Vulnerabilities (CVE)

Filtered by vendor Ninjaforms Subscribe
Filtered by product Ninja Forms
Total 36 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2020-36174 1 Ninjaforms 1 Ninja Forms 2024-11-21 4.3 MEDIUM 6.5 MEDIUM
The Ninja Forms plugin before 3.4.27.1 for WordPress allows CSRF via services integration.
CVE-2020-36173 1 Ninjaforms 1 Ninja Forms 2024-11-21 5.0 MEDIUM 5.3 MEDIUM
The Ninja Forms plugin before 3.4.28 for WordPress lacks escaping for submissions-table fields.
CVE-2020-12462 1 Ninjaforms 1 Ninja Forms 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
The ninja-forms plugin before 3.4.24.2 for WordPress allows CSRF with resultant XSS.
CVE-2018-7280 1 Ninjaforms 1 Ninja Forms 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
The Ninja Forms plugin before 3.2.14 for WordPress has XSS.
CVE-2018-20981 1 Ninjaforms 1 Ninja Forms 2024-11-21 6.4 MEDIUM 9.1 CRITICAL
The ninja-forms plugin before 3.3.9 for WordPress has insufficient restrictions on submission-data retrieval during Export Personal Data requests.
CVE-2018-20980 1 Ninjaforms 1 Ninja Forms 2024-11-21 5.0 MEDIUM 7.5 HIGH
The ninja-forms plugin before 3.2.15 for WordPress has parameter tampering.
CVE-2018-19796 1 Ninjaforms 1 Ninja Forms 2024-11-21 5.8 MEDIUM 6.1 MEDIUM
An open redirect in the Ninja Forms plugin before 3.3.19.1 for WordPress allows Remote Attackers to redirect a user via the lib/StepProcessing/step-processing.php (aka submissions download page) redirect parameter.
CVE-2018-16308 1 Ninjaforms 1 Ninja Forms 2024-11-21 6.8 MEDIUM 8.6 HIGH
The Ninja Forms plugin before 3.3.14.1 for WordPress allows CSV injection.
CVE-2017-18574 1 Ninjaforms 1 Ninja Forms 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
The ninja-forms plugin before 3.0.31 for WordPress has insufficient HTML escaping in the builder.
CVE-2016-1209 1 Ninjaforms 1 Ninja Forms 2024-11-21 7.5 HIGH 9.8 CRITICAL
The Ninja Forms plugin before 2.9.42.1 for WordPress allows remote attackers to conduct PHP object injection attacks via crafted serialized values in a POST request.
CVE-2015-2220 1 Ninjaforms 1 Ninja Forms 2024-11-21 4.3 MEDIUM N/A
Multiple cross-site scripting (XSS) vulnerabilities in the Ninja Forms plugin before 2.8.9 for WordPress allow (1) remote attackers to inject arbitrary web script or HTML via the ninja_forms_field_1 parameter in a ninja_forms_ajax_submit action to wp-admin/admin-ajax.php or (2) remote administrators to inject arbitrary web script or HTML via the fields[1] parameter to wp-admin/post.php.
CVE-2014-9688 1 Ninjaforms 1 Ninja Forms 2024-11-21 7.5 HIGH N/A
Unspecified vulnerability in the Ninja Forms plugin before 2.8.10 for WordPress has unknown impact and remote attack vectors related to admin users.
CVE-2024-39628 1 Ninjaforms 1 Ninja Forms 2024-10-20 N/A 8.8 HIGH
Cross-Site Request Forgery (CSRF) vulnerability in Saturday Drive Ninja Forms allows Cross Site Request Forgery.This issue affects Ninja Forms: from n/a through 3.8.6.
CVE-2024-7354 1 Ninjaforms 1 Ninja Forms 2024-10-04 N/A 6.1 MEDIUM
The Ninja Forms WordPress plugin before 3.8.11 does not escape an URL before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
CVE-2024-3866 1 Ninjaforms 1 Ninja Forms 2024-10-02 N/A 6.1 MEDIUM
The Ninja Forms Contact Form plugin for WordPress is vulnerable to Reflected Self-Based Cross-Site Scripting via the 'Referer' header in all versions up to, and including, 3.8.15 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. Successful exploitation of this vulnerability requires "maintenance mode" for a targeted form to be enabled. However, there is no setting available to the attacker or even an administrator-level user to enable this mode. The mode is only enabled during a required update, which is a very short window of time. Additionally, because of the self-based nature of this vulnerability, attackers would have to rely on additional techniques to execute a supplied payload in the context of targeted user.
CVE-2024-43999 1 Ninjaforms 1 Ninja Forms 2024-09-25 N/A 4.8 MEDIUM
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Saturday Drive Ninja Forms allows Stored XSS.This issue affects Ninja Forms: from n/a through 3.8.11.