Eklenti güvenlik geçmişi
Ninja Forms güvenlik açıkları
ABD Ulusal Güvenlik Açığı Veritabanı’nda (NVD) Ninja Forms – Contact Form Builder with Calculators, Quizzes, Signatures & AI Form Builder eklentisi için 60 açık kaydı bulunuyor; en yenisi 2 Ekim 2026 tarihli. Bunların 22 tanesi kritik veya yüksek önemde, 38 tanesi oturum açmadan istismar edilebiliyor. Güncel sürüm 3.15.5.
- Toplam kayıt
- 60
- Kritik veya yüksek
- 22
- Oturumsuz istismar
- 38
- Son kayıt
- 2 Ekim 2026
Bilinen açık kayıtları
En yeniden eskiye. Her kaydın özgün metni NVD’de.
depolanmış siteler arası betik çalıştırma (XSS)
Etkilenen sürümler: 3.15.4 ve öncesi · Oturum açmadan istismar edilebilir
The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Paragraph Text (RTE) Field Submission in all versions up to, and including, 3.15.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This is only exploitable when the targeted Paragraph Text field has the Rich Text Editor (RTE) option enabled.
Türkçe kayıt ve ne yapmalısiteler arası betik çalıştırma (XSS)
Etkilenen sürümler: 3.15.3 ve öncesi · Oturum açmadan istismar edilebilir
Unauthenticated Cross Site Scripting (XSS) in Ninja Forms <= 3.15.3 versions.
siteler arası betik çalıştırma (XSS)
Etkilenen sürümler: 3.15.3 ve öncesi · Oturum açmadan istismar edilebilir
Unauthenticated Cross Site Scripting (XSS) in Ninja Forms <= 3.15.3 versions.
depolanmış siteler arası betik çalıştırma (XSS)
Etkilenen sürümler: Kayıtta belirtilmemiş · Oturum açmadan istismar edilebilir
Ninja Forms 3.15.3 stores an anonymous non-RTE textarea value and renders it without safe HTML encoding in the legacy submission editor. An attacker can break out of the textarea with stored script. When an Administrator opens the attacker-known direct submission URL, the script runs in the WordPress admin origin.
siteler arası betik çalıştırma (XSS)
Etkilenen sürümler: Kayıtta belirtilmemiş · Oturum açmadan istismar edilebilir
The Ninja Forms WordPress plugin 3.15.3 does not escape submitted form field values before outputting them on the submission edit screen in the admin area, which could allow unauthenticated users to submit values through a public form that then execute in the browser of any high-privileged user who reviews the submission.
PHP nesne enjeksiyonu
Etkilenen sürümler: Kayıtta belirtilmemiş · Oturum açmadan istismar edilebilir
The Ninja Forms WordPress plugin 3.15.3 does not prevent user-submitted form field values from being deserialised when an administrator later exports form submissions to CSV, allowing unauthenticated attackers to perform PHP Object Injection; if a suitable POP chain is present via another installed plugin or theme, this can lead to actions such as arbitrary file operations or remote code execution.
PHP nesne enjeksiyonu
Etkilenen sürümler: 3.14.6 ve öncesi
The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.14.6 via deserialization of untrusted input . This makes it possible for authenticated attackers, with administrator-level access and above, to inject a PHP Object. No known POP chain is present in the vulnerable software, which means this vulnerability has no impact unless another plugin or theme containing a POP chain is installed on the site. If a POP chain is present via an additional plugin or theme installed on the target system, it may allow the attacker to perform actions like delete arbitrary files, retrieve sensitive data, or execute code depending on the POP chain present. The deserialization is triggered automatically during form import when WPN_Helper::build_nf_cache() invokes $action->get_settings() immediately after the crafted form is imported, requiring no further interaction beyond the import action itself.
