cleantalk
Vulnerabilities and Security Researches

Vulnerabilities and security researches forninja-forms ninja-forms

Direction: ascending
Jun 06, 2024

Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress # CVE-2021-24381

CVE, Research URL

CVE-2021-24381

Date
Oct 25, 2021
Research Description
The Ninja Forms Contact Form WordPress plugin before 3.5.8.2 does not sanitise and escape the custom class name of the form field created, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.
Affected versions
max 3.6.8.
Status
vulnerable

Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress # CVE-2021-24163

CVE, Research URL

CVE-2021-24163

Date
Apr 06, 2021
Research Description
The AJAX action, wp_ajax_ninja_forms_sendwp_remote_install_handler, did not have a capability check on it, nor did it have any nonce protection, therefore making it possible for low-level users, such as subscribers, to install and activate the SendWP Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress WordPress plugin before 3.4.34 and retrieve the client_secret key needed to establish the SendWP connection while also installing the SendWP plugin.
Affected versions
max 3.4.34.
Status
vulnerable

Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress # CVE-2021-24889

CVE, Research URL

CVE-2021-24889

Date
Nov 29, 2021
Research Description
The Ninja Forms Contact Form WordPress plugin before 3.6.4 does not escape keys of the fields POST parameter, which could allow high privilege users to perform SQL injections attacks
Affected versions
max 3.6.4.
Status
vulnerable

Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress # CVE-2021-34647

CVE, Research URL

CVE-2021-34647

Date
Sep 22, 2021
Research Description
The Ninja Forms WordPress plugin is vulnerable to sensitive information disclosure via the bulk_export_submissions function found in the ~/includes/Routes/Submissions.php file, in versions up to and including 3.5.7. This allows authenticated attackers to export all Ninja Forms submissions data via the /ninja-forms-submissions/export REST API which can include personally identifiable information.
Affected versions
max 3.5.8.
Status
vulnerable

Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress # CVE-2021-24164

CVE, Research URL

CVE-2021-24164

Date
Apr 06, 2021
Research Description
In the Ninja Forms Contact Form WordPress plugin before 3.4.34.1, low-level users, such as subscribers, were able to trigger the action, wp_ajax_nf_oauth, and retrieve the connection url needed to establish a connection. They could also retrieve the client_id for an already established OAuth connection.
Affected versions
max 3.4.34.1.
Status
vulnerable

Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress # CVE-2020-36173

CVE, Research URL

CVE-2020-36173

Date
Jan 06, 2021
Research Description
The Ninja Forms plugin before 3.4.28 for WordPress lacks escaping for submissions-table fields.
Affected versions
max 3.4.28.
Status
vulnerable

Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress # CVE-2020-36174

CVE, Research URL

CVE-2020-36174

Date
Jan 06, 2021
Research Description
The Ninja Forms plugin before 3.4.27.1 for WordPress allows CSRF via services integration.
Affected versions
max 3.4.27.1.
Status
vulnerable

Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress # CVE-2020-8594

CVE, Research URL

CVE-2020-8594

Date
Feb 15, 2020
Research Description
The Ninja Forms plugin 3.4.22 for WordPress has Multiple Stored XSS vulnerabilities via ninja_forms[recaptcha_site_key], ninja_forms[recaptcha_secret_key], ninja_forms[recaptcha_lang], or ninja_forms[date_format].
Affected versions
max 3.4.23.
Status
vulnerable

Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress # CVE-2018-19796

CVE, Research URL

CVE-2018-19796

Date
Dec 03, 2018
Research Description
An open redirect in the Ninja Forms plugin before 3.3.19.1 for WordPress allows Remote Attackers to redirect a user via the lib/StepProcessing/step-processing.php (aka submissions download page) redirect parameter.
Affected versions
max 3.3.19.1.
Status
vulnerable

Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress # CVE-2018-20981

CVE, Research URL

CVE-2018-20981

Date
Aug 22, 2019
Research Description
The ninja-forms plugin before 3.3.9 for WordPress has insufficient restrictions on submission-data retrieval during Export Personal Data requests.
Affected versions
max 3.3.9.
Status
vulnerable

Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress # CVE-2021-34648

CVE, Research URL

CVE-2021-34648

Date
Sep 22, 2021
Research Description
The Ninja Forms WordPress plugin is vulnerable to arbitrary email sending via the trigger_email_action function found in the ~/includes/Routes/Submissions.php file, in versions up to and including 3.5.7. This allows authenticated attackers to send arbitrary emails from the affected server via the /ninja-forms-submissions/email-action REST API which can be used to socially engineer victims.
Affected versions
max 3.5.8.
Status
vulnerable

Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress # CVE-2021-24166

CVE, Research URL

CVE-2021-24166

Date
Apr 06, 2021
Research Description
The wp_ajax_nf_oauth_disconnect from the Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress WordPress plugin before 3.4.34 had no nonce protection making it possible for attackers to craft a request to disconnect a site's OAuth connection.
Affected versions
max 3.4.34.
Status
vulnerable

Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress # CVE-2020-36175

CVE, Research URL

CVE-2020-36175

Date
Jan 06, 2021
Research Description
The Ninja Forms plugin before 3.4.27.1 for WordPress allows attackers to bypass validation via the email field.
Affected versions
max 3.4.27.1.
Status
vulnerable

Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress # CVE-2020-12462

CVE, Research URL

CVE-2020-12462

Date
Apr 29, 2020
Research Description
The ninja-forms plugin before 3.4.24.2 for WordPress allows CSRF with resultant XSS.
Affected versions
max 3.4.24.2.
Status
vulnerable

Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress # CVE-2018-20980

CVE, Research URL

CVE-2018-20980

Date
Aug 22, 2019
Research Description
The ninja-forms plugin before 3.2.15 for WordPress has parameter tampering.
Affected versions
max 3.2.15.
Status
vulnerable

Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress # CVE-2017-18574

CVE, Research URL

CVE-2017-18574

Date
Aug 22, 2019
Research Description
The ninja-forms plugin before 3.0.31 for WordPress has insufficient HTML escaping in the builder.
Affected versions
max 3.0.31.
Status
vulnerable

Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress # CVE-2021-24165

CVE, Research URL

CVE-2021-24165

Date
Apr 06, 2021
Research Description
In the Ninja Forms Contact Form WordPress plugin before 3.4.34, the wp_ajax_nf_oauth_connect AJAX action was vulnerable to open redirect due to the use of a user supplied redirect parameter and no protection in place.
Affected versions
max 3.4.34.
Status
vulnerable

Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress # CVE-2019-15025

CVE, Research URL

CVE-2019-15025

Date
Aug 14, 2019
Research Description
The ninja-forms plugin before 3.3.21.2 for WordPress has SQL injection in the search filter on the submissions page.
Affected versions
max 3.3.21.2.
Status
vulnerable

Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress # CVE-2014-9688

CVE, Research URL

CVE-2014-9688

Date
Mar 05, 2015
Research Description
Unspecified vulnerability in the Ninja Forms plugin before 2.8.10 for WordPress has unknown impact and remote attack vectors related to admin users.
Affected versions
max 2.8.10.
Status
vulnerable

Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress # CVE-2018-19287

CVE, Research URL

CVE-2018-19287

Date
Nov 15, 2018
Research Description
XSS in the Ninja Forms plugin before 3.3.18 for WordPress allows Remote Attackers to execute JavaScript via the includes/Admin/Menus/Submissions.php (aka submissions page) begin_date, end_date, or form_id parameter.
Affected versions
max 3.3.18.
Status
vulnerable

Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress # CVE-2015-2220

CVE, Research URL

CVE-2015-2220

Date
Mar 05, 2015
Research Description
Multiple cross-site scripting (XSS) vulnerabilities in the Ninja Forms plugin before 2.8.9 for WordPress allow (1) remote attackers to inject arbitrary web script or HTML via the ninja_forms_field_1 parameter in a ninja_forms_ajax_submit action to wp-admin/admin-ajax.php or (2) remote administrators to inject arbitrary web script or HTML via the fields[1] parameter to wp-admin/post.php.
Affected versions
max 2.8.9.
Status
vulnerable

Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress # CVE-2018-16308

CVE, Research URL

CVE-2018-16308

Date
Sep 01, 2018
Research Description
The Ninja Forms plugin before 3.3.14.1 for WordPress allows CSV injection.
Affected versions
max 3.3.14.
Status
vulnerable

Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress # CVE-2016-1209

CVE, Research URL

CVE-2016-1209

Date
May 14, 2016
Research Description
The Ninja Forms plugin before 2.9.42.1 for WordPress allows remote attackers to conduct PHP object injection attacks via crafted serialized values in a POST request.
Affected versions
Min 2.9.36, max 2.9.42.
Status
vulnerable

Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress # CVE-2021-25056

CVE, Research URL

CVE-2021-25056

Date
Jul 04, 2022
Research Description
The Ninja Forms Contact Form WordPress plugin before 3.6.10 does not sanitise and escape field labels, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.
Affected versions
max 3.6.10.
Status
vulnerable

Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress # CVE-2021-36827

CVE, Research URL

CVE-2021-36827

Date
Jun 16, 2022
Research Description
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Saturday Drive's Ninja Forms Contact Form plugin <= 3.6.9 at WordPress via "label".
Affected versions
max 3.6.10.
Status
vulnerable

Ninja Forms Contact Form &#8211; The Drag and Drop Form Builder for WordPress # CVE-2021-25066

CVE, Research URL

CVE-2021-25066

Date
Jul 04, 2022
Research Description
The Ninja Forms Contact Form WordPress plugin before 3.6.10 does not sanitize and escape some imported data, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.
Affected versions
max 3.6.11.
Status
vulnerable

Ninja Forms Contact Form &#8211; The Drag and Drop Form Builder for WordPress # CVE-2022-2903

CVE, Research URL

CVE-2022-2903

Date
Sep 26, 2022
Research Description
The Ninja Forms Contact Form WordPress plugin before 3.6.13 unserialises the content of an imported file, which could lead to PHP object injections issues when an admin import (intentionally or not) a malicious file and a suitable gadget chain is present on the blog.
Affected versions
max 3.6.13.
Status
vulnerable

Ninja Forms Contact Form &#8211; The Drag and Drop Form Builder for WordPress # CVE-2023-37979

CVE, Research URL

CVE-2023-37979

Date
Jul 27, 2023
Research Description
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Saturday Drive Ninja Forms Contact Form plugin <= 3.6.25 versions.
Affected versions
max 3.6.26.
Status
vulnerable

Ninja Forms Contact Form &#8211; The Drag and Drop Form Builder for WordPress # CVE-2023-1835

CVE, Research URL

CVE-2023-1835

Date
May 15, 2023
Research Description
The Ninja Forms Contact Form WordPress plugin before 3.6.22 does not properly escape user input before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
Affected versions
max 3.6.22.
Status
vulnerable

Ninja Forms Contact Form &#8211; The Drag and Drop Form Builder for WordPress # CVE-2023-36505

CVE, Research URL

CVE-2023-36505

Date
Apr 17, 2024
Research Description
Improper Input Validation vulnerability in Saturday Drive Ninja Forms Contact Form.This issue affects Ninja Forms Contact Form : from n/a through 3.6.24.
Affected versions
max 3.6.25.
Status
vulnerable

Ninja Forms Contact Form &#8211; The Drag and Drop Form Builder for WordPress # CVE-2023-35909

CVE, Research URL

CVE-2023-35909

Date
Dec 07, 2023
Research Description
Uncontrolled Resource Consumption vulnerability in Saturday Drive Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress leading to DoS.This issue affects Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress: from n/a through 3.6.25.
Affected versions
max 3.6.26.
Status
vulnerable

Ninja Forms Contact Form &#8211; The Drag and Drop Form Builder for WordPress # CVE-2023-4109

CVE, Research URL

CVE-2023-4109

Date
Aug 30, 2023
Research Description
The Ninja Forms WordPress Ninja Forms Contact Form WordPress plugin before 3.6.26 was affected by a HTML Injection security vulnerability.
Affected versions
max 3.6.26.
Status
vulnerable

Ninja Forms Contact Form &#8211; The Drag and Drop Form Builder for WordPress # CVE-2023-5530

