Ninjaforms
Ninjaforms Ninja Forms: vulnerabilidades y CVE
Ninjaforms Ninja Forms tiene 75 vulnerabilidades publicadas, 20 de ellas en los últimos 12 meses. 7 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE75
Últimos 12 meses20
Críticas7
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-102385 | Alta (7.1) | 0.25% | — | 30 sept 2026 | Unauthenticated Cross Site Scripting (XSS) in Ninja Forms <= 3.15.3 versions. |
| CVE-2026-95515 | Alta (7.1) | 0.18% | — | 23 sept 2026 | Unauthenticated Cross Site Scripting (XSS) in Ninja Forms <= 3.15.3 versions. |
| CVE-2026-94504 | Alta (7.2) | 0.41% | — | 22 sept 2026 | Ninja Forms 3.15.3 stores an anonymous non-RTE textarea value and renders it without safe HTML encoding in the legacy submission editor. An attacker can break out of the textarea with stored script. When an… |
| CVE-2026-92438 | Alta (8.8) | 0.35% | — | 22 sept 2026 | The Ninja Forms WordPress plugin 3.15.3 does not escape submitted form field values before outputting them on the submission edit screen in the admin area, which could allow unauthenticated users to submit values… |
| CVE-2026-91827 | Alta (7.5) | 0.30% | — | 22 sept 2026 | The Ninja Forms WordPress plugin 3.15.3 does not prevent user-submitted form field values from being deserialised when an administrator later exports form submissions to CSV, allowing unauthenticated attackers to… |
| CVE-2026-11363 | Media (6.6) | 0.66% | — | 9 sept 2026 | The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.14.6 via deserialization of untrusted input . This makes… |
| CVE-2026-80437 | Media (4.8) | 0.24% | — | 6 sept 2026 | The Ninja Forms WordPress plugin from 3.14.10 before 3.15.2 does not prevent shortcodes in request-derived values from being executed when it substitutes them into content it later processes for shortcodes, allowing… |
| CVE-2026-19769 | Alta (7.2) | 0.25% | — | 5 sept 2026 | The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Repeater Child 'type' Confusion via Unmatched Array Key in all versions up to, and… |
| CVE-2026-15256 | Media (4.8) | 0.24% | — | 6 ago 2026 | The Ninja Forms WordPress plugin before 3.14.10 does not prevent user-supplied query-string input, used to pre-populate a form field's default value, from being processed as a shortcode, allowing unauthenticated… |
| CVE-2026-15663 | Media (4.9) | 0.51% | — | 24 jul 2026 | The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to generic SQL Injection via Import File 'settings' Key in all versions up to, and including, 3.14.9 due to insufficient… |
| CVE-2026-65052 | Alta (8.7) | 0.58% | — | 21 jul 2026 | Ninja Forms WordPress plugin version 3.14.8 and prior contains an improper input validation vulnerability that allows unauthenticated attackers to inject arbitrary numeric values into form calculations and payment… |
| CVE-2026-65051 | Media (6.9) | 0.49% | — | 21 jul 2026 | Ninja Forms WordPress plugin version 3.14.8 contains a client-side enforcement of server-side security vulnerability that allows unauthenticated attackers to bypass all form validation by merging attacker-controlled… |
| CVE-2026-65050 | Alta (7.1) | 0.44% | — | 21 jul 2026 | Ninja Forms WordPress plugin version 3.14.8 and prior contains a missing authorization vulnerability in the render callback of the `ninja-forms/submissions-table` Gutenberg block that allows authenticated attackers with… |
| CVE-2026-65049 | Alta (8.4) | 0.44% | — | 21 jul 2026 | Ninja Forms plugin version 3.14.8 and prior for WordPress Multisite contains an incorrect authorization vulnerability that allows a subsite Administrator to trigger network-wide deletion of all Ninja Forms data by… |
| CVE-2026-65048 | Crítica (9.3) | 0.54% | — | 21 jul 2026 | Ninja Forms plugin for WordPress versions 3.10.4 through 3.14.9 contains an unauthenticated stored cross-site scripting vulnerability in the Repeatable Fieldset feature where parseSubmissionIndex() accepts arbitrary… |
| CVE-2026-1239 | Alta (7.5) | 0.48% | — | 1 jul 2026 | The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to unauthorized access of data due to a missing authorization check on the 'ninja-forms-views/token/refresh' REST… |
| CVE-2026-1307 | Media (6.5) | 0.22% | — | 28 mar 2026 | The Ninja Forms - The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.14.1 via a callback function for the… |
| CVE-2026-2268 | Alta (7.5) | 0.35% | — | 10 feb 2026 | The Ninja Forms plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.14.0. This is due to the unsafe application of the `ninja_forms_merge_tags` filter to… |
| CVE-2025-14072 | Media (5.3) | 0.35% | — | 2 ene 2026 | The Ninja Forms WordPress plugin before 3.13.3 allows unauthenticated attackers to generate valid access tokens via the REST API which can then be used to read form submissions. |
| CVE-2025-11924 | Alta (7.5) | 0.44% | — | 17 dic 2025 | The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 3.13.2. This is due to the plugin not properly… |
| CVE-2025-10499 | Media (4.3) | 0.16% | — | 27 sept 2025 | The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.12.0. This is due to missing or incorrect nonce… |
| CVE-2025-10498 | Media (5.4) | 0.16% | — | 27 sept 2025 | The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.12.0. This is due to missing or incorrect nonce… |
| CVE-2025-9083 | Crítica (9.8) | 0.54% | — | 18 sept 2025 | The Ninja Forms WordPress plugin before 3.11.1 unserializes user input via form field, which could allow Unauthenticated users to perform PHP Object Injection when a suitable gadget is present on the blog. |
| CVE-2025-5398 | Media (5.4) | 0.24% | — | 27 jun 2025 | The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the use of a templating engine in all versions up to, and including, 3.10.2.1 due to… |
| CVE-2025-2561 | Media (4.8) | 0.25% | — | 19 may 2025 | The Ninja Forms WordPress plugin before 3.10.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the… |
| CVE-2025-2560 | Media (4.8) | 0.25% | — | 19 may 2025 | The Ninja Forms WordPress plugin before 3.10.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the… |
| CVE-2025-2524 | Media (4.8) | 0.30% | — | 19 may 2025 | The Ninja Forms WordPress plugin before 3.10.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the… |
| CVE-2024-13470 | Media (5.4) | 0.31% | — | 30 ene 2025 | The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode in all versions up to, and including, 3.8.24 due to… |
| CVE-2024-12238 | Media (6.3) | 0.47% | — | 29 dic 2024 | The The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 3.8.22. This is due to the software allowing… |
| CVE-2024-11052 | Media (6.1) | 0.32% | — | 12 dic 2024 | The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the calculations parameter in all versions up to, and including, 3.8.19 due to… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.