CVEs (4)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Ninjaforms 1Ninja Forms File Uploads Sep 26, 2024 Sep 7, 2024 N/A· v4 6.1 MEDIUM· v3 N/A· v2 The Ninja Forms - File Uploads plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an uploaded file (e.g. RTX file) in all versions up to, and including, 3.3.16 due to insufficient input sanitization an...Show more |
1Ninjaforms 1Ninja Forms File Uploads Jun 17, 2026 Mar 23, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The Ninja Forms - File Uploads Extension WordPress plugin is vulnerable to reflected cross-site scripting due to missing sanitization of the files filename parameter found in the ~/includes/ajax/controllers/uploads.php f...Show more |
1Ninjaforms 1Ninja Forms File Uploads Jun 17, 2026 Mar 23, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The Ninja Forms - File Uploads Extension WordPress plugin is vulnerable to arbitrary file uploads due to insufficient input file type validation found in the ~/includes/ajax/controllers/uploads.php file which can be bypa...Show more |
1Ninjaforms 1Ninja Forms File Uploads Jun 17, 2026 May 7, 2019 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 Path Traversal and Unrestricted File Upload exists in the Ninja Forms plugin before 3.0.23 for WordPress (when the Uploads add-on is activated). This allows an attacker to traverse the file system to access files and exe...Show more |