VendorsNinja Formsninja_forms_file_uploadsall versions
Vulnerabilities

Ninja Forms File Uploads

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

4CVEs
CVE-2022-0888
Ninja Forms - File Uploads Extension <= 3.3.0 - Arbitrary File Upload
Published 2022-03-23 · Modified
9.8EPSS 0.394
CVE-2019-10869
Path Traversal and Unrestricted File Upload exists in the Ninja Forms plugin before 3.0.23 for WordPress (when the Uploads add-on is activated). This allows an attacker to traverse the file system to access files and execute code via the includes/fields/upload.php (aka upload/submit page) name and tmp_name parameters.
Published 2019-05-07 · Modified
8.1EPSS 0.080
CVE-2022-0889
Ninja Forms - File Uploads Extension <= 3.3.12 - Reflected Cross-Site Scripting
Published 2022-03-23 · Modified
7.2EPSS 0.008
CVE-2024-1596
Ninja Forms File Uploads <= 3.3.16 - Unauthenticated Stored Cross-Site Scripting via File Upload
Published 2024-09-07 · Analyzed
7.2EPSS 0.004