The Ninja Forms WordPress plugin 3.15.3 does not prevent user-submitted form field values from being deserialised when an administrator later exports form submissions to CSV, allowing unauthenticated attackers to perform PHP Object Injection; if a suitable POP
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Unknown | Ninja Forms | 3.15.3< 3.15.4 |
affected |
Shenlong is analyzing...
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Unknown | Ninja Forms | 3.15.3 ~ 3.15.4 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-92438 | 8.8 HIGH | Ninja Forms 3.15.3 - Unauthenticated Stored XSS via Paragraph Text Field in Submissions Ad |
| CVE-2026-88788 | Text Styler <= 1.1.1 - Contributor+ Stored XSS |
No comments yet