enjeksiyon
Etkilenen sürümler: 3.15.2 öncesi · Oturum açmadan istismar edilebilir
The Ninja Forms WordPress plugin from 3.14.10 before 3.15.2 does not prevent shortcodes in request-derived values from being executed when it substitutes them into content it later processes for shortcodes, allowing unauthenticated users to run any shortcode registered on the site.
depolanmış siteler arası betik çalıştırma (XSS)
Etkilenen sürümler: 3.15.1 ve öncesi · Oturum açmadan istismar edilebilir
The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Repeater Child 'type' Confusion via Unmatched Array Key in all versions up to, and including, 3.15.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Exploitation requires the Ninja Forms File Uploads add-on to be active, as the attack routes the unwhitelisted child entry through the File Uploads handler to write an attacker-supplied HTML file containing arbitrary JavaScript into any web-server-writable directory, including the site root, where it is served from the site's own origin.
eksik yetki denetimi
Etkilenen sürümler: 3.15.2 öncesi
The Ninja Forms WordPress plugin before 3.15.2 does not restrict its REST abilities to administrators, accepting a Ninja Forms WordPress plugin before 3.15.2-specific capability as equivalent to full site administration, which allows any user granted that capability to read Ninja Forms WordPress plugin before 3.15.2 settings and stored form submissions, overwrite the Ninja Forms WordPress plugin before 3.15.2's configuration, and create or modify arbitrary posts and pages. The capability belongs to no default WordPress role and the Ninja Forms WordPress plugin before 3.15.2 never grants it, so an administrator must have assigned it, typically when delegating access to the form builder.
enjeksiyon
Etkilenen sürümler: 3.14.10 öncesi · Oturum açmadan istismar edilebilir
The Ninja Forms WordPress plugin before 3.14.10 does not prevent user-supplied query-string input, used to pre-populate a form field's default value, from being processed as a shortcode, allowing unauthenticated attackers to execute arbitrary shortcodes registered on the site when a form so configured is embedded on a public page.
SQL enjeksiyonu
Etkilenen sürümler: 3.14.9 ve öncesi
The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to generic SQL Injection via Import File 'settings' Key in all versions up to, and including, 3.14.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with administrator-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. The vulnerable keys originate from the 'settings' object in an attacker-controlled import file processed via file_get_contents() or base64-decoded/JSON-decoded blobs, bypassing wp_magic_quotes protections entirely; two distinct sinks are affected — _save_setting() in Model.php and insert_form_meta() in ImportForm.php — as only the value side is escaped while the key side receives no sanitization or parameterization at any point in the call chain.
güvenlik
Etkilenen sürümler: Kayıtta belirtilmemiş · Oturum açmadan istismar edilebilir
Ninja Forms WordPress plugin version 3.14.8 and prior contains an improper input validation vulnerability that allows unauthenticated attackers to inject arbitrary numeric values into form calculations and payment totals by submitting values that do not match any configured option in ListSelect or ListRadio fields. Attackers can tamper with form submission payloads to the ajax submit endpoint, causing the get_calc_value() method to fail open and return attacker-controlled values, enabling manipulation of payment amounts to zero or arbitrary figures and bypassing admin-configured pricing logic.
güvenlik
Etkilenen sürümler: Kayıtta belirtilmemiş · Oturum açmadan istismar edilebilir
Ninja Forms WordPress plugin version 3.14.8 contains a client-side enforcement of server-side security vulnerability that allows unauthenticated attackers to bypass all form validation by merging attacker-controlled field metadata over server-loaded form definitions before validation runs. Attackers can craft a malicious AJAX submission overriding field types, removing required flags, and disabling CAPTCHA checks through the nopriv AJAX endpoint to trigger form actions such as email notifications and database storage with unverified, attacker-controlled content.