CVE, Research URL

CVE-2023-5530

Date
Nov 07, 2023
Research Description
The Ninja Forms Contact Form WordPress plugin before 3.6.34 does not sanitize and escape its label fields, which could allow high privilege users such as admin to perform Stored XSS attacks. Only users with the unfiltered_html capability can perform this, and such users are already allowed to use JS in posts/comments etc however the vendor acknowledged and fixed the issue
Affected versions
max 3.6.34.
Status
vulnerable

Ninja Forms Contact Form &#8211; The Drag and Drop Form Builder for WordPress # CVE-2024-2113

CVE, Research URL

CVE-2024-2113

Date
Mar 29, 2024
Research Description
The Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.8.0. This is due to missing or incorrect nonce validation on the nf_download_all_subs AJAX action. This makes it possible for unauthenticated attackers to trigger an export of a form's submission to a publicly accessible location via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Affected versions
max 3.8.1.
Status
vulnerable

Ninja Forms Contact Form &#8211; The Drag and Drop Form Builder for WordPress # CVE-2024-26019

CVE, Research URL

CVE-2024-26019

Date
Apr 11, 2024
Research Description
Ninja Forms prior to 3.8.1 contains a cross-site scripting vulnerability in submit processing. If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user who is accessing to the website using the product.
Affected versions
max 3.8.1.
Status
vulnerable

Ninja Forms Contact Form &#8211; The Drag and Drop Form Builder for WordPress # CVE-2024-25572

CVE, Research URL

CVE-2024-25572

Date
Apr 11, 2024
Research Description
Cross-site request forgery (CSRF) vulnerability exists in Ninja Forms prior to 3.4.31. If a website administrator views a malicious page while logging in, unintended operations may be performed.
Affected versions
max 3.8.1.
Status
vulnerable

Ninja Forms Contact Form &#8211; The Drag and Drop Form Builder for WordPress # CVE-2024-0685

CVE, Research URL

CVE-2024-0685

Date
Feb 02, 2024
Research Description
The Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to Second Order SQL Injection via the email address value submitted through forms in all versions up to, and including, 3.7.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to inject SQL in their email address that will append additional into the already existing query when an administrator triggers a personal data export.
Affected versions
max 3.7.2.
Status
vulnerable

Ninja Forms Contact Form &#8211; The Drag and Drop Form Builder for WordPress # CVE-2024-2108

CVE, Research URL

CVE-2024-2108

Date
Mar 29, 2024
Research Description
The Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an image title embedded into a form in all versions up to, and including, 3.8.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected versions
max 3.8.1.
Status
vulnerable

Ninja Forms Contact Form &#8211; The Drag and Drop Form Builder for WordPress # CVE-2024-29220

CVE, Research URL

CVE-2024-29220

Date
Apr 11, 2024
Research Description
Ninja Forms prior to 3.8.1 contains a cross-site scripting vulnerability in custom fields for labels. If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user who is accessing to the website using the product.
Affected versions
max 3.8.1.
Status
vulnerable
Jun 10, 2024

Ninja Forms Contact Form &#8211; The Drag and Drop Form Builder for WordPress # CVE-2023-38386

CVE, Research URL

CVE-2023-38386

Date
Jun 19, 2024
Research Description
Missing Authorization vulnerability in Saturday Drive Ninja Forms.This issue affects Ninja Forms: from n/a through 3.6.25.
Affected versions
max 3.6.26.
Status
vulnerable

Ninja Forms Contact Form &#8211; The Drag and Drop Form Builder for WordPress # CVE-2014-8815

CVE, Research URL

CVE-2014-8815

Date
-
Research Description
The Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘update_message’ parameter in versions up to, and including, 2.8.6 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
Affected versions
max 2.8.6.
Status
vulnerable

Ninja Forms Contact Form &#8211; The Drag and Drop Form Builder for WordPress # CVE-2023-38393

CVE, Research URL

CVE-2023-38393

Date
Jun 19, 2024
Research Description
Missing Authorization vulnerability in Saturday Drive Ninja Forms.This issue affects Ninja Forms: from n/a through 3.6.25.
Affected versions
max 3.6.26.
Status
vulnerable
Jul 08, 2024

Ninja Forms Contact Form &#8211; The Drag and Drop Form Builder for WordPress # CVE-2024-37934

CVE, Research URL

CVE-2024-37934

Date
Jul 09, 2024
Research Description
Improper Control of Generation of Code ('Code Injection') vulnerability in Saturday Drive Ninja Forms allows Code Injection.This issue affects Ninja Forms: from n/a through 3.8.4.
Affected versions
max 3.8.5.
Status
vulnerable
Jul 28, 2024

Ninja Forms Contact Form &#8211; The Drag and Drop Form Builder for WordPress # CVE-2024-39628

CVE, Research URL

CVE-2024-39628

Date
Aug 27, 2024
Research Description
Cross-Site Request Forgery (CSRF) vulnerability in Saturday Drive Ninja Forms allows Cross Site Request Forgery.This issue affects Ninja Forms: from n/a through 3.8.6.
Affected versions
max 3.8.7.
Status
vulnerable
Sep 01, 2024

Ninja Forms Contact Form &#8211; The Drag and Drop Form Builder for WordPress # CVE-2024-43999

CVE, Research URL

CVE-2024-43999

Date
Sep 18, 2024
Research Description
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Saturday Drive Ninja Forms allows Stored XSS.This issue affects Ninja Forms: from n/a through 3.8.11.
Affected versions
max 3.8.12.
Status
vulnerable
Sep 03, 2024

Ninja Forms Contact Form &#8211; The Drag and Drop Form Builder for WordPress # CVE-2024-7354

CVE, Research URL

CVE-2024-7354

Date
Sep 02, 2024
Research Description
The Ninja Forms WordPress plugin before 3.8.11 does not escape an URL before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
Affected versions
Min 3.8.6, max 3.8.11.
Status
vulnerable
Sep 26, 2024

Ninja Forms Contact Form &#8211; The Drag and Drop Form Builder for WordPress # CVE-2024-3866

