Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
MEDIUM 5.3
CVE-2025-14072
The Ninja Forms WordPress plugin before 3.13.3 allows unauthenticated attackers to generate valid access tokens via the REST API which can then be u…
Ninja Forms
3.13.3+
HIGH 7.5
CVE-2025-11924
The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up …
Ninja Forms
3.13.1+
MEDIUM 5.4
CVE-2025-10498
The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, an…
Ninja Forms
3.12.1+
CRITICAL 9.8
CVE-2025-9083
The Ninja Forms WordPress plugin before 3.11.1 unserializes user input via form field, which could allow Unauthenticated users to perform PHP Object…
Ninja Forms
3.11.1+
MEDIUM 5.4
CVE-2025-5398
The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the use of a tem…
Ninja Forms
3.10.2.2+
MEDIUM 5.4
CVE-2024-13470
The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's sho…
Ninja Forms
3.8.25+
MEDIUM 6.3
CVE-2024-12238
The The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to arbitrary shortcode execution in all version…
Ninja Forms
3.8.23+
MEDIUM 6.1
CVE-2024-11052
The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the calculations…
Ninja Forms
3.8.20+
MEDIUM 6.1
CVE-2024-3866
The Ninja Forms Contact Form plugin for WordPress is vulnerable to Reflected Self-Based Cross-Site Scripting via the 'Referer' header in all versions…
Ninja Forms
3.8.16+
MEDIUM 6.1
CVE-2024-1596
The Ninja Forms - File Uploads plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an uploaded file (e.g. RTX file) in all versions…
Ninja Forms File Uploads
3.3.18+
MEDIUM 6.1
CVE-2024-7354
The Ninja Forms WordPress plugin before 3.8.11 does not escape an URL before outputting it back in an attribute, leading to a Reflected Cross-Site S…
Ninja Forms
3.8.11+
HIGH 8.8
CVE-2024-39628
Cross-Site Request Forgery (CSRF) vulnerability in Saturday Drive Ninja Forms allows Cross Site Request Forgery.This issue affects Ninja Forms: from …
Ninja Forms
3.8.7+
CRITICAL 9.8
CVE-2024-37934
Improper Control of Generation of Code ('Code Injection') vulnerability in Saturday Drive Ninja Forms allows Code Injection.This issue affects Ninja …
Ninja Forms
3.8.5+
HIGH 8.8
CVE-2023-38393
Missing Authorization vulnerability in Saturday Drive Ninja Forms.This issue affects Ninja Forms: from n/a through 3.6.25.
Ninja Forms
after 3.6.26
CRITICAL 9.8
CVE-2023-38386
Missing Authorization vulnerability in Saturday Drive Ninja Forms.This issue affects Ninja Forms: from n/a through 3.6.25.
Ninja Forms
3.6.26+
HIGH 7.2
CVE-2023-36505
Improper Input Validation vulnerability in Saturday Drive Ninja Forms Contact Form.This issue affects Ninja Forms Contact Form : from n/a through 3.6…
Ninja Forms
3.6.25+
HIGH 8.8
CVE-2024-25572
Cross-site request forgery (CSRF) vulnerability exists in Ninja Forms prior to 3.4.31. If a website administrator views a malicious page while loggin…
Ninja Forms
3.4.31+
MEDIUM 6.1
CVE-2024-29220
Ninja Forms prior to 3.8.1 contains a cross-site scripting vulnerability in custom fields for labels. If this vulnerability is exploited, an arbitrar…
Ninja Forms
3.8.1+
MEDIUM 5.4
CVE-2024-26019
Ninja Forms prior to 3.8.1 contains a cross-site scripting vulnerability in submit processing. If this vulnerability is exploited, an arbitrary scrip…
Ninja Forms
3.8.1+
MEDIUM 5.4
CVE-2024-2108
The Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an …
Ninja Forms
3.8.1+
CRITICAL 9.8
CVE-2024-0685
The Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to Second Order SQL Injection via the …
Ninja Forms
after 3.7.1
MEDIUM 5.3
CVE-2023-35909
Uncontrolled Resource Consumption vulnerability in Saturday Drive Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress leading to …
Ninja Forms
3.6.26+
MEDIUM 6.1
CVE-2023-37979EPSS 10%
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Saturday Drive Ninja Forms Contact Form plugin <= 3.6.25 versions.
Ninja Forms
3.6.26+
MEDIUM 6.1
CVE-2023-1835
The Ninja Forms Contact Form WordPress plugin before 3.6.22 does not properly escape user input before outputting it back in an admin page, leading t…
Ninja Forms
3.6.22+
HIGH 7.2
CVE-2022-2903
The Ninja Forms Contact Form WordPress plugin before 3.6.13 unserialises the content of an imported file, which could lead to PHP object injections i…
Ninja Forms
3.6.13+
CRITICAL 9.8
CVE-2022-0888EPSS 39%
The Ninja Forms - File Uploads Extension WordPress plugin is vulnerable to arbitrary file uploads due to insufficient input file type validation foun…
Ninja Forms File Uploads
after 3.3.0
MEDIUM 6.1
CVE-2022-0889
The Ninja Forms - File Uploads Extension WordPress plugin is vulnerable to reflected cross-site scripting due to missing sanitization of the files fi…
Ninja Forms File Uploads
after 3.3.12
HIGH 7.2
CVE-2021-24889
The Ninja Forms Contact Form WordPress plugin before 3.6.4 does not escape keys of the fields POST parameter, which could allow high privilege users …
Ninja Forms
3.6.4+
MEDIUM 6.5
CVE-2021-34647
The Ninja Forms WordPress plugin is vulnerable to sensitive information disclosure via the bulk_export_submissions function found in the ~/includes/R…
Ninja Forms
after 3.5.7
HIGH 8.8
CVE-2021-24163
The AJAX action, wp_ajax_ninja_forms_sendwp_remote_install_handler, did not have a capability check on it, nor did it have any nonce protection, ther…
Ninja Forms
3.4.34+