Vulnerability index

Browse CVEs

47 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Ninja Forms MEDIUM 5.3
CVE-2025-14072

The Ninja Forms WordPress plugin before 3.13.3 allows unauthenticated attackers to generate valid access tokens via the REST API which can then be u…

Fix: 3.13.3+
Fix from $1,600 2026-01-02
Ninja Forms HIGH 7.5
CVE-2025-11924

The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up …

Fix: 3.13.1+
Fix from $1,950 2025-12-17
Ninja Forms MEDIUM 5.4
CVE-2025-10498

The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, an…

Fix: 3.12.1+
Fix from $1,600 2025-09-27
Ninja Forms CRITICAL 9.8
CVE-2025-9083

The Ninja Forms WordPress plugin before 3.11.1 unserializes user input via form field, which could allow Unauthenticated users to perform PHP Object…

Fix: 3.11.1+
Fix from $2,300 2025-09-18
Ninja Forms MEDIUM 5.4
CVE-2025-5398

The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the use of a tem…

Fix: 3.10.2.2+
Fix from $1,600 2025-06-27
Ninja Forms MEDIUM 5.4
CVE-2024-13470

The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's sho…

Fix: 3.8.25+
Fix from $1,600 2025-01-30
Ninja Forms MEDIUM 6.3
CVE-2024-12238

The The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to arbitrary shortcode execution in all version…

Fix: 3.8.23+
Fix from $1,600 2024-12-29
Ninja Forms MEDIUM 6.1
CVE-2024-11052

The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the calculations…

Fix: 3.8.20+
Fix from $1,600 2024-12-12
Ninja Forms MEDIUM 6.1
CVE-2024-3866

The Ninja Forms Contact Form plugin for WordPress is vulnerable to Reflected Self-Based Cross-Site Scripting via the 'Referer' header in all versions…

Fix: 3.8.16+
Fix from $1,600 2024-09-25
Ninja Forms File Uploads MEDIUM 6.1
CVE-2024-1596

The Ninja Forms - File Uploads plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an uploaded file (e.g. RTX file) in all versions…

Fix: 3.3.18+
Fix from $1,600 2024-09-07
Ninja Forms MEDIUM 6.1
CVE-2024-7354

The Ninja Forms WordPress plugin before 3.8.11 does not escape an URL before outputting it back in an attribute, leading to a Reflected Cross-Site S…

Fix: 3.8.11+
Fix from $1,600 2024-09-02
Ninja Forms HIGH 8.8
CVE-2024-39628

Cross-Site Request Forgery (CSRF) vulnerability in Saturday Drive Ninja Forms allows Cross Site Request Forgery.This issue affects Ninja Forms: from …

Fix: 3.8.7+
Fix from $1,950 2024-08-26
Ninja Forms CRITICAL 9.8
CVE-2024-37934

Improper Control of Generation of Code ('Code Injection') vulnerability in Saturday Drive Ninja Forms allows Code Injection.This issue affects Ninja …

Fix: 3.8.5+
Fix from $2,300 2024-07-09
Ninja Forms HIGH 8.8
CVE-2023-38393

Missing Authorization vulnerability in Saturday Drive Ninja Forms.This issue affects Ninja Forms: from n/a through 3.6.25.

Fix: after 3.6.26
Fix from $1,950 2024-06-19
Ninja Forms CRITICAL 9.8
CVE-2023-38386

Missing Authorization vulnerability in Saturday Drive Ninja Forms.This issue affects Ninja Forms: from n/a through 3.6.25.

Fix: 3.6.26+
Fix from $2,300 2024-06-19
Ninja Forms HIGH 7.2
CVE-2023-36505

Improper Input Validation vulnerability in Saturday Drive Ninja Forms Contact Form.This issue affects Ninja Forms Contact Form : from n/a through 3.6…

Fix: 3.6.25+
Fix from $1,950 2024-04-17
Ninja Forms HIGH 8.8
CVE-2024-25572

Cross-site request forgery (CSRF) vulnerability exists in Ninja Forms prior to 3.4.31. If a website administrator views a malicious page while loggin…

Fix: 3.4.31+
Fix from $1,950 2024-04-11
Ninja Forms MEDIUM 6.1
CVE-2024-29220

Ninja Forms prior to 3.8.1 contains a cross-site scripting vulnerability in custom fields for labels. If this vulnerability is exploited, an arbitrar…

Fix: 3.8.1+
Fix from $1,600 2024-04-11
Ninja Forms MEDIUM 5.4
CVE-2024-26019

Ninja Forms prior to 3.8.1 contains a cross-site scripting vulnerability in submit processing. If this vulnerability is exploited, an arbitrary scrip…

Fix: 3.8.1+
Fix from $1,600 2024-04-11
Ninja Forms MEDIUM 5.4
CVE-2024-2108

The Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an …

Fix: 3.8.1+
Fix from $1,600 2024-03-29
Ninja Forms CRITICAL 9.8
CVE-2024-0685

The Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to Second Order SQL Injection via the …

Fix: after 3.7.1
Fix from $2,300 2024-02-02
Ninja Forms MEDIUM 5.3
CVE-2023-35909

Uncontrolled Resource Consumption vulnerability in Saturday Drive Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress leading to …

Fix: 3.6.26+
Fix from $1,600 2023-12-07
Ninja Forms MEDIUM 6.1
CVE-2023-37979EPSS 10%

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Saturday Drive Ninja Forms Contact Form plugin <= 3.6.25 versions.

Fix: 3.6.26+
Fix from $1,600 2023-07-27
Ninja Forms MEDIUM 6.1
CVE-2023-1835

The Ninja Forms Contact Form WordPress plugin before 3.6.22 does not properly escape user input before outputting it back in an admin page, leading t…

Fix: 3.6.22+
Fix from $1,600 2023-05-15
Ninja Forms HIGH 7.2
CVE-2022-2903

The Ninja Forms Contact Form WordPress plugin before 3.6.13 unserialises the content of an imported file, which could lead to PHP object injections i…

Fix: 3.6.13+
Fix from $1,950 2022-09-26
Ninja Forms File Uploads CRITICAL 9.8
CVE-2022-0888EPSS 39%

The Ninja Forms - File Uploads Extension WordPress plugin is vulnerable to arbitrary file uploads due to insufficient input file type validation foun…

Fix: after 3.3.0
Fix from $2,300 2022-03-23
Ninja Forms File Uploads MEDIUM 6.1
CVE-2022-0889

The Ninja Forms - File Uploads Extension WordPress plugin is vulnerable to reflected cross-site scripting due to missing sanitization of the files fi…

Fix: after 3.3.12
Fix from $1,600 2022-03-23
Ninja Forms HIGH 7.2
CVE-2021-24889

The Ninja Forms Contact Form WordPress plugin before 3.6.4 does not escape keys of the fields POST parameter, which could allow high privilege users …

Fix: 3.6.4+
Fix from $1,950 2021-11-29
Ninja Forms MEDIUM 6.5
CVE-2021-34647

The Ninja Forms WordPress plugin is vulnerable to sensitive information disclosure via the bulk_export_submissions function found in the ~/includes/R…

Fix: after 3.5.7
Fix from $1,600 2021-09-22
Ninja Forms HIGH 8.8
CVE-2021-24163

The AJAX action, wp_ajax_ninja_forms_sendwp_remote_install_handler, did not have a capability check on it, nor did it have any nonce protection, ther…

Fix: 3.4.34+
Fix from $1,950 2021-04-05