Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Ninja Forms – The Contact Form Builder That Grows With You — Vulnerabilities & Security Advisories 17

All 17 CVE vulnerabilities found in Ninja Forms – The Contact Form Builder That Grows With You, with AI-generated Chinese analysis, references, and POCs.

This page aggregates vulnerabilities associated with Ninja Forms – The Contact Form Builder That Grows With You, focusing specifically on software defects and security weaknesses. It collects documented security flaws, including injection risks, access control failures, and configuration errors, covering advisories published over the past several years. Visitors can use this section to track the vendor's historical security posture, analyze the prevalence of specific weakness classes like cross-site scripting or stored data exposure, and review the complete vulnerability timeline for this contact form plugin. The dataset highlights recurring themes in WordPress form builders, helping developers and security teams identify patterns in how input handling and data storage have evolved. No individual CVE identifiers are listed; instead, the focus remains on thematic aggregation and trend analysis to support proactive remediation strategies and informed product selection.

Vendor: kstover

CVE ID Title CVSS Severity Published
CVE-2026-11363 Ninja Forms <= 3.14.6 - Authenticated (Administrator+) PHP Object Injection via Form Import CWE-502 6.6 Medium 2026-09-09
CVE-2026-19769 Ninja Forms <= 3.15.1 - Unauthenticated Stored Cross-Site Scripting via Repeater Child 'type' Confusion via Unmatched Array Key CWE-79 7.2 High 2026-09-05
CVE-2026-15663 Ninja Forms <= 3.14.9 - Authenticated (Administrator+) SQL Injection via Import File 'settings' Key CWE-89 4.9 Medium 2026-07-24
CVE-2026-1239 Ninja Forms <= 3.14.1 - Missing Authorization to Unauthenticated Sensitive Information Disclosure via token/refresh REST Endpoint CWE-862 7.5 High 2026-07-01
CVE-2026-1307 Ninja Forms <= 3.14.1 - Authenticated (Contributor+) Sensitive Information Disclosure via Block Editor Token CWE-200 6.5 Medium 2026-03-28
CVE-2026-2268 Ninja Forms <= 3.14.0 - Unauthenticated Information Disclosure in nf_ajax_submit AJAX Action CWE-200 7.5 High 2026-02-10
CVE-2025-11924 Ninja Forms – The Contact Form Builder That Grows With You <= 3.13.2 - Insecure Direct Object Reference to Unauthenticated Sensitive Information Exposure via Unscoped Bearer Token CWE-639 7.5 High 2025-12-17
CVE-2025-10498 Ninja Forms – The Contact Form Builder That Grows With You <= 3.12.0 - Cross-Site Request Forgery to Limited File Deletion CWE-352 4.3 Medium 2025-09-27
CVE-2025-10499 Ninja Forms – The Contact Form Builder That Grows With You <= 3.12.0 - Cross-Site Request Forgery to Plugin Settings Update CWE-352 4.3 Medium 2025-09-27
CVE-2025-5398 Ninja Forms <= 3.10.2.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via CSTI CWE-79 6.4 Medium 2025-06-27
CVE-2024-13470 Ninja Forms – The Contact Form Builder That Grows With You <= 3.8.24 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode CWE-79 6.4 Medium 2025-01-30
CVE-2024-12238 Ninja Forms – The Contact Form Builder That Grows With You <= 3.8.22 - Authenticated (Subscriber+) Arbitrary Shortcode Execution CWE-94 6.3 Medium 2024-12-29
CVE-2024-11052 Ninja Forms – The Contact Form Builder That Grows With You <= 3.8.19 - Unauthenticated Stored Cross-Site Scripting via Form Calculations CWE-79 7.2 High 2024-12-12
CVE-2024-3866 Ninja Forms Contact Form <= 3.8.15 - Reflected Self-Based Cross-Site Scripting via Referer CWE-79 4.7 Medium 2024-09-25
CVE-2024-2108 Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress <= 3.8.0 - Authenticated (Author+) Stored Cross-Site Scripting CWE-79 4.6 Medium 2024-03-29
CVE-2024-2113 Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress <= 3.8.0 - Cross-Site Request Forgery to Publicly Accessible Form Submission Export CWE-352 4.3 Medium 2024-03-29
CVE-2024-0685 Ninja Forms Contact Form <= 3.7.1 - Unauthenticated Second Order SQL Injection CWE-89 5.9 Medium 2024-02-02

All 17 known CVE vulnerabilities affecting Ninja Forms – The Contact Form Builder That Grows With You with full Chinese analysis, references, and POCs where available.