📦 Ninja Forms

by Ninjaforms

🔍 What is Ninja Forms?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-11924

HIGH CVSS 7.5 Dec 17, 2025

This vulnerability allows unauthenticated attackers to read arbitrary form definitions and submission records in Ninja Forms WordPress plugin. Attackers can exploit this using leaked bearer tokens fro...

CVE-2024-11052

HIGH CVSS 7.2 Dec 12, 2024

This vulnerability allows unauthenticated attackers to inject malicious JavaScript into WordPress pages using the Ninja Forms plugin. When users visit compromised pages, the scripts execute in their b...

CVE-2023-38393

HIGH CVSS 7.6 Jun 19, 2024

This CVE describes a Missing Authorization vulnerability in the Ninja Forms WordPress plugin that allows subscribers to perform unauthorized actions. It affects all Ninja Forms installations from unsp...

CVE-2024-25572

HIGH CVSS 8.8 Apr 11, 2024

This CSRF vulnerability in Ninja Forms WordPress plugin allows attackers to trick authenticated administrators into performing unintended actions on their own websites. Attackers can exploit this by l...

CVE-2021-24889

HIGH CVSS 7.2 Nov 29, 2021

This SQL injection vulnerability in the Ninja Forms Contact Form WordPress plugin allows authenticated administrators to execute arbitrary SQL commands. It affects WordPress sites running Ninja Forms ...

CVE-2021-24163

HIGH CVSS 8.8 Apr 5, 2021

This vulnerability in the Ninja Forms WordPress plugin allows low-privileged users (like subscribers) to install and activate the SendWP plugin without authorization and retrieve sensitive client_secr...

CVE-2025-10499

MEDIUM CVSS 4.3 Sep 27, 2025

This CSRF vulnerability in Ninja Forms WordPress plugin allows unauthenticated attackers to trick administrators into unknowingly enabling usage statistics collection. All WordPress sites using Ninja ...

CVE-2025-10498

MEDIUM CVSS 4.3 Sep 27, 2025

This CSRF vulnerability in Ninja Forms WordPress plugin allows unauthenticated attackers to delete CSV export files by tricking administrators into clicking malicious links. It affects WordPress sites...

CVE-2025-5398

MEDIUM CVSS 6.4 Jun 27, 2025

This vulnerability allows authenticated WordPress users with contributor-level access or higher to inject malicious scripts into pages using the Ninja Forms plugin. When other users visit those compro...

CVE-2025-2560

MEDIUM CVSS 4.8 May 19, 2025

This vulnerability in the Ninja Forms WordPress plugin allows administrators to inject malicious scripts into plugin settings, which then execute when other users view those settings. It affects WordP...

CVE-2024-13470

MEDIUM CVSS 6.4 Jan 30, 2025

This vulnerability allows authenticated WordPress users with contributor-level access or higher to inject malicious scripts into pages using the Ninja Forms plugin's shortcode. The scripts are stored ...

CVE-2024-12238

MEDIUM CVSS 6.3 Dec 29, 2024

This vulnerability allows authenticated WordPress users with Subscriber-level access or higher to execute arbitrary shortcodes through the Ninja Forms plugin. Attackers can leverage this to run malici...

CVE-2024-50515

MEDIUM CVSS 5.9 Nov 19, 2024

This stored cross-site scripting (XSS) vulnerability in Ninja Forms WordPress plugin allows attackers to inject malicious scripts into web pages that are then executed when other users view those page...

CVE-2024-3866

MEDIUM CVSS 4.7 Sep 25, 2024

This vulnerability allows unauthenticated attackers to inject malicious scripts via the Referer header in Ninja Forms Contact Form for WordPress. It affects all WordPress sites using Ninja Forms versi...

CVE-2024-7354

MEDIUM CVSS 6.1 Sep 2, 2024

This vulnerability allows attackers to inject malicious scripts via specially crafted URLs in the Ninja Forms WordPress plugin. When high-privilege users like administrators click these links, the scr...