VendorsNinja Formsninja_formsany version
Vulnerabilities

Ninja Forms Ninja Forms any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

56CVEs
CVE-2016-1209
The Ninja Forms plugin before 2.9.42.1 for WordPress allows remote attackers to conduct PHP object injection attacks via crafted serialized values in a POST request.
Published 2016-05-14 · Modified
9.81 PoCEPSS 0.616
CVE-2024-0685
Ninja Forms Contact Form <= 3.7.1 - Unauthenticated Second Order SQL Injection
Published 2024-02-02 · Modified
9.8EPSS 0.008
CVE-2025-9083
Ninja-forms < 3.11.1 - Unauthenticated PHP Objection
Published 2025-09-18 · Analyzed
9.8EPSS 0.005
CVE-2023-38386
WordPress Ninja Forms plugin <= 3.6.25 - Contributor+ Broken Access Control vulnerability
Published 2024-06-19 · Analyzed
9.8EPSS 0.005
CVE-2024-37934
WordPress Ninja Forms plugin <= 3.8.4 - Subscriber+ Arbitrary Shortcode Execution vulnerability
Published 2024-07-09 · Modified
9.8EPSS 0.005
CVE-2018-20981
The ninja-forms plugin before 3.3.9 for WordPress has insufficient restrictions on submission-data retrieval during Export Personal Data requests.
Published 2019-08-22 · Modified
9.1EPSS 0.017
CVE-2021-24163
Ninja Forms < 3.4.34 - Authenticated SendWP Plugin Installation and Client Secret Key Disclosure
Published 2021-04-05 · Modified
8.8EPSS 0.014
CVE-2023-38393
WordPress Ninja Forms plugin <= 3.6.25 - Subscriber+ Broken Access Control vulnerability
Published 2024-06-19 · Modified
8.8EPSS 0.005
CVE-2024-25572
Cross-site request forgery (CSRF) vulnerability exists in Ninja Forms prior to 3.4.31. If a website administrator views a malicious page while logging in, unintended operations may be performed.
Published 2024-04-11 · Analyzed
8.8EPSS 0.003
CVE-2024-39628
WordPress Ninja Forms plugin <= 3.8.6 - Cross Site Request Forgery (CSRF) vulnerability
Published 2024-08-26 · Modified
8.8EPSS 0.002
CVE-2018-16308
The Ninja Forms plugin before 3.3.14.1 for WordPress allows CSV injection.
Published 2018-09-01 · Modified
8.6EPSS 0.018
CVE-2014-9688
Unspecified vulnerability in the Ninja Forms plugin before 2.8.10 for WordPress has unknown impact and remote attack vectors related to admin users.
Published 2015-03-05 · Modified
7.5EPSS 0.020
CVE-2018-20980
The ninja-forms plugin before 3.2.15 for WordPress has parameter tampering.
Published 2019-08-22 · Modified
7.5EPSS 0.014
CVE-2025-11924
Ninja Forms – The Contact Form Builder That Grows With You <= 3.13.2 - Insecure Direct Object Reference to Unauthenticated Sensitive Information Exposure via Unscoped Bearer Token
Published 2025-12-17 · Analyzed
7.5EPSS 0.004
CVE-2022-2903
NinjaForms < 3.6.13 - Admin+ PHP Objection Injection
Published 2022-09-26 · Modified
7.2EPSS 0.014
CVE-2021-24889
Ninja Forms < 3.6.4 - Admin+ SQL Injection
Published 2021-11-29 · Modified
7.2EPSS 0.013
CVE-2023-36505
WordPress Ninja Forms Plugin <= 3.6.24 is vulnerable to Arbitrary File Deletion
Published 2024-04-17 · Modified
7.2EPSS 0.006
CVE-2024-11052
Ninja Forms – The Contact Form Builder That Grows With You <= 3.8.19 - Unauthenticated Stored Cross-Site Scripting via Form Calculations
Published 2024-12-12 · Analyzed
7.2EPSS 0.003
CVE-2023-37979
WordPress Ninja Forms Plugin <= 3.6.25 is vulnerable to Cross Site Scripting (XSS)
Published 2023-07-27 · Modified
7.11 PoCEPSS 0.097
CVE-2021-34647
Ninja Forms <= 3.5.7 Sensitive Information Disclosure
Published 2021-09-22 · Modified
6.5EPSS 0.012
CVE-2020-36174
The Ninja Forms plugin before 3.4.27.1 for WordPress allows CSRF via services integration.
