Wpmanageninja
Wpmanageninja Ninja Tables: vulnerabilidades y CVE
Wpmanageninja Ninja Tables tiene 17 vulnerabilidades publicadas, 7 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE17
Últimos 12 meses7
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-86612 | Media (5.6) | 0.17% | — | 23 sept 2026 | The Ninja Tables WordPress plugin before 5.2.17 does not restrict shortcode expansion to administrator-authored table rows which, in a non-default configuration, allows unauthenticated users to have arbitrary shortcodes… |
| CVE-2026-61964 | Alta (7.1) | 0.25% | — | 6 ago 2026 | Unauthenticated Cross Site Scripting (XSS) in Ninja Tables <= 5.2.9 versions. |
| CVE-2026-65474 | Media (5.3) | 0.33% | — | 23 jul 2026 | Unauthenticated Sensitive Data Exposure in Ninja Tables <= 5.2.10 versions. |
| CVE-2026-2306 | Media (4.3) | 0.25% | — | 6 may 2026 | The Ninja Tables – Easy Data Table Builder plugin for WordPress is vulnerable to unauthorized database table creation due to missing authorization checks on the `createFluentCartTable` function in all versions up to,… |
| CVE-2026-25008 | Media (4.3) | 0.22% | — | 19 feb 2026 | Insertion of Sensitive Information Into Sent Data vulnerability in Shahjahan Jewel Ninja Tables ninja-tables allows Retrieve Embedded Sensitive Data.This issue affects Ninja Tables: from n/a through <= 5.2.5. |
| CVE-2025-69351 | Alta (8.5) | 0.24% | — | 6 ene 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Shahjahan Jewel Ninja Tables ninja-tables allows Blind SQL Injection.This issue affects Ninja Tables: from n/a… |
| CVE-2025-67519 | Alta (7.6) | 0.42% | — | 9 dic 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Shahjahan Jewel Ninja Tables ninja-tables allows SQL Injection.This issue affects Ninja Tables: from n/a through <=… |
| CVE-2025-2940 | Alta (7.2) | 0.33% | — | 27 jun 2025 | The Ninja Tables – Easy Data Table Builder plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 5.0.18 via the args[url] parameter. This makes it possible for… |
| CVE-2025-2939 | Media (5.6) | 0.50% | — | 3 jun 2025 | The Ninja Tables – Easy Data Table Builder plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 5.0.18 via deserialization of untrusted input from the args[callback] parameter… |
| CVE-2024-12772 | Media (5.4) | 0.33% | — | 31 ene 2025 | The Ninja Tables WordPress plugin before 5.0.17 does not sanitize and escape a parameter before outputting it back in the page when importing a CSV, leading to a Cross Site Scripting vulnerability. |
| CVE-2024-7304 | Media (5.4) | 0.39% | — | 27 ago 2024 | The Ninja Tables – Easiest Data Table Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 5.0.12 due to insufficient input sanitization… |
| CVE-2024-23504 | Media (5.3) | 0.33% | — | 14 jun 2024 | Missing Authorization vulnerability in WPManageNinja LLC Ninja Tables.This issue affects Ninja Tables: from n/a through 5.0.5. |
| CVE-2024-23503 | Media (4.3) | 0.33% | — | 11 jun 2024 | Missing Authorization vulnerability in WPManageNinja LLC Ninja Tables.This issue affects Ninja Tables: from n/a through 5.0.6. |
| CVE-2024-35635 | Media (4.9) | 0.24% | — | 3 jun 2024 | Server-Side Request Forgery (SSRF) vulnerability in WPManageNinja LLC Ninja Tables.This issue affects Ninja Tables: from n/a through 5.0.9. |
| CVE-2022-47136 | Alta (8.8) | 0.27% | — | 25 may 2023 | Cross-Site Request Forgery (CSRF) vulnerability in WPManageNinja LLC Ninja Tables – Best Data Table Plugin for WordPress plugin <= 4.3.4 versions. |
| CVE-2022-47137 | Media (4.8) | 0.42% | — | 10 may 2023 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in WPManageNinja LLC Ninja Tables plugin <= 4.3.4 versions. |
| CVE-2021-24900 | Media (4.8) | 0.69% | — | 1 feb 2022 | The Ninja Tables WordPress plugin before 4.1.8 does not sanitise and escape some of its table fields, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.