← Back

Ninjaforms

ninjaforms

64 CVEs • 5 products

Products (5)

Click to collapse
Toggle

CVEs (64)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Ninjaforms
1Ninja Forms
Jun 17, 2026
Feb 21, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The Ninja Forms plugin before 3.2.14 for WordPress has XSS.
1Ninjaforms
1Ninja Forms
May 6, 2026
May 14, 2016
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The Ninja Forms plugin before 2.9.42.1 for WordPress allows remote attackers to conduct PHP object injection attacks via crafted serialized values in a POST request.
1Ninjaforms
1Ninja Forms
May 6, 2026
Mar 5, 2015
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Multiple cross-site scripting (XSS) vulnerabilities in the Ninja Forms plugin before 2.8.9 for WordPress allow (1) remote attackers to inject arbitrary web script or HTML via the ninja_forms_field_1 parameter in a ninja_...Show more
Multiple cross-site scripting (XSS) vulnerabilities in the Ninja Forms plugin before 2.8.9 for WordPress allow (1) remote attackers to inject arbitrary web script or HTML via the ninja_forms_field_1 parameter in a ninja_forms_ajax_submit action to wp-admin/admin-ajax.php or (2) remote administrators to inject arbitrary web script or HTML via the fields[1] parameter to wp-admin/post.php.Show less
1Ninjaforms
1Ninja Forms
May 6, 2026
Mar 5, 2015
N/A· v4
N/A· v3
7.5 HIGH· v2
Unspecified vulnerability in the Ninja Forms plugin before 2.8.10 for WordPress has unknown impact and remote attack vectors related to admin users.