Published 2021-01-06 · Modified
6.5EPSS 0.006
CVE-2021-34648
Ninja Forms <= 3.5.7 Unprotected REST-API to Email Injection
Published 2021-09-22 · Modified
6.4EPSS 0.007
CVE-2024-13470
Ninja Forms – The Contact Form Builder That Grows With You <= 3.8.24 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
Published 2025-01-30 · Analyzed
6.4EPSS 0.003
CVE-2025-5398
Ninja Forms <= 3.10.2.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via CSTI
Published 2025-06-27 · Analyzed
6.4EPSS 0.002
CVE-2024-12238
Ninja Forms – The Contact Form Builder That Grows With You <= 3.8.22 - Authenticated (Subscriber+) Arbitrary Shortcode Execution
Published 2024-12-29 · Analyzed
6.3EPSS 0.005
CVE-2021-24165
Ninja Forms < 3.4.34 - Administrator Open Redirect
Published 2021-04-05 · Modified
6.1EPSS 0.016
CVE-2018-19796
An open redirect in the Ninja Forms plugin before 3.3.19.1 for WordPress allows Remote Attackers to redirect a user via the lib/StepProcessing/step-processing.php (aka submissions download page) redirect parameter.
Published 2018-12-03 · Modified
6.1EPSS 0.016
CVE-2023-1835
Ninja Forms < 3.6.22 - Reflected XSS
Published 2023-05-15 · Modified
6.1EPSS 0.009
CVE-2017-18574
The ninja-forms plugin before 3.0.31 for WordPress has insufficient HTML escaping in the builder.
Published 2019-08-22 · Modified
6.1EPSS 0.009
CVE-2018-7280
The Ninja Forms plugin before 3.2.14 for WordPress has XSS.
Published 2018-02-21 · Modified
6.1EPSS 0.008
CVE-2024-7354
Ninja Forms 3.8.6-3.8.10 - Reflected XSS
Published 2024-09-02 · Analyzed
6.1EPSS 0.007
CVE-2020-12462
The ninja-forms plugin before 3.4.24.2 for WordPress allows CSRF with resultant XSS.
Published 2020-04-29 · Modified
6.1EPSS 0.005
CVE-2024-29220
Ninja Forms prior to 3.8.1 contains a cross-site scripting vulnerability in custom fields for labels. If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user who is accessing to the website using the product.
Published 2024-04-11 · Analyzed
6.1EPSS 0.005
CVE-2024-3866
Ninja Forms Contact Form <= 3.8.15 - Reflected Self-Based Cross-Site Scripting via Referer
Published 2024-09-25 · Analyzed
6.1EPSS 0.003
CVE-2024-50514
WordPress Ninja Forms – The Contact Form Builder That Grows With You plugin <= 3.8.16 - Cross Site Scripting (XSS) vulnerability
Published 2024-11-19 · Modified
5.9EPSS 0.004
CVE-2024-50515
WordPress Ninja Forms – The Contact Form Builder That Grows With You plugin <= 3.8.16 - Cross Site Scripting (XSS) vulnerability
Published 2024-11-19 · Modified
5.9EPSS 0.004
CVE-2024-43999
WordPress Ninja Forms plugin <= 3.8.11 - Cross Site Scripting (XSS) vulnerability
Published 2024-09-17 · Analyzed
5.9EPSS 0.003
CVE-2021-24166
Ninja Forms < 3.4.34 - CSRF to OAuth Service Disconnection
Published 2021-04-05 · Modified
5.8EPSS 0.005
CVE-2024-26019
Ninja Forms prior to 3.8.1 contains a cross-site scripting vulnerability in submit processing. If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user who is accessing to the website using the product.
Published 2024-04-11 · Analyzed
5.4EPSS 0.005
CVE-2024-2108
Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress <= 3.8.0 - Authenticated (Author+) Stored Cross-Site Scripting
Published 2024-03-29 · Modified
5.4EPSS 0.003
1 / 2Next →