CVE, Research URL

CVE-2024-3866

Date
Sep 25, 2024
Research Description
The Ninja Forms Contact Form plugin for WordPress is vulnerable to Reflected Self-Based Cross-Site Scripting via the 'Referer' header in all versions up to, and including, 3.8.15 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. Successful exploitation of this vulnerability requires "maintenance mode" for a targeted form to be enabled. However, there is no setting available to the attacker or even an administrator-level user to enable this mode. The mode is only enabled during a required update, which is a very short window of time. Additionally, because of the self-based nature of this vulnerability, attackers would have to rely on additional techniques to execute a supplied payload in the context of targeted user.
Affected versions
max 3.8.16.
Status
vulnerable
Oct 31, 2024

Ninja Forms Contact Form &#8211; The Drag and Drop Form Builder for WordPress # CVE-2024-50515

CVE, Research URL

CVE-2024-50515

Date
Nov 19, 2024
Research Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kevin Stover Ninja Forms ninja-forms allows Stored XSS.This issue affects Ninja Forms: from n/a through <= 3.8.16.
Affected versions
max 3.8.18.
Status
vulnerable

Ninja Forms Contact Form &#8211; The Drag and Drop Form Builder for WordPress # CVE-2024-50514

CVE, Research URL

CVE-2024-50514

Date
Nov 19, 2024
Research Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kevin Stover Ninja Forms ninja-forms allows Stored XSS.This issue affects Ninja Forms: from n/a through <= 3.8.16.
Affected versions
max 3.8.18.
Status
vulnerable
Dec 13, 2024

Ninja Forms Contact Form &#8211; The Drag and Drop Form Builder for WordPress # CVE-2024-11052

CVE, Research URL

CVE-2024-11052

Date
Dec 12, 2024
Research Description
The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the calculations parameter in all versions up to, and including, 3.8.19 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected versions
max 3.8.20.
Status
vulnerable
Dec 29, 2024

Ninja Forms Contact Form &#8211; The Drag and Drop Form Builder for WordPress # CVE-2024-12238

CVE, Research URL

CVE-2024-12238

Date
Dec 29, 2024
Research Description
The The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 3.8.22. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for authenticated attackers, with Subscriber-level access and above, to execute arbitrary shortcodes.
Affected versions
max 3.8.23.
Status
vulnerable
Feb 01, 2025

Ninja Forms Contact Form &#8211; The Drag and Drop Form Builder for WordPress # CVE-2024-13470

CVE, Research URL

CVE-2024-13470

Date
Jan 30, 2025
Research Description
The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode in all versions up to, and including, 3.8.24 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected versions
max 3.8.25.
Status
vulnerable
May 21, 2025

Ninja Forms Contact Form &#8211; The Drag and Drop Form Builder for WordPress # CVE-2025-2524

CVE, Research URL

CVE-2025-2524

Date
May 19, 2025
Research Description
The Ninja Forms WordPress plugin before 3.10.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
Affected versions
max 3.10.1.
Status
vulnerable

Ninja Forms Contact Form &#8211; The Drag and Drop Form Builder for WordPress # CVE-2025-2561

CVE, Research URL

CVE-2025-2561

Date
May 19, 2025
Research Description
The Ninja Forms WordPress plugin before 3.10.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
Affected versions
max 3.10.1.
Status
vulnerable

Ninja Forms Contact Form &#8211; The Drag and Drop Form Builder for WordPress # CVE-2025-2560

CVE, Research URL

CVE-2025-2560

Date
May 19, 2025
Research Description
The Ninja Forms WordPress plugin before 3.10.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
Affected versions
max 3.10.1.
Status
vulnerable
Jul 03, 2025

Ninja Forms Contact Form &#8211; The Drag and Drop Form Builder for WordPress # CVE-2025-5398

CVE, Research URL

CVE-2025-5398

Date
Jun 27, 2025
Research Description
The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the use of a templating engine in all versions up to, and including, 3.10.2.1 due to insufficient output escaping on user data passed through the template. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected versions
max 3.10.2.2.
Status
vulnerable
Oct 11, 2025

Ninja Forms Contact Form &#8211; The Drag and Drop Form Builder for WordPress # CVE-2025-10499

CVE, Research URL

CVE-2025-10499

Date
Sep 27, 2025
Research Description
The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.12.0. This is due to missing or incorrect nonce validation on the maybe_opt_in() function. This makes it possible for unauthenticated attackers to opt an affected site into usage statistics collection via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Affected versions
max 3.12.1.
Status
vulnerable

Ninja Forms Contact Form &#8211; The Drag and Drop Form Builder for WordPress # CVE-2025-10498

CVE, Research URL

CVE-2025-10498

Date
Sep 27, 2025
Research Description
The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.12.0. This is due to missing or incorrect nonce validation when exporting CSV files. This makes it possible for unauthenticated attackers to delete those files granted they can trick an administrator into performing an action such as clicking on a link.
Affected versions
max 3.12.1.
Status
vulnerable
Jan 09, 2026

Ninja Forms Contact Form &#8211; The Drag and Drop Form Builder for WordPress # CVE-2025-14072

CVE, Research URL

CVE-2025-14072

Date
Jan 02, 2026
Research Description
The Ninja Forms WordPress plugin before 3.13.3 allows unauthenticated attackers to generate valid access tokens via the REST API which can then be used to read form submissions.
Affected versions
max 3.13.3.
Status
vulnerable

Ninja Forms Contact Form &#8211; The Drag and Drop Form Builder for WordPress # CVE-2025-11924

CVE, Research URL

CVE-2025-11924

Date
Dec 17, 2025
Research Description
The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 3.13.2. This is due to the plugin not properly verifying that a user is authorized before the `ninja-forms-views` REST endpoints return form metadata and submission content. This makes it possible for unauthenticated attackers to read arbitrary form definitions and submission records via a leaked bearer token granted they can load any page containing the Submissions Table block. NOTE: The developer released a patch for this issue in 3.13.1, but inadvertently introduced a REST API endpoint in which a valid bearer token could be minted for arbitrary form IDs, making this patch ineffective.
Affected versions
max 3.13.3.
Status
vulnerable
Apr 13, 2026

Ninja Forms Contact Form &#8211; The Drag and Drop Form Builder for WordPress # CVE-2026-1307

