cleantalk
Vulnerabilities and Security Researches

Vulnerabilities and security researches forninja-tables ninja-tables

Direction: ascending
Jun 07, 2024

Ninja Tables – Best Data Table Plugin for WordPress # CVE-2021-24900

CVE, Research URL

CVE-2021-24900

Date
Feb 01, 2022
Research Description
The Ninja Tables WordPress plugin before 4.1.8 does not sanitise and escape some of its table fields, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed
Affected versions
Min -, max -.
Status
vulnerable

Ninja Tables – Best Data Table Plugin for WordPress # CVE-2022-47136

CVE, Research URL

CVE-2022-47136

Date
May 25, 2023
Research Description
Cross-Site Request Forgery (CSRF) vulnerability in WPManageNinja LLC Ninja Tables – Best Data Table Plugin for WordPress plugin <= 4.3.4 versions.
Affected versions
Min -, max -.
Status
vulnerable

Ninja Tables &#8211; Best Data Table Plugin for WordPress # CVE-2024-35635

CVE, Research URL

CVE-2024-35635

Date
Jun 03, 2024
Research Description
Server-Side Request Forgery (SSRF) vulnerability in WPManageNinja LLC Ninja Tables.This issue affects Ninja Tables: from n/a through 5.0.9.
Affected versions
Min -, max -.
Status
vulnerable

Ninja Tables &#8211; Best Data Table Plugin for WordPress # CVE-2022-47137

CVE, Research URL

CVE-2022-47137

Date
May 10, 2023
Research Description
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in WPManageNinja LLC Ninja Tables plugin <= 4.3.4 versions.
Affected versions
Min -, max -.
Status
vulnerable
Jun 10, 2024

Ninja Tables &#8211; Best Data Table Plugin for WordPress # CVE-2024-23504

CVE, Research URL

CVE-2024-23504

Date
Jun 14, 2024
Research Description
Missing Authorization vulnerability in WPManageNinja LLC Ninja Tables.This issue affects Ninja Tables: from n/a through 5.0.5.
Affected versions
Min -, max -.
Status
vulnerable
Jul 10, 2024

Ninja Tables &#8211; Best Data Table Plugin for WordPress # CVE-2024-23503

CVE, Research URL

CVE-2024-23503

Date
Jun 11, 2024
Research Description
Missing Authorization vulnerability in WPManageNinja LLC Ninja Tables.This issue affects Ninja Tables: from n/a through 5.0.6.
Affected versions
Min -, max -.
Status
vulnerable
Aug 27, 2024

Ninja Tables &#8211; Best Data Table Plugin for WordPress # CVE-2024-7304

CVE, Research URL

CVE-2024-7304

Date
Aug 27, 2024
Research Description
The Ninja Tables – Easiest Data Table Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 5.0.12 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses the SVG file.
Affected versions
Min -, max -.
Status
vulnerable
Feb 01, 2025

Ninja Tables &#8211; Best Data Table Plugin for WordPress # CVE-2024-12772

CVE, Research URL

CVE-2024-12772

Date
Jan 31, 2025
Research Description
The Ninja Tables WordPress plugin before 5.0.17 does not sanitize and escape a parameter before outputting it back in the page when importing a CSV, leading to a Cross Site Scripting vulnerability.
Affected versions
Min -, max -.
Status
vulnerable
Jun 14, 2025

Ninja Tables &#8211; Best Data Table Plugin for WordPress # CVE-2025-2939

CVE, Research URL

CVE-2025-2939

Date
Jun 03, 2025
Research Description
The Ninja Tables – Easy Data Table Builder plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 5.0.18 via deserialization of untrusted input from the args[callback] parameter . This makes it possible for unauthenticated attackers to inject a PHP Object. The additional presence of a POP chain allows attackers to execute arbitrary functions, though it does not allow user supplied parameters only single functions can be called so the impact is limited.
Affected versions
Min -, max -.
Status
vulnerable