eksik yetki denetimi
Etkilenen sürümler: Kayıtta belirtilmemiş
Ninja Forms WordPress plugin version 3.14.8 and prior contains a missing authorization vulnerability in the render callback of the `ninja-forms/submissions-table` Gutenberg block that allows authenticated attackers with Author-level privileges to expose stored form submissions to unauthenticated visitors by embedding the block with an arbitrary formID on a published post. Attackers can retrieve the signed bearer token injected into every page visitor's browser via `wp_localize_script` and use it against the REST API submissions endpoint to access all saved form submission field values, including sensitive personally identifiable information such as names, email addresses, and phone numbers.
eksik yetki denetimi
Etkilenen sürümler: Kayıtta belirtilmemiş · Oturum açmadan istismar edilebilir
Ninja Forms plugin version 3.14.8 and prior for WordPress Multisite contains an incorrect authorization vulnerability that allows a subsite Administrator to trigger network-wide deletion of all Ninja Forms data by exploiting a site-scoped capability check combined with unsafe multisite migration defaults. Attackers can send a crafted POST request to the admin-ajax.php endpoint with the nf_delete_all_data action and a per-site nonce to invoke migration routines that unconditionally iterate all blogs via switch_to_blog(), dropping all nf3_* tables and clearing options and transients across every subsite in the network without requiring super-admin or network-admin privileges.
depolanmış siteler arası betik çalıştırma (XSS)
Etkilenen sürümler: 3.14.9 ve öncesi · Oturum açmadan istismar edilebilir
Ninja Forms plugin for WordPress versions 3.10.4 through 3.14.9 contains an unauthenticated stored cross-site scripting vulnerability in the Repeatable Fieldset feature where parseSubmissionIndex() accepts arbitrary strings as submission indexes without numeric validation, and admin_form_element() interpolates the index directly into HTML without escaping. An unauthenticated attacker can submit a public form with a crafted repeater child key containing malicious script payloads, which execute in an administrator's browser when viewing submissions in the WordPress admin panel, enabling session-cookie theft, creation of administrator accounts, installation of malicious plugins, and arbitrary modification of site content.
eksik yetki denetimi
Etkilenen sürümler: 3.14.1 ve öncesi · Oturum açmadan istismar edilebilir
The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to unauthorized access of data due to a missing authorization check on the 'ninja-forms-views/token/refresh' REST callback in all versions up to, and including, 3.14.1. This makes it possible for unauthenticated attackers to view form submissions, which could potentially contain sensitive information.
hassas bilgi ifşası
Etkilenen sürümler: 3.14.1 ve öncesi
The Ninja Forms - The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.14.1 via a callback function for the admin_enqueue_scripts action handler in blocks/bootstrap.php. This makes it possible for authenticated attackers, with Contributor-level access and above, to gain access to an authorization token to view form submissions for arbitrary forms, which could potentially contain sensitive information.
hassas bilgi ifşası
Etkilenen sürümler: 3.14.0 ve öncesi · Oturum açmadan istismar edilebilir
The Ninja Forms plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.14.0. This is due to the unsafe application of the `ninja_forms_merge_tags` filter to user-supplied input within repeater fields, which allows the resolution of `{post_meta:KEY}` merge tags without authorization checks. This makes it possible for unauthenticated attackers to extract arbitrary post metadata from any post on the site, including sensitive data such as WooCommerce billing emails, API keys, private tokens, and customer personal information via the `nf_ajax_submit` AJAX action.
güvenlik
Etkilenen sürümler: 3.13.3 öncesi · Oturum açmadan istismar edilebilir
The Ninja Forms WordPress plugin before 3.13.3 allows unauthenticated attackers to generate valid access tokens via the REST API which can then be used to read form submissions.
yetkisiz nesne erişimi (IDOR)
Etkilenen sürümler: 3.13.2 ve öncesi · Oturum açmadan istismar edilebilir
The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 3.13.2. This is due to the plugin not properly verifying that a user is authorized before the `ninja-forms-views` REST endpoints return form metadata and submission content. This makes it possible for unauthenticated attackers to read arbitrary form definitions and submission records via a leaked bearer token granted they can load any page containing the Submissions Table block. NOTE: The developer released a patch for this issue in 3.13.1, but inadvertently introduced a REST API endpoint in which a valid bearer token could be minted for arbitrary form IDs, making this patch ineffective.