CVE, Research URL

CVE-2026-1307

Date
Mar 28, 2026
Research Description
The Ninja Forms - The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.14.1 via a callback function for the admin_enqueue_scripts action handler in blocks/bootstrap.php. This makes it possible for authenticated attackers, with Contributor-level access and above, to gain access to an authorization token to view form submissions for arbitrary forms, which could potentially contain sensitive information.
Affected versions
max 3.14.2.
Status
vulnerable
Apr 23, 2026

Ninja Forms Contact Form &#8211; The Drag and Drop Form Builder for WordPress # CVE-2026-2268

CVE, Research URL

CVE-2026-2268

Date
Feb 10, 2026
Research Description
The Ninja Forms plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.14.0. This is due to the unsafe application of the `ninja_forms_merge_tags` filter to user-supplied input within repeater fields, which allows the resolution of `{post_meta:KEY}` merge tags without authorization checks. This makes it possible for unauthenticated attackers to extract arbitrary post metadata from any post on the site, including sensitive data such as WooCommerce billing emails, API keys, private tokens, and customer personal information via the `nf_ajax_submit` AJAX action.
Affected versions
max 3.14.1.
Status
vulnerable

Ninja Forms Contact Form &#8211; The Drag and Drop Form Builder for WordPress # CVE-2025-9083

CVE, Research URL

CVE-2025-9083

Date
Sep 18, 2025
Research Description
The Ninja Forms WordPress plugin before 3.11.1 unserializes user input via form field, which could allow Unauthenticated users to perform PHP Object Injection when a suitable gadget is present on the blog.
Affected versions
max 3.11.1.
Status
vulnerable
Jun 16, 2026

Ninja Forms Contact Form &#8211; The Drag and Drop Form Builder for WordPress # 8814fbe519d0ae2de82a6b8c3aae02f1e350852d

Date
Feb 16, 2021
Research Description
Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 3.4.34 WordPress Ninja Forms Contact Form plugin <= 3.4.33 - Cross-Site Request Forgery (CSRF) vulnerability Cross-Site Request Forgery (CSRF) vulnerability found by Chloe Chamberland in WordPress Ninja Forms Contact Form plugin (versions <= 3.4.33).
Affected versions
max 3.4.34.
Status
vulnerable

Ninja Forms Contact Form &#8211; The Drag and Drop Form Builder for WordPress # 6362e851e00b374ca3099ade770798fd41e570ce

Date
Feb 16, 2021
Research Description
Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 3.4.34 WordPress Ninja Forms Contact Form plugin <= 3.4.33 - Administrator Open Redirect vulnerability Administrator Open Redirect vulnerability found by Chloe Chamberland in WordPress Ninja Forms Contact Form plugin (versions <= 3.4.33).
Affected versions
max 3.4.34.
Status
vulnerable

Ninja Forms Contact Form &#8211; The Drag and Drop Form Builder for WordPress # f815fadab1550c44ce7eabd76f9d3a6bfb0e7524

Date
Sep 22, 2020
Research Description
Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 3.4.27.1 WordPress Ninja Forms plugin <= 3.4.27 - Cross-Site Request Forgery (CSRF) leading to Arbitrary Plugin Installation vulnerability Cross-Site Request Forgery (CSRF) leading to Arbitrary Plugin Installation vulnerability found by Slavco Mihajloski in WordPress Ninja Forms plugin (versions <= 3.4.27).
Affected versions
max 3.4.27.1.
Status
vulnerable

Ninja Forms Contact Form &#8211; The Drag and Drop Form Builder for WordPress # 75bab3d93feeb6aa3802dc7683d145a058edfd8b

Date
Mar 22, 2022
Research Description
Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 3.6.8 WordPress Ninja Forms plugin <= 3.6.7 - Unauthenticated Email Address Disclosure vulnerability Unauthenticated Email Address Disclosure vulnerability discovered by Agence Web Coheractio in WordPress Ninja Forms plugin (versions <= 3.6.7).
Affected versions
max 3.6.8.
Status
vulnerable

Ninja Forms Contact Form &#8211; The Drag and Drop Form Builder for WordPress # 6c18b14c0c353cf9105f9102eea21f6bbad609c9

Date
Feb 16, 2021
Research Description
Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 3.4.34 WordPress Ninja Forms Contact Form plugin <= 3.4.33 - Authenticated OAuth Connection Key Disclosure vulnerability Authenticated OAuth Connection Key Disclosure vulnerability found by Chloe Chamberland in WordPress Ninja Forms Contact Form plugin (versions <= 3.4.33).
Affected versions
max 3.4.34.
Status
vulnerable

Ninja Forms Contact Form &#8211; The Drag and Drop Form Builder for WordPress # 97c8efa05613e39107ff483222451ad3fd30e590

Date
Feb 16, 2021
Research Description
Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 3.4.34 WordPress Ninja Forms Contact Form plugin <= 3.4.33 - Authenticated SendWP Plugin Installation and Client Secret Key Disclosure vulnerability Authenticated SendWP Plugin Installation and Client Secret Key Disclosure vulnerability found by Chloe Chamberland in WordPress Ninja Forms Contact Form plugin (versions <= 3.4.33).
Affected versions
max 3.4.34.
Status
vulnerable

Ninja Forms Contact Form &#8211; The Drag and Drop Form Builder for WordPress # 62e22fe8163168a9aa45945f81c33955375f669e

Date
Aug 28, 2018
Research Description
Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 3.3.14 WordPress Ninja Forms plugin <= 3.3.13 - CSV Injection vulnerability CSV Injection vulnerability fund by Mostafa Gharzi in WordPress Ninja Forms plugin (versions <= 3.3.13).
Affected versions
max 3.3.14.
Status
vulnerable

Ninja Forms Contact Form &#8211; The Drag and Drop Form Builder for WordPress # 44611624527c30088b5dc0ee35f92f28ce05427b

Date
Sep 30, 2015
Research Description
Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 2.9.28 WordPress Ninja Forms Plugin <= 2.9.27 - Malicious File Export There is an unknown vulnerability in this plugin. Upgrade this plugin.
Affected versions
max 2.9.28.
Status
vulnerable

