WordPress Ninja Forms是WordPress基金会的一款信息化产品。 WordPress Ninja Forms 3.14.8版本存在处理逻辑错误漏洞,该漏洞源于客户端执行服务端安全策略,可能导致未经身份验证的攻击者通过将攻击者控制的字段元数据合并到服务加载的表单定义中,绕过所有表单验证。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Saturday Drive | Ninja Forms | < 3.14.9 |
affected |
3.14.9 |
unaffected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Saturday Drive | Ninja Forms | 0 ~ 3.14.9 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-65048 | 9.3 CRITICAL | Ninja Forms Unauthenticated Stored Cross-Site Scripting via Repeatable Fieldset Submission |
| CVE-2026-65049 | 9.3 CRITICAL | Ninja Forms Cross-Site Network-Wide Data Deletion on WordPress Multisite via nf_delete_all |
| CVE-2026-65052 | 7.5 HIGH | Ninja Forms Calculation and Payment Total Tampering via Fail-Open get_calc_value in ListSe |
| CVE-2026-65050 | 6.5 MEDIUM | Ninja Forms Missing Authorization in submissions-table Gutenberg Block Discloses Form Subm |
No comments yet