siteler arası istek sahteciliği (CSRF)
Etkilenen sürümler: 3.12.0 ve öncesi · Oturum açmadan istismar edilebilir
The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.12.0. This is due to missing or incorrect nonce validation on the maybe_opt_in() function. This makes it possible for unauthenticated attackers to opt an affected site into usage statistics collection via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
siteler arası istek sahteciliği (CSRF)
Etkilenen sürümler: 3.12.0 ve öncesi · Oturum açmadan istismar edilebilir
The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.12.0. This is due to missing or incorrect nonce validation when exporting CSV files. This makes it possible for unauthenticated attackers to delete those files granted they can trick an administrator into performing an action such as clicking on a link.
PHP nesne enjeksiyonu
Etkilenen sürümler: 3.11.1 öncesi · Oturum açmadan istismar edilebilir
The Ninja Forms WordPress plugin before 3.11.1 unserializes user input via form field, which could allow Unauthenticated users to perform PHP Object Injection when a suitable gadget is present on the blog.
depolanmış siteler arası betik çalıştırma (XSS)
Etkilenen sürümler: 3.10.2.1 ve öncesi
The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the use of a templating engine in all versions up to, and including, 3.10.2.1 due to insufficient output escaping on user data passed through the template. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
depolanmış siteler arası betik çalıştırma (XSS)
Etkilenen sürümler: 3.10.1 öncesi
The Ninja Forms WordPress plugin before 3.10.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
depolanmış siteler arası betik çalıştırma (XSS)
Etkilenen sürümler: 3.10.1 öncesi
The Ninja Forms WordPress plugin before 3.10.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
depolanmış siteler arası betik çalıştırma (XSS)
Etkilenen sürümler: 3.10.1 öncesi
The Ninja Forms WordPress plugin before 3.10.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
depolanmış siteler arası betik çalıştırma (XSS)
Etkilenen sürümler: 3.8.24 ve öncesi
The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode in all versions up to, and including, 3.8.24 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
uzaktan kod çalıştırma
Etkilenen sürümler: 3.8.22 ve öncesi
The The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 3.8.22. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for authenticated attackers, with Subscriber-level access and above, to execute arbitrary shortcodes.
depolanmış siteler arası betik çalıştırma (XSS)
Etkilenen sürümler: 3.8.19 ve öncesi · Oturum açmadan istismar edilebilir
The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the calculations parameter in all versions up to, and including, 3.8.19 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
depolanmış siteler arası betik çalıştırma (XSS)
Etkilenen sürümler: 3.8.16 ve öncesi
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kevin Stover Ninja Forms ninja-forms allows Stored XSS.This issue affects Ninja Forms: from n/a through <= 3.8.16.
depolanmış siteler arası betik çalıştırma (XSS)
Etkilenen sürümler: 3.8.16 ve öncesi
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kevin Stover Ninja Forms ninja-forms allows Stored XSS.This issue affects Ninja Forms: from n/a through <= 3.8.16.
yansıtılan siteler arası betik çalıştırma (XSS)
Etkilenen sürümler: 3.8.15 ve öncesi · Oturum açmadan istismar edilebilir
The Ninja Forms Contact Form plugin for WordPress is vulnerable to Reflected Self-Based Cross-Site Scripting via the 'Referer' header in all versions up to, and including, 3.8.15 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. Successful exploitation of this vulnerability requires "maintenance mode" for a targeted form to be enabled. However, there is no setting available to the attacker or even an administrator-level user to enable this mode. The mode is only enabled during a required update, which is a very short window of time. Additionally, because of the self-based nature of this vulnerability, attackers would have to rely on additional techniques to execute a supplied payload in the context of targeted user.