Ninja Forms Contact Form &#8211; The Drag and Drop Form Builder for WordPress # 1653e6eaad668bd925e29c77b85c0abfaf421ab9

Date
Aug 04, 2015
Research Description
Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 2.9.22 WordPress Ninja Forms Plugin <= 2.9.21 - Cross Site Scripting Because of this vulnerability, the attackers can inject arbitrary JavaScript or HTML code. Update the plugin.
Affected versions
max 2.9.22.
Status
vulnerable

Ninja Forms Contact Form &#8211; The Drag and Drop Form Builder for WordPress # 165ba9a9422d8ed51d0905bb36cbc8aac59737b6

Date
Sep 08, 2014
Research Description
Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 2.7.8 WordPress Ninja Forms Plugin - Authorization Bypass Ninja Forms plugin is prone to an authorization BYPASS vulnerability that allows an attacker to bypass security restrictions and perform unauthorized actions. Update the plugin.
Affected versions
max 2.7.8.
Status
vulnerable

Ninja Forms Contact Form &#8211; The Drag and Drop Form Builder for WordPress # 1983ed4b8251c56d274067560a67a5a1106e1b18

Date
Jun 25, 2019
Research Description
Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 3.3.21.3 WordPress Ninja Forms plugin <= 3.3.21 - Cross-Site Scripting (XSS) vulnerability Cross-Site Scripting (XSS) vulnerability found in WordPress Ninja Forms plugin (versions <= 3.3.21).
Affected versions
max 3.3.21.3.
Status
vulnerable

Ninja Forms Contact Form &#8211; The Drag and Drop Form Builder for WordPress # 8ed0fce1003899b0e7622e875f01c25d26bf20a9

Date
Aug 28, 2018
Research Description
Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 3.3.14 WordPress Ninja Forms plugin <= 3.3.13 - Cross-Site Scripting (XSS) vulnerability Cross-Site Scripting (XSS) vulnerability found in WordPress Ninja Forms plugin (versions <= 3.3.13).
Affected versions
max 3.3.14.
Status
vulnerable

Ninja Forms Contact Form &#8211; The Drag and Drop Form Builder for WordPress # 6b719ff83199e1e612a77d8e095bab815a0b8dfe

Date
Jul 19, 2016
Research Description
Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 2.9.52 WordPress Ninja Forms Plugin <= 2.9.51 - Multiple Cross Site Scripting Because of this vulnerability, attackers can inject malicious JavaScript code into the application. Update this plugin.
Affected versions
max 2.9.52.
Status
vulnerable

Ninja Forms Contact Form &#8211; The Drag and Drop Form Builder for WordPress # 7a7ae6840be2b22784ca13d3564a1dca63d26055

Date
Jun 15, 2022
Research Description
Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] <= 3.6.10 WordPress Ninja Forms plugin <= 3.6.10 - Unauthenticated PHP Object Injection vulnerability Unauthenticated PHP Object Injection vulnerability discovered in WordPress Ninja Forms plugin (versions <= 3.6.10). Update the WordPress Ninja Forms plugin to the latest available version (at least 3.6.11).
Affected versions
max 3.6.10.
Status
vulnerable

Ninja Forms Contact Form &#8211; The Drag and Drop Form Builder for WordPress # c08677aed644ad9abd1f6777af407fb61f0b1746

Date
Jun 25, 2019
Research Description
Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 3.3.21.3 WordPress Ninja Forms plugin <= 3.3.21 - SQL injection (SQLi) vulnerability SQL injection (SQLi) vulnerability found in WordPress Ninja Forms plugin (versions <= 3.3.21).
Affected versions
max 3.3.21.3.
Status
vulnerable

Ninja Forms Contact Form &#8211; The Drag and Drop Form Builder for WordPress # 5e24776f52ce6209a0bfdb73a1eec92de49e8179

Date
Jun 05, 2015
Research Description
Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 2.9.19 WordPress Ninja Forms Plugin <= 2.9.18 - Cross Site Scripting Because of this vulnerability, the attackers can inject arbitrary JavaScript or HTML code. Update the plugin.
Affected versions
max 2.9.19.
Status
vulnerable

Ninja Forms Contact Form &#8211; The Drag and Drop Form Builder for WordPress # 646a679abf35dc7c80910f05a6a2657cd7abb6c1

Date
Apr 20, 2015
Research Description
Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 2.9.11 WordPress Ninja Forms Plugin <= 2.9.10 - Cross Site Scripting Because of this vulnerability, the attackers can inject arbitrary JavaScript or HTML code. Upgrade the plugin.
Affected versions
max 2.9.11.
Status
vulnerable

Ninja Forms Contact Form &#8211; The Drag and Drop Form Builder for WordPress # c6722c6bd80a41a9f5e55c8860889e4095aeffb0

Date
Aug 16, 2016
Research Description
Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 2.9.55.2 WordPress Ninja Forms Plugin <= 2.9.55.1 - Authenticated SQL Injection There is a bug in this plugin. It could leak the site’s usernames and hashed passwords. Update the plugin.
Affected versions
max 2.9.55.2.
Status
vulnerable

Ninja Forms Contact Form &#8211; The Drag and Drop Form Builder for WordPress # b2c9b7bc99d03823fc8c26e4a668f61748a955a8

Date
Jul 19, 2016
Research Description
Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 2.9.52 Ninja Forms Contact Form <= 2.9.51 - Multiple Reflected Cross-Site Scripting The Ninja Forms Contact Form plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via multiple parameters in versions before 2.9.52 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
Affected versions
max 2.9.52.
Status
vulnerable

Ninja Forms Contact Form &#8211; The Drag and Drop Form Builder for WordPress # c88c43569e81d71bd8346be971376755391d9309

Date
Nov 06, 2014
Research Description
Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 2.8.7 Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress <= 2.8.6 - Reflected Cross-Site Scripting The Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘update_message’ parameter in versions up to, and including, 2.8.6 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
Affected versions
max 2.8.7.
Status
vulnerable

Ninja Forms Contact Form &#8211; The Drag and Drop Form Builder for WordPress # 285248894cf3f46268dd01b511e7be621b633209

