4.28+
Fix from $1,600 2021-01-06
Ninja Forms MEDIUM 5.3
CVE-2020-36175

The Ninja Forms plugin before 3.4.27.1 for WordPress allows attackers to bypass validation via the email field.

Fix: 3.4.27.1+
Fix from $1,600 2021-01-06
Ninja Forms MEDIUM 6.1
CVE-2020-12462

The ninja-forms plugin before 3.4.24.2 for WordPress allows CSRF with resultant XSS.

Fix: 3.4.24.2+
Fix from $1,600 2020-04-29
Ninja Forms MEDIUM 5.4
CVE-2020-8594

The Ninja Forms plugin 3.4.22 for WordPress has Multiple Stored XSS vulnerabilities via ninja_forms[recaptcha_site_key], ninja_forms[recaptcha_secret…

No fix yet
Fix from $1,600 2020-02-14
Ninja Forms CRITICAL 9.1
CVE-2018-20981

The ninja-forms plugin before 3.3.9 for WordPress has insufficient restrictions on submission-data retrieval during Export Personal Data requests.

Fix: 3.3.9+
Fix from $2,300 2019-08-22
Ninja Forms HIGH 7.5
CVE-2018-20980

The ninja-forms plugin before 3.2.15 for WordPress has parameter tampering.

Fix: 3.2.15+
Fix from $1,950 2019-08-22
Ninja Forms MEDIUM 6.1
CVE-2017-18574

The ninja-forms plugin before 3.0.31 for WordPress has insufficient HTML escaping in the builder.

Fix: 3.0.31+
Fix from $1,600 2019-08-22
Ninjaforms CRITICAL 9.8
CVE-2019-15025

The ninja-forms plugin before 3.3.21.2 for WordPress has SQL injection in the search filter on the submissions page.

Fix: 3.3.21.2+
Fix from $2,300 2019-08-14
Ninja Forms File Uploads HIGH 8.1
CVE-2019-10869EPSS 8%

Path Traversal and Unrestricted File Upload exists in the Ninja Forms plugin before 3.0.23 for WordPress (when the Uploads add-on is activated). This…

Fix: 3.0.23+
Fix from $1,950 2019-05-07
Ninja Forms MEDIUM 6.1
CVE-2018-19796

An open redirect in the Ninja Forms plugin before 3.3.19.1 for WordPress allows Remote Attackers to redirect a user via the lib/StepProcessing/step-p…

Fix: 3.3.19.1+
Fix from $1,600 2018-12-03
Ninja Forms HIGH 8.6
CVE-2018-16308

The Ninja Forms plugin before 3.3.14.1 for WordPress allows CSV injection.

Fix: 3.3.14.1+
Fix from $1,950 2018-09-01
Ninja Forms MEDIUM 6.1
CVE-2018-7280

The Ninja Forms plugin before 3.2.14 for WordPress has XSS.

Fix: 3.2.14+
Fix from $1,600 2018-02-21
Ninja Forms CRITICAL 9.8
CVE-2016-1209EPSS 62%

The Ninja Forms plugin before 2.9.42.1 for WordPress allows remote attackers to conduct PHP object injection attacks via crafted serialized values in…

Fix: after 2.9.42
Fix from $2,300 2016-05-14
Ninja Forms HIGH 7.5
CVE-2014-9688

Unspecified vulnerability in the Ninja Forms plugin before 2.8.10 for WordPress has unknown impact and remote attack vectors related to admin users.

Fix: after 2.8.9
Fix from $1,950 2015-03-05