depolanmış siteler arası betik çalıştırma (XSS)
Etkilenen sürümler: 3.8.11 ve öncesi
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Saturday Drive Ninja Forms allows Stored XSS.This issue affects Ninja Forms: from n/a through 3.8.11.
yansıtılan siteler arası betik çalıştırma (XSS)
Etkilenen sürümler: 3.8.11 öncesi · Oturum açmadan istismar edilebilir
The Ninja Forms WordPress plugin before 3.8.11 does not escape an URL before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
siteler arası istek sahteciliği (CSRF)
Etkilenen sürümler: 3.8.6 ve öncesi · Oturum açmadan istismar edilebilir
Cross-Site Request Forgery (CSRF) vulnerability in Saturday Drive Ninja Forms allows Cross Site Request Forgery.This issue affects Ninja Forms: from n/a through 3.8.6.
uzaktan kod çalıştırma
Etkilenen sürümler: 3.8.4 ve öncesi · Oturum açmadan istismar edilebilir
Improper Control of Generation of Code ('Code Injection') vulnerability in Saturday Drive Ninja Forms allows Code Injection.This issue affects Ninja Forms: from n/a through 3.8.4.
eksik yetki denetimi
Etkilenen sürümler: 3.6.25 ve öncesi
Missing Authorization vulnerability in Saturday Drive Ninja Forms.This issue affects Ninja Forms: from n/a through 3.6.25.
eksik yetki denetimi
Etkilenen sürümler: 3.6.25 ve öncesi · Oturum açmadan istismar edilebilir
Missing Authorization vulnerability in Saturday Drive Ninja Forms.This issue affects Ninja Forms: from n/a through 3.6.25.
siteler arası betik çalıştırma (XSS)
Etkilenen sürümler: Kayıtta belirtilmemiş · Oturum açmadan istismar edilebilir
Ninja Forms prior to 3.8.1 contains a cross-site scripting vulnerability in custom fields for labels. If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user who is accessing to the website using the product.
siteler arası betik çalıştırma (XSS)
Etkilenen sürümler: Kayıtta belirtilmemiş
Ninja Forms prior to 3.8.1 contains a cross-site scripting vulnerability in submit processing. If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user who is accessing to the website using the product.
siteler arası istek sahteciliği (CSRF)
Etkilenen sürümler: Kayıtta belirtilmemiş · Oturum açmadan istismar edilebilir
Cross-site request forgery (CSRF) vulnerability exists in Ninja Forms prior to 3.4.31. If a website administrator views a malicious page while logging in, unintended operations may be performed.
siteler arası istek sahteciliği (CSRF)
Etkilenen sürümler: 3.8.0 ve öncesi · Oturum açmadan istismar edilebilir
The Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.8.0. This is due to missing or incorrect nonce validation on the nf_download_all_subs AJAX action. This makes it possible for unauthenticated attackers to trigger an export of a form's submission to a publicly accessible location via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
depolanmış siteler arası betik çalıştırma (XSS)
Etkilenen sürümler: 3.8.0 ve öncesi
The Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an image title embedded into a form in all versions up to, and including, 3.8.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
SQL enjeksiyonu
Etkilenen sürümler: 3.7.1 ve öncesi · Oturum açmadan istismar edilebilir
The Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to Second Order SQL Injection via the email address value submitted through forms in all versions up to, and including, 3.7.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to inject SQL in their email address that will append additional into the already existing query when an administrator triggers a personal data export.
eksik yetki denetimi
Etkilenen sürümler: 3.5.7 ve öncesi
The Ninja Forms WordPress plugin is vulnerable to arbitrary email sending via the trigger_email_action function found in the ~/includes/Routes/Submissions.php file, in versions up to and including 3.5.7. This allows authenticated attackers to send arbitrary emails from the affected server via the /ninja-forms-submissions/email-action REST API which can be used to socially engineer victims.