Date
Mar 22, 2022
Research Description
Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 3.6.8 Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress <= 3.6.7 - Email Address Disclosure The Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to Sensitive Data Exposure in versions up to, and including, 3.6.7. This can allow unauthenticated attackers to extract sensitive data including other users' email addresses which can be used to help perform future attacks.
Affected versions
max 3.6.8.
Status
vulnerable

Ninja Forms Contact Form &#8211; The Drag and Drop Form Builder for WordPress # 0bc642976d29821d5fd23074ac0888a4976b0eab

Date
Apr 17, 2017
Research Description
Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 3.0.32 Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress <= 3.0.31 - Arbitrary Wordpress Shortcode Injection The Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to Arbitrary Wordpress Shortcode Injection in versions up to, and including, 3.0.31. This makes it possible for unauthenticated attackers to preview un-published forms and could possibly be used to leverage further attacks.
Affected versions
max 3.0.32.
Status
vulnerable

Ninja Forms Contact Form &#8211; The Drag and Drop Form Builder for WordPress # 5b398fa56cafc9d3c602ad3cdf4ac8bf17e8be2d

Date
Aug 16, 2016
Research Description
Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 2.9.55.2 Ninja Forms Contact Form <= 2.9.55.1 - Authenticated SQL Injection The Ninja Forms Contact Form plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 2.9.55.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for Subscriber-level attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
Affected versions
max 2.9.55.2.
Status
vulnerable

Ninja Forms Contact Form &#8211; The Drag and Drop Form Builder for WordPress # 4d4dec44bed3364eeef20d4c24615d186947040c

Date
Sep 30, 2015
Research Description
Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 2.9.28 Ninja Forms Contact Form <= 2.9.27 - CSV Injection The Ninja Forms Contact Form plugin for WordPress is vulnerable to CSV Injection in versions up to, and including, 2.9.27 via the export() function. This allows authenticated attackers to embed untrusted input into exported CSV files, which can result in code execution when these files are downloaded and opened on a local system with a vulnerable configuration.
Affected versions
max 2.9.28.
Status
vulnerable

Ninja Forms Contact Form &#8211; The Drag and Drop Form Builder for WordPress # 2d7b56a3ba05e8ba90e4bb0d2b0979d98f560240

Date
Aug 04, 2015
Research Description
Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 2.9.22 Ninja Forms Contact Form <= 2.9.21 - Reflected Cross-Site Scripting The Ninja Forms Contact Form plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 2.9.21 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
Affected versions
max 2.9.22.
Status
vulnerable

Ninja Forms Contact Form &#8211; The Drag and Drop Form Builder for WordPress # 4d853456ce172f350a9d0a401ea82c05e7ce461c

Date
Apr 20, 2015
Research Description
Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 2.9.11 Ninja Forms <= 2.9.10 - Reflected Cross-Site Scripting The Ninja Forms plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 2.9.10 due to insufficient input sanitization and output escaping on add_query_arg and remove_query_arg. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser.
Affected versions
max 2.9.11.
Status
vulnerable

Ninja Forms Contact Form &#8211; The Drag and Drop Form Builder for WordPress # b84c1dcccc9b9a3c55a57523da9e43d8134d022b

Date
Jun 05, 2015
Research Description
Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 2.9.19 Ninja Forms Contact Form <= 2.9.18 - Cross-Site Scripting The Ninja Forms Contact Form plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 2.9.18 due to insufficient input sanitization and output escaping. This makes it possible for unauthorized attackers to inject arbitrary web scripts that execute in a victim's browser.
Affected versions
max 2.9.19.
Status
vulnerable

Ninja Forms Contact Form &#8211; The Drag and Drop Form Builder for WordPress # cc43d8f4fa796879a20d51bcee8882361a17f7ed

Date
Jun 15, 2022
Research Description
Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 3.6.11 Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress <= 3.6.10 - Code Injection The Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to code injection in versions up to, and including 3.6.10 due to insufficient validation on Merge Tags that makes it possible to call arbitrary Ninja Form classes. This could lead to a variety of actions, however, one notable one is deserialization when the NF_Admin_Processes_ImportForm::startup method is called. On sites with a POP chain this could be used to achieve remote code execution in the worst possible scenarios.
Affected versions
max 3.6.11.
Status
vulnerable

Ninja Forms Contact Form &#8211; The Drag and Drop Form Builder for WordPress # d95c22bf19ccb520b61bb7864bc8c03e52e2d88c

Date
Jun 07, 2022
Research Description
Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 3.6.10 Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress <= 3.6.9 - Cross-Site Request Forgery to Field Import and PHP Object Injection The Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including 3.6.9, due to missing nonce validation on the import_fields_listener() function that makes it possible for unauthenticated attackers to import new form fields granted that can trick an attacker into performing an action such as clicking on a link. This CSRF vulnerability can also be exploited to achieve PHP Object Injection due to the use of unserialize() on the user supplied file contents.
Affected versions
max 3.6.10.
Status
vulnerable

Ninja Forms Contact Form &#8211; The Drag and Drop Form Builder for WordPress # 897115ff2e79aea9d4fbc14733f0a1df9e9a557a

Date
Aug 27, 2018
Research Description
Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 3.3.14 Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress <= 3.3.13 - Cross-Site Scripting The Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to Cross-Site Scripting via the form input function in versions up to, and including, 3.3.13 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected versions
max 3.3.14.
Status
vulnerable

Ninja Forms Contact Form &#8211; The Drag and Drop Form Builder for WordPress # f456817941a1bba1744a5a404546997b68d0dd43

Date
Dec 08, 2015
Research Description
Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 2.9.29 Ninja Forms Contact Form <= 2.9.28 - Stored Cross-Site Scripting The Ninja Forms Contact Form plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 2.9.28 due to insufficient input sanitization and output escaping during form submission. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser.
Affected versions
max 2.9.29.
Status
vulnerable

Ninja Forms Contact Form &#8211; The Drag and Drop Form Builder for WordPress # 8843d66b-e895-4336-afda-00b99442cdc1

Date
-
Research Description
Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 3.6.11 Ninja Forms &lt; 3.6.11 - Unauthenticated PHP Object Injection The plugin does not validate merge tags provided in the request, which could allow unauthenticated attackers to call any static method present in the blog. One from the plugin in particular could allow for PHP Object Injection when a suitable gadget is also present on the blog. Attackers have been exploiting such issue since June 9th, 2022
Affected versions
max 3.6.11.
Status
vulnerable

