| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2021-25056 | Ninja Forms < 3.6.10 - Admin+ Stored Cross-Site Scripting | Unknown | Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress | 中危 | - | 2022-07-04 13:05:21 | Deep Dive |
| CVE-2021-36827 | WordPress Ninja Forms Contact Form plugin <= 3.6.9 - Authenticated Stored Cross-Site Scripting (XSS) vulnerability | Saturday Drive | Ninja Forms Contact Form (WordPress plugin) | Medium | 4.8 | 2022-06-16 17:11:17 | Deep Dive |
| CVE-2022-0888 | Ninja Forms - File Uploads Extension <= 3.3.0 - Arbitrary File Upload | SaturdayDrive | Ninja Forms - File Uploads | Critical | 9.8 | 2022-03-23 19:46:51 | Deep Dive |
| CVE-2022-0889 | Ninja Forms - File Uploads Extension <= 3.3.12 - Reflected Cross-Site Scripting | SaturdayDrive | Ninja Forms - File Uploads | High | 7.2 | 2022-03-23 19:46:49 | Deep Dive |
| CVE-2021-24889 | Ninja Forms < 3.6.4 - Admin+ SQL Injection | Unknown | Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress | 高危 | - | 2021-11-29 08:25:45 | Deep Dive |
| CVE-2021-24381 | NinjaForms < 3.5.8.2 - Admin+ Stored Cross-Site Scripting | Unknown | Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress | 中危 | - | 2021-10-25 13:20:32 | Deep Dive |
| CVE-2021-34647 | Ninja Forms <= 3.5.7 Sensitive Information Disclosure | Saturday Drive | Ninja Forms | Medium | 6.5 | 2021-09-22 17:53:19 | Deep Dive |
| CVE-2021-34648 | Ninja Forms <= 3.5.7 Unprotected REST-API to Email Injection | Saturday Drive | Ninja Forms | Medium | 6.4 | 2021-09-22 17:53:12 | Deep Dive |
| CVE-2021-34620 | CSRF in WP Fluent Forms < 3.6.67 allows stored XSS and Privilege Escalation | WP Manage Ninja | WP Fluent Forms | 高危 | - | 2021-07-07 12:21:04 | Deep Dive |
| CVE-2021-24163 | Ninja Forms < 3.4.34 - Authenticated SendWP Plugin Installation and Client Secret Key Disclosure | Unknown | Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress | 高危 | - | 2021-04-05 18:27:43 | Deep Dive |
| CVE-2021-24166 | Ninja Forms < 3.4.34 - CSRF to OAuth Service Disconnection | Unknown | Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress | 中危 | - | 2021-04-05 18:27:43 | Deep Dive |
| CVE-2021-24165 | Ninja Forms < 3.4.34 - Administrator Open Redirect | Unknown | Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress | 中危 | - | 2021-04-05 18:27:43 | Deep Dive |
| CVE-2021-24164 | Ninja Forms < 3.4.34.1 - Authenticated OAuth Connection Key Disclosure | Unknown | Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress | 中危 | - | 2021-04-05 18:27:43 | Deep Dive |