hassas bilgi ifşası
Etkilenen sürümler: 3.5.7 ve öncesi
The Ninja Forms WordPress plugin is vulnerable to sensitive information disclosure via the bulk_export_submissions function found in the ~/includes/Routes/Submissions.php file, in versions up to and including 3.5.7. This allows authenticated attackers to export all Ninja Forms submissions data via the /ninja-forms-submissions/export REST API which can include personally identifiable information.
hatalı girdi doğrulama
Etkilenen sürümler: 3.4.27.1 öncesi · Oturum açmadan istismar edilebilir
The Ninja Forms plugin before 3.4.27.1 for WordPress allows attackers to bypass validation via the email field.
siteler arası istek sahteciliği (CSRF)
Etkilenen sürümler: 3.4.27.1 öncesi · Oturum açmadan istismar edilebilir
The Ninja Forms plugin before 3.4.27.1 for WordPress allows CSRF via services integration.
enjeksiyon
Etkilenen sürümler: 3.4.28 öncesi · Oturum açmadan istismar edilebilir
The Ninja Forms plugin before 3.4.28 for WordPress lacks escaping for submissions-table fields.
depolanmış siteler arası betik çalıştırma (XSS)
Etkilenen sürümler: Kayıtta belirtilmemiş
The Ninja Forms plugin 3.4.22 for WordPress has Multiple Stored XSS vulnerabilities via ninja_forms[recaptcha_site_key], ninja_forms[recaptcha_secret_key], ninja_forms[recaptcha_lang], or ninja_forms[date_format].
açık yönlendirme
Etkilenen sürümler: 3.3.19.1 öncesi · Oturum açmadan istismar edilebilir
An open redirect in the Ninja Forms plugin before 3.3.19.1 for WordPress allows Remote Attackers to redirect a user via the lib/StepProcessing/step-processing.php (aka submissions download page) redirect parameter.
siteler arası betik çalıştırma (XSS)
Etkilenen sürümler: 3.3.18 öncesi · Oturum açmadan istismar edilebilir
XSS in the Ninja Forms plugin before 3.3.18 for WordPress allows Remote Attackers to execute JavaScript via the includes/Admin/Menus/Submissions.php (aka submissions page) begin_date, end_date, or form_id parameter.
güvenlik
Etkilenen sürümler: 3.3.14.1 öncesi · Oturum açmadan istismar edilebilir
The Ninja Forms plugin before 3.3.14.1 for WordPress allows CSV injection.
siteler arası betik çalıştırma (XSS)
Etkilenen sürümler: 3.2.14 öncesi · Oturum açmadan istismar edilebilir
The Ninja Forms plugin before 3.2.14 for WordPress has XSS.
PHP nesne enjeksiyonu
Etkilenen sürümler: 2.9.42.1 öncesi · Oturum açmadan istismar edilebilir
The Ninja Forms plugin before 2.9.42.1 for WordPress allows remote attackers to conduct PHP object injection attacks via crafted serialized values in a POST request.
- CVE-2015-22205 Mart 2015
siteler arası betik çalıştırma (XSS)
Etkilenen sürümler: 2.8.9 öncesi
Multiple cross-site scripting (XSS) vulnerabilities in the Ninja Forms plugin before 2.8.9 for WordPress allow (1) remote attackers to inject arbitrary web script or HTML via the ninja_forms_field_1 parameter in a ninja_forms_ajax_submit action to wp-admin/admin-ajax.php or (2) remote administrators to inject arbitrary web script or HTML via the fields[1] parameter to wp-admin/post.php.
- CVE-2014-96885 Mart 2015
güvenlik
Etkilenen sürümler: 2.8.10 öncesi
Unspecified vulnerability in the Ninja Forms plugin before 2.8.10 for WordPress has unknown impact and remote attack vectors related to admin users.
Kaynak: NVD (kamu malı veri) ve WordPress.org eklenti dizini. Kayıtlar eklentinin WordPress.org adresi veya tam adıyla eşleştirilir. Veri 7 Ekim 2026 itibarıyla.