| CVE-2025-2560 | Ninja Forms < 3.10.1 - Admin+ Stored XSS | Unknown | Ninja Forms | - | - | 2025-05-19 06:00:05 | Deep Dive |
| CVE-2025-2524 | Ninja Forms < 3.10.1 - Admin+ Stored XSS | Unknown | Ninja Forms | - | - | 2025-05-19 06:00:05 | Deep Dive |
| CVE-2024-13940 | Ninja Forms Webhooks <= 3.0.7 - Authenticated (Admin+) Server-Side Request Forgery via Form Webhook | Ninja Forms | Ninja Forms Webhooks | Medium | 5.5 | 2025-05-14 08:22:08 | Deep Dive |
| CVE-2025-32269 | WordPress WP Zendesk for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms Plugin <= 1.1.3 - Cross Site Request Forgery (CSRF) to Settings Change vulnerability | CRM Perks | WP Zendesk for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms | Medium | 4.3 | 2025-04-04 15:59:43 | Deep Dive |
| CVE-2025-30863 | WordPress Integration for Google Sheets and Contact Form 7, WPForms, Elementor, Ninja Forms plugin <= 1.0.9 - Cross Site Request Forgery (CSRF) vulnerability | CRM Perks | Integration for Google Sheets and Contact Form 7, WPForms, Elementor, Ninja Forms | Medium | 4.3 | 2025-03-27 10:55:33 | Deep Dive |
| CVE-2024-13470 | Ninja Forms – The Contact Form Builder That Grows With You <= 3.8.24 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode | kstover | Ninja Forms – The Contact Form Builder That Grows With You | Medium | 6.4 | 2025-01-30 07:23:05 | Deep Dive |
| CVE-2025-24708 | WordPress WP Dynamics CRM plugin <= 1.1.6 - Reflected Cross Site Scripting (XSS) vulnerability | CRM Perks | WP Dynamics CRM for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms | High | 7.1 | 2025-01-27 14:22:18 | Deep Dive |
| CVE-2024-12238 | Ninja Forms – The Contact Form Builder That Grows With You <= 3.8.22 - Authenticated (Subscriber+) Arbitrary Shortcode Execution | kstover | Ninja Forms – The Contact Form Builder That Grows With You | Medium | 6.3 | 2024-12-29 05:22:54 | Deep Dive |
| CVE-2024-11052 | Ninja Forms – The Contact Form Builder That Grows With You <= 3.8.19 - Unauthenticated Stored Cross-Site Scripting via Form Calculations | kstover | Ninja Forms – The Contact Form Builder That Grows With You | High | 7.2 | 2024-12-12 05:24:24 | Deep Dive |
| CVE-2024-50514 | WordPress Ninja Forms – The Contact Form Builder That Grows With You plugin <= 3.8.16 - Cross Site Scripting (XSS) vulnerability | Kevin Stover | Ninja Forms | Medium | 5.9 | 2024-11-19 16:32:17 | Deep Dive |
| CVE-2024-50515 | WordPress Ninja Forms – The Contact Form Builder That Grows With You plugin <= 3.8.16 - Cross Site Scripting (XSS) vulnerability | Kevin Stover | Ninja Forms | Medium | 5.9 | 2024-11-19 16:32:17 | Deep Dive |
| CVE-2024-10717 | Styler for Ninja Forms <= 3.3.4 - Authenticated (Subscriber+) Arbitrary Option Deletion via deactivate_license | wpmonks | Styler for Ninja Forms | Medium | 6.5 | 2024-11-13 02:02:34 | Deep Dive |
| CVE-2024-3866 | Ninja Forms Contact Form <= 3.8.15 - Reflected Self-Based Cross-Site Scripting via Referer | kstover | Ninja Forms – The Contact Form Builder That Grows With You | Medium | 4.7 | 2024-09-25 06:49:02 | Deep Dive |
| CVE-2024-43999 | WordPress Ninja Forms plugin <= 3.8.11 - Cross Site Scripting (XSS) vulnerability | Saturday Drive | Ninja Forms | Medium | 5.9 | 2024-09-17 23:14:19 | Deep Dive |
| CVE-2024-1596 | Ninja Forms File Uploads <= 3.3.16 - Unauthenticated Stored Cross-Site Scripting via File Upload | SaturdayDrive | Ninja Forms - File Uploads | High | 7.2 | 2024-09-07 11:17:03 | Deep Dive |
| CVE-2024-7354 | Ninja Forms 3.8.6-3.8.10 - Reflected XSS | Unknown | Ninja Forms | - | - | 2024-09-02 06:00:01 | Deep Dive |
| CVE-2024-39628 | WordPress Ninja Forms plugin <= 3.8.6 - Cross Site Request Forgery (CSRF) vulnerability | Saturday Drive | Ninja Forms | Medium | 5.4 | 2024-08-26 20:58:10 | Deep Dive |
| CVE-2024-37934 | WordPress Ninja Forms plugin <= 3.8.4 - Subscriber+ Arbitrary Shortcode Execution vulnerability | Saturday Drive | Ninja Forms | Medium | 5.4 | 2024-07-09 12:22:20 | Deep Dive |
| CVE-2023-38393 | WordPress Ninja Forms plugin <= 3.6.25 - Subscriber+ Broken Access Control vulnerability | Saturday Drive | Ninja Forms | High | 7.6 | 2024-06-19 14:15:39 | Deep Dive |
| CVE-2023-38386 | WordPress Ninja Forms plugin <= 3.6.25 - Contributor+ Broken Access Control vulnerability | Saturday Drive | Ninja Forms | High | 7.6 | 2024-06-19 13:06:42 | Deep Dive |