Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Ninja Forms — Vulnerabilities & Security Advisories 24

All 24 CVE vulnerabilities found in Ninja Forms, with AI-generated Chinese analysis, references, and POCs.

This page documents vulnerability aggregation for Ninja Forms, a popular WordPress plugin developed by Ninja Forms LLC, focusing on weaknesses classified under CWE identifiers. It collects data regarding security flaws identified in the software, covering advisories and disclosures released from its initial public availability through recent updates. Users can utilize this resource to track the vendor’s security response history, understand the prevalence and impact of specific weakness classes within this ecosystem, and examine the chronological vulnerability profile of the product to assess its security posture over time. The information serves as a reference for developers, security researchers, and administrators seeking to understand the risk landscape associated with Ninja Forms. By consolidating these details, the page provides a centralized view of past incidents, aiding in the evaluation of remediation efforts and the identification of recurring patterns in the plugin’s codebase or configuration. This context supports informed decision-making regarding deployment strategies and patch management cycles. The scope includes various vulnerability types such as cross-site scripting, SQL injection, and unauthorized access issues, reflecting the diverse attack surfaces present in modern WordPress plugins. Stakeholders interested in the evolution of security practices within this specific tool can find valuable insights into how the vendor addresses threats and maintains compliance with industry standards. This overview facilitates a deeper comprehension of the technical debt and security maturity of the product.

Vendor: Saturday Drive

CVE ID Title CVSS Severity Published
CVE-2026-15256 Ninja Forms < 3.14.10 - Unauthenticated Arbitrary Shortcode Execution via Query-String Populated Field Default 4.8 Medium 2026-08-06
CVE-2026-65052 Ninja Forms Calculation and Payment Total Tampering via Fail-Open get_calc_value in ListSelect and ListRadio Fields CWE-472 7.5 High 2026-07-21
CVE-2026-65051 Ninja Forms Server-Side Validation Bypass via Client-Controlled Field Metadata Merge in AJAX Submission Handler CWE-602 6.5 Medium 2026-07-21
CVE-2026-65050 Ninja Forms Missing Authorization in submissions-table Gutenberg Block Discloses Form Submissions to Unauthenticated Visitors CWE-862 6.5 Medium 2026-07-21
CVE-2026-65049 Ninja Forms Cross-Site Network-Wide Data Deletion on WordPress Multisite via nf_delete_all_data AJAX Action CWE-863 9.3 Critical 2026-07-21
CVE-2026-65048 Ninja Forms Unauthenticated Stored Cross-Site Scripting via Repeatable Fieldset Submission Index CWE-79 9.3 Critical 2026-07-21
CVE-2025-14072 Ninja Forms < 3.13.3 - Unauthenticated Token Generation and Submission Disclosure 5.3 - 2026-01-02
CVE-2025-9083 Ninja-forms < 3.11.1 - Unauthenticated PHP Objection 9.8AI Critical AI 2025-09-18
CVE-2025-2561 Ninja Forms < 3.10.1 - Admin+ Stored XSS 4.8AI Medium AI 2025-05-19
CVE-2025-2524 Ninja Forms < 3.10.1 - Admin+ Stored XSS 4.8AI Medium AI 2025-05-19
CVE-2025-2560 Ninja Forms < 3.10.1 - Admin+ Stored XSS 4.8AI Medium AI 2025-05-19
CVE-2024-50515 WordPress Ninja Forms – The Contact Form Builder That Grows With You plugin <= 3.8.16 - Cross Site Scripting (XSS) vulnerability CWE-79 5.9 Medium 2024-11-19
CVE-2024-50514 WordPress Ninja Forms – The Contact Form Builder That Grows With You plugin <= 3.8.16 - Cross Site Scripting (XSS) vulnerability CWE-79 5.9 Medium 2024-11-19
CVE-2024-43999 WordPress Ninja Forms plugin <= 3.8.11 - Cross Site Scripting (XSS) vulnerability CWE-79 5.9 Medium 2024-09-17
CVE-2024-7354 Ninja Forms 3.8.6-3.8.10 - Reflected XSS 6.1AI Medium AI 2024-09-02
CVE-2024-39628 WordPress Ninja Forms plugin <= 3.8.6 - Cross Site Request Forgery (CSRF) vulnerability CWE-352 5.4 Medium 2024-08-26
CVE-2024-37934 WordPress Ninja Forms plugin <= 3.8.4 - Subscriber+ Arbitrary Shortcode Execution vulnerability CWE-94 5.4 Medium 2024-07-09
CVE-2023-38393 WordPress Ninja Forms plugin <= 3.6.25 - Subscriber+ Broken Access Control vulnerability CWE-862 7.6 High 2024-06-19
CVE-2023-38386 WordPress Ninja Forms plugin <= 3.6.25 - Contributor+ Broken Access Control vulnerability CWE-862 7.6 High 2024-06-19
CVE-2024-25572 WordPress Plugin Ninja Forms Contact Form 安全漏洞 8.8AI High AI 2024-04-11
CVE-2024-26019 WordPress Plugin Ninja Forms Contact Form 安全漏洞 6.1AI Medium AI 2024-04-11
CVE-2024-29220 WordPress plugin Ninja Forms 安全漏洞 5.4AI Medium AI 2024-04-11
CVE-2021-34647 Ninja Forms <= 3.5.7 Sensitive Information Disclosure CWE-863 6.5 Medium 2021-09-22
CVE-2021-34648 Ninja Forms <= 3.5.7 Unprotected REST-API to Email Injection CWE-863 6.4 Medium 2021-09-22

All 24 known CVE vulnerabilities affecting Ninja Forms with full Chinese analysis, references, and POCs where available.