Ninja Forms Contact Form &#8211; The Drag and Drop Form Builder for WordPress # cec7d366-7663-4b83-9640-a58f2fcf5e41

Date
-
Research Description
Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 3.6.8 Ninja Forms &lt; 3.6.8 - Unauthenticated Email Address Disclosure The plugin does not delete the temporary files created when exporting submissions, which could allow unauthenticated attackers to download them and get sensitive information such as the email address of users who submitted a form given that the file is publicly accessible, and with a guessable name
Affected versions
max 3.6.8.
Status
vulnerable

Ninja Forms Contact Form &#8211; The Drag and Drop Form Builder for WordPress # a3146860-4065-437b-8a17-7a8ac802c565

Date
-
Research Description
Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 2.9.28 Ninja Forms &lt;= 2.9.27 - Malicious File Export The Ninja Forms Contact Form &ndash; The Drag and Drop Form Builder for WordPress WordPress plugin was affected by a Malicious File Export security vulnerability.
Affected versions
max 2.9.28.
Status
vulnerable

Ninja Forms Contact Form &#8211; The Drag and Drop Form Builder for WordPress # a495b360-a81f-4d42-a8d4-a74e2c2a7cee

Date
-
Research Description
Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 2.9.52 Ninja Forms &lt;= 2.9.51 - Multiple Authenticated Cross-Site Scripting (XSS) The Ninja Forms Contact Form &ndash; The Drag and Drop Form Builder for WordPress WordPress plugin was affected by a Multiple Authenticated Cross-Site Scripting (XSS) security vulnerability.
Affected versions
max 2.9.52.
Status
vulnerable

Ninja Forms Contact Form &#8211; The Drag and Drop Form Builder for WordPress # c84fa906-4d70-4d4d-990e-a0510bcf72ed

Date
-
Research Description
Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 2.9.22 Ninja Forms &lt;= 2.9.21 - Authenticated Reflected Cross-Site Scripting (XSS) The Ninja Forms Contact Form &ndash; The Drag and Drop Form Builder for WordPress WordPress plugin was affected by an Authenticated Reflected Cross-Site Scripting (XSS) security vulnerability.
Affected versions
max 2.9.22.
Status
vulnerable

Ninja Forms Contact Form &#8211; The Drag and Drop Form Builder for WordPress # ba6fa3d6-e3f7-449a-bd78-d57c26a67aa6

Date
-
Research Description
Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 3.5.5 Nina Forms &lt; 3.5.5 - Reflected Cross-Site Scripting The plugin does not escape generated links before outputting them in attributes, leading to Reflected Cross-Site Scripting
Affected versions
max 3.5.5.
Status
vulnerable

Ninja Forms Contact Form &#8211; The Drag and Drop Form Builder for WordPress # fd19ade3-4d3b-446e-9b08-7b07b1ec1927

Date
-
Research Description
Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 3.3.14 Ninja Forms &lt;= 3.3.13 - Cross-Site Scripting (XSS) in Import Function The Ninja Forms Contact Form &ndash; The Drag and Drop Form Builder for WordPress WordPress plugin was affected by a Cross-Site Scripting (XSS) in Import Function security vulnerability.
Affected versions
max 3.3.14.
Status
vulnerable

Ninja Forms Contact Form &#8211; The Drag and Drop Form Builder for WordPress # a494753c-187e-4de9-9564-dc8a36df048b

Date
-
Research Description
Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 2.9.55.2 Ninja Forms &lt;= 2.9.55.1 - Authenticated SQL Injection The Ninja Forms Contact Form &ndash; The Drag and Drop Form Builder for WordPress WordPress plugin was affected by an Authenticated SQL Injection security vulnerability.
Affected versions
max 2.9.55.2.
Status
vulnerable

Ninja Forms Contact Form &#8211; The Drag and Drop Form Builder for WordPress # 0dc1757f-dbe1-454f-a476-0305aee23fb6

Date
-
Research Description
Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 2.9.19 Ninja Forms &lt;= 2.9.18 - Cross-Site Scripting (XSS) The Ninja Forms Contact Form &ndash; The Drag and Drop Form Builder for WordPress WordPress plugin was affected by a Cross-Site Scripting (XSS) security vulnerability.
Affected versions
max 2.9.19.
Status
vulnerable

Ninja Forms Contact Form &#8211; The Drag and Drop Form Builder for WordPress # 730abdcf-e0a0-4d7c-a3b6-ca56c6a59df2

Date
-
Research Description
Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 3.3.21.3 Ninja Forms &lt;= 3.3.21 - XSS and SQLi Reflected XSS vulnerability in the administrative dashboard. Blind SQL injection vulnerability in the search filter on the submissions page.
Affected versions
max 3.3.21.3.
Status
vulnerable

Ninja Forms Contact Form &#8211; The Drag and Drop Form Builder for WordPress # d0adf831-26c0-46f8-8964-df5f48ec77cd

Date
-
Research Description
Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 2.9.11 Ninja Forms &lt;= 2.9.10 - Cross-Site Scripting (XSS) The Ninja Forms Contact Form &ndash; The Drag and Drop Form Builder for WordPress WordPress plugin was affected by a Cross-Site Scripting (XSS) security vulnerability.
Affected versions
max 2.9.11.
Status
vulnerable

Ninja Forms Contact Form &#8211; The Drag and Drop Form Builder for WordPress # de4537020d7c9e36885cc1b5b28145cc99523699

Date
Sep 03, 2024
Research Description
Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] >= 3.8.6 - <= 3.8.10 WordPress Ninja Forms Plugin 3.8.6-3.8.10 is vulnerable to Cross Site Scripting (XSS) <p>WordPress Ninja Forms Plugin 3.8.6-3.8.10 is vulnerable to Cross Site Scripting (XSS)</p><p>Software: Ninja Forms</p><p>Link: https://wordpress.org/plugins/ninja-forms/#developers</p><p>Affected Version 3.8.6-3.8.10</p><p>Fixed in version 3.8.11 </p>
Affected versions
Min 3.8.6, max 3.8.10.
Status
vulnerable