Ninjaforms
Ninjaforms Ninja Forms: vulnerabilities and CVEs
Ninjaforms Ninja Forms has 76 published vulnerabilities, 21 of them in the last 12 months. 7 are rated critical and 0 are listed by CISA as actively exploited.
CVEs76
Last 12 months21
Critical7
Actively exploited0
All vulnerabilities in the catalogue →⭐ Follow this technology
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-90438 | High (7.2) | 0.29% | — | Oct 2, 2026 | The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Paragraph Text (RTE) Field Submission in all versions up to, and including, 3.15.4 due… |
| CVE-2026-102385 | High (7.1) | 0.18% | — | Sep 30, 2026 | Unauthenticated Cross Site Scripting (XSS) in Ninja Forms <= 3.15.3 versions. |
| CVE-2026-95515 | High (7.1) | 0.18% | — | Sep 23, 2026 | Unauthenticated Cross Site Scripting (XSS) in Ninja Forms <= 3.15.3 versions. |
| CVE-2026-94504 | High (7.2) | 0.41% | — | Sep 22, 2026 | Ninja Forms 3.15.3 stores an anonymous non-RTE textarea value and renders it without safe HTML encoding in the legacy submission editor. An attacker can break out of the textarea with stored script. When an… |
| CVE-2026-92438 | High (8.8) | 0.35% | — | Sep 22, 2026 | The Ninja Forms WordPress plugin 3.15.3 does not escape submitted form field values before outputting them on the submission edit screen in the admin area, which could allow unauthenticated users to submit values… |
| CVE-2026-91827 | High (7.5) | 0.30% | — | Sep 22, 2026 | The Ninja Forms WordPress plugin 3.15.3 does not prevent user-submitted form field values from being deserialised when an administrator later exports form submissions to CSV, allowing unauthenticated attackers to… |
| CVE-2026-11363 | Medium (6.6) | 0.66% | — | Sep 9, 2026 | The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.14.6 via deserialization of untrusted input . This makes… |
| CVE-2026-80437 | Medium (4.8) | 0.24% | — | Sep 6, 2026 | The Ninja Forms WordPress plugin from 3.14.10 before 3.15.2 does not prevent shortcodes in request-derived values from being executed when it substitutes them into content it later processes for shortcodes, allowing… |
| CVE-2026-19769 | High (7.2) | 0.25% | — | Sep 5, 2026 | The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Repeater Child 'type' Confusion via Unmatched Array Key in all versions up to, and… |
| CVE-2026-15256 | Medium (4.8) | 0.24% | — | Aug 6, 2026 | The Ninja Forms WordPress plugin before 3.14.10 does not prevent user-supplied query-string input, used to pre-populate a form field's default value, from being processed as a shortcode, allowing unauthenticated… |
| CVE-2026-15663 | Medium (4.9) | 0.51% | — | Jul 24, 2026 | The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to generic SQL Injection via Import File 'settings' Key in all versions up to, and including, 3.14.9 due to insufficient… |
| CVE-2026-65052 | High (8.7) | 0.58% | — | Jul 21, 2026 | Ninja Forms WordPress plugin version 3.14.8 and prior contains an improper input validation vulnerability that allows unauthenticated attackers to inject arbitrary numeric values into form calculations and payment… |
| CVE-2026-65051 | Medium (6.9) | 0.49% | — | Jul 21, 2026 | Ninja Forms WordPress plugin version 3.14.8 contains a client-side enforcement of server-side security vulnerability that allows unauthenticated attackers to bypass all form validation by merging attacker-controlled… |
| CVE-2026-65050 | High (7.1) | 0.44% | — | Jul 21, 2026 | Ninja Forms WordPress plugin version 3.14.8 and prior contains a missing authorization vulnerability in the render callback of the `ninja-forms/submissions-table` Gutenberg block that allows authenticated attackers with… |
| CVE-2026-65049 | High (8.4) | 0.44% | — | Jul 21, 2026 | Ninja Forms plugin version 3.14.8 and prior for WordPress Multisite contains an incorrect authorization vulnerability that allows a subsite Administrator to trigger network-wide deletion of all Ninja Forms data by… |
| CVE-2026-65048 | Critical (9.3) | 0.54% | — | Jul 21, 2026 | Ninja Forms plugin for WordPress versions 3.10.4 through 3.14.9 contains an unauthenticated stored cross-site scripting vulnerability in the Repeatable Fieldset feature where parseSubmissionIndex() accepts arbitrary… |
| CVE-2026-1239 | High (7.5) | 0.48% | — | Jul 1, 2026 | The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to unauthorized access of data due to a missing authorization check on the 'ninja-forms-views/token/refresh' REST… |
| CVE-2026-1307 | Medium (6.5) | 0.22% | — | Mar 28, 2026 | The Ninja Forms - The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.14.1 via a callback function for the… |
| CVE-2026-2268 | High (7.5) | 0.35% | — | Feb 10, 2026 | The Ninja Forms plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.14.0. This is due to the unsafe application of the `ninja_forms_merge_tags` filter to… |
| CVE-2025-14072 | Medium (5.3) | 0.35% | — | Jan 2, 2026 | The Ninja Forms WordPress plugin before 3.13.3 allows unauthenticated attackers to generate valid access tokens via the REST API which can then be used to read form submissions. |
| CVE-2025-11924 | High (7.5) | 0.44% | — | Dec 17, 2025 | The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 3.13.2. This is due to the plugin not properly… |
| CVE-2025-10499 | Medium (4.3) | 0.16% | — | Sep 27, 2025 | The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.12.0. This is due to missing or incorrect nonce… |
| CVE-2025-10498 | Medium (5.4) | 0.16% | — | Sep 27, 2025 | The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.12.0. This is due to missing or incorrect nonce… |
| CVE-2025-9083 | Critical (9.8) | 0.54% | — | Sep 18, 2025 | The Ninja Forms WordPress plugin before 3.11.1 unserializes user input via form field, which could allow Unauthenticated users to perform PHP Object Injection when a suitable gadget is present on the blog. |
| CVE-2025-5398 | Medium (5.4) | 0.24% | — | Jun 27, 2025 | The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the use of a templating engine in all versions up to, and including, 3.10.2.1 due to… |
| CVE-2025-2561 | Medium (4.8) | 0.25% | — | May 19, 2025 | The Ninja Forms WordPress plugin before 3.10.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the… |
| CVE-2025-2560 | Medium (4.8) | 0.25% | — | May 19, 2025 | The Ninja Forms WordPress plugin before 3.10.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the… |
| CVE-2025-2524 | Medium (4.8) | 0.30% | — | May 19, 2025 | The Ninja Forms WordPress plugin before 3.10.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the… |
| CVE-2024-13470 | Medium (5.4) | 0.31% | — | Jan 30, 2025 | The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode in all versions up to, and including, 3.8.24 due to… |
| CVE-2024-12238 | Medium (6.3) | 0.47% | — | Dec 29, 2024 | The The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 3.8.22. This is due to the software allowing… |
🎯 How it gets exploited (ATT&CK techniques)
Number of CVEs of this technology mapped to each exploitation or primary-impact technique.