Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Ninja Forms — Vulnerabilities & Security Advisories 24

All 24 CVE vulnerabilities found in Ninja Forms, with AI-generated Chinese analysis, references, and POCs.

This page documents vulnerability aggregation for Ninja Forms, a popular WordPress plugin developed by Ninja Forms LLC, focusing on weaknesses classified under CWE identifiers. It collects data regarding security flaws identified in the software, covering advisories and disclosures released from its initial public availability through recent updates. Users can utilize this resource to track the vendor’s security response history, understand the prevalence and impact of specific weakness classes within this ecosystem, and examine the chronological vulnerability profile of the product to assess its security posture over time. The information serves as a reference for developers, security researchers, and administrators seeking to understand the risk landscape associated with Ninja Forms. By consolidating these details, the page provides a centralized view of past incidents, aiding in the evaluation of remediation efforts and the identification of recurring patterns in the plugin’s codebase or configuration. This context supports informed decision-making regarding deployment strategies and patch management cycles. The scope includes various vulnerability types such as cross-site scripting, SQL injection, and unauthorized access issues, reflecting the diverse attack surfaces present in modern WordPress plugins. Stakeholders interested in the evolution of security practices within this specific tool can find valuable insights into how the vendor addresses threats and maintains compliance with industry standards. This overview facilitates a deeper comprehension of the technical debt and security maturity of the product.

Vendor: Saturday Drive

CVE IDTitleCVSSSeverityPublished
CVE-2026-15256 Ninja Forms < 3.14.10 - Unauthenticated Arbitrary Shortcode Execution via Query-String Populated Field Default 4.8 Medium2026-08-06
CVE-2026-65052 Ninja Forms Calculation and Payment Total Tampering via Fail-Open get_calc_value in ListSelect and ListRadio Fields CWE-472 7.5 High2026-07-21
CVE-2026-65051 Ninja Forms Server-Side Validation Bypass via Client-Controlled Field Metadata Merge in AJAX Submission Handler CWE-602 6.5 Medium2026-07-21
CVE-2026-65050 Ninja Forms Missing Authorization in submissions-table Gutenberg Block Discloses Form Submissions to Unauthenticated Visitors CWE-862 6.5 Medium2026-07-21
CVE-2026-65049 Ninja Forms Cross-Site Network-Wide Data Deletion on WordPress Multisite via nf_delete_all_data AJAX Action CWE-863 9.3 Critical2026-07-21
CVE-2026-65048 Ninja Forms Unauthenticated Stored Cross-Site Scripting via Repeatable Fieldset Submission Index CWE-79 9.3 Critical2026-07-21
CVE-2025-14072 Ninja Forms < 3.13.3 - Unauthenticated Token Generation and Submission Disclosure 5.3 -2026-01-02
CVE-2025-9083 Ninja-forms < 3.11.1 - Unauthenticated PHP Objection 9.8AICriticalAI2025-09-18
CVE-2025-2561 Ninja Forms < 3.10.1 - Admin+ Stored XSS 4.8AIMediumAI2025-05-19
CVE-2025-2524 Ninja Forms < 3.10.1 - Admin+ Stored XSS 4.8AIMediumAI2025-05-19
CVE-2025-2560 Ninja Forms < 3.10.1 - Admin+ Stored XSS 4.8AIMediumAI2025-05-19
CVE-2024-50515 WordPress Ninja Forms – The Contact Form Builder That Grows With You plugin <= 3.8.16 - Cross Site Scripting (XSS) vulnerability CWE-79 5.9 Medium2024-11-19
CVE-2024-50514 WordPress Ninja Forms – The Contact Form Builder That Grows With You plugin <= 3.8.16 - Cross Site Scripting (XSS) vulnerability CWE-79 5.9 Medium2024-11-19
CVE-2024-43999 WordPress Ninja Forms plugin <= 3.8.11 - Cross Site Scripting (XSS) vulnerability CWE-79 5.9 Medium2024-09-17
CVE-2024-7354 Ninja Forms 3.8.6-3.8.10 - Reflected XSS 6.1AIMediumAI2024-09-02
CVE-2024-39628 WordPress Ninja Forms plugin <= 3.8.6 - Cross Site Request Forgery (CSRF) vulnerability CWE-352 5.4 Medium2024-08-26
CVE-2024-37934 WordPress Ninja Forms plugin <= 3.8.4 - Subscriber+ Arbitrary Shortcode Execution vulnerability CWE-94 5.4 Medium2024-07-09
CVE-2023-38393 WordPress Ninja Forms plugin <= 3.6.25 - Subscriber+ Broken Access Control vulnerability CWE-862 7.6 High2024-06-19
CVE-2023-38386 WordPress Ninja Forms plugin <= 3.6.25 - Contributor+ Broken Access Control vulnerability CWE-862 7.6 High2024-06-19
CVE-2024-25572 WordPress Plugin Ninja Forms Contact Form 安全漏洞 8.8AIHighAI2024-04-11
CVE-2024-26019 WordPress Plugin Ninja Forms Contact Form 安全漏洞 6.1AIMediumAI2024-04-11
CVE-2024-29220 WordPress plugin Ninja Forms 安全漏洞 5.4AIMediumAI2024-04-11
CVE-2021-34647 Ninja Forms <= 3.5.7 Sensitive Information Disclosure CWE-863 6.5 Medium2021-09-22
CVE-2021-34648 Ninja Forms <= 3.5.7 Unprotected REST-API to Email Injection CWE-863 6.4 Medium2021-09-22

All 24 known CVE vulnerabilities affecting Ninja Forms with full Chinese analysis, references, and POCs where available.