Filtered by vendor Ninjaforms
Subscribe
Total
55 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2020-36173 | 1 Ninjaforms | 1 Ninja Forms | 2024-11-21 | 5.0 MEDIUM | 5.3 MEDIUM |
The Ninja Forms plugin before 3.4.28 for WordPress lacks escaping for submissions-table fields. | |||||
CVE-2020-12462 | 1 Ninjaforms | 1 Ninja Forms | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
The ninja-forms plugin before 3.4.24.2 for WordPress allows CSRF with resultant XSS. | |||||
CVE-2019-15025 | 1 Ninjaforms | 1 Ninjaforms | 2024-11-21 | 7.5 HIGH | 9.8 CRITICAL |
The ninja-forms plugin before 3.3.21.2 for WordPress has SQL injection in the search filter on the submissions page. | |||||
CVE-2019-10869 | 1 Ninjaforms | 1 Ninja Forms File Uploads | 2024-11-21 | 6.8 MEDIUM | 8.1 HIGH |
Path Traversal and Unrestricted File Upload exists in the Ninja Forms plugin before 3.0.23 for WordPress (when the Uploads add-on is activated). This allows an attacker to traverse the file system to access files and execute code via the includes/fields/upload.php (aka upload/submit page) name and tmp_name parameters. | |||||
CVE-2018-7280 | 1 Ninjaforms | 1 Ninja Forms | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
The Ninja Forms plugin before 3.2.14 for WordPress has XSS. | |||||
CVE-2018-20981 | 1 Ninjaforms | 1 Ninja Forms | 2024-11-21 | 6.4 MEDIUM | 9.1 CRITICAL |
The ninja-forms plugin before 3.3.9 for WordPress has insufficient restrictions on submission-data retrieval during Export Personal Data requests. | |||||
CVE-2018-20980 | 1 Ninjaforms | 1 Ninja Forms | 2024-11-21 | 5.0 MEDIUM | 7.5 HIGH |
The ninja-forms plugin before 3.2.15 for WordPress has parameter tampering. | |||||
CVE-2018-19796 | 1 Ninjaforms | 1 Ninja Forms | 2024-11-21 | 5.8 MEDIUM | 6.1 MEDIUM |
An open redirect in the Ninja Forms plugin before 3.3.19.1 for WordPress allows Remote Attackers to redirect a user via the lib/StepProcessing/step-processing.php (aka submissions download page) redirect parameter. | |||||
CVE-2018-16308 | 1 Ninjaforms | 1 Ninja Forms | 2024-11-21 | 6.8 MEDIUM | 8.6 HIGH |
The Ninja Forms plugin before 3.3.14.1 for WordPress allows CSV injection. | |||||
CVE-2017-18574 | 1 Ninjaforms | 1 Ninja Forms | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
The ninja-forms plugin before 3.0.31 for WordPress has insufficient HTML escaping in the builder. | |||||
CVE-2024-39628 | 1 Ninjaforms | 1 Ninja Forms | 2024-10-20 | N/A | 5.4 MEDIUM |
Cross-Site Request Forgery (CSRF) vulnerability in Saturday Drive Ninja Forms allows Cross Site Request Forgery.This issue affects Ninja Forms: from n/a through 3.8.6. | |||||
CVE-2024-7354 | 1 Ninjaforms | 1 Ninja Forms | 2024-10-04 | N/A | 6.1 MEDIUM |
The Ninja Forms WordPress plugin before 3.8.11 does not escape an URL before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin | |||||
CVE-2024-3866 | 1 Ninjaforms | 1 Ninja Forms | 2024-10-02 | N/A | 4.7 MEDIUM |
The Ninja Forms Contact Form plugin for WordPress is vulnerable to Reflected Self-Based Cross-Site Scripting via the 'Referer' header in all versions up to, and including, 3.8.15 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. Successful exploitation of this vulnerability requires "maintenance mode" for a targeted form to be enabled. However, there is no setting available to the attacker or even an administrator-level user to enable this mode. The mode is only enabled during a required update, which is a very short window of time. Additionally, because of the self-based nature of this vulnerability, attackers would have to rely on additional techniques to execute a supplied payload in the context of targeted user. | |||||
CVE-2024-1596 | 1 Ninjaforms | 1 Ninja Forms File Uploads | 2024-09-26 | N/A | 7.2 HIGH |
The Ninja Forms - File Uploads plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an uploaded file (e.g. RTX file) in all versions up to, and including, 3.3.16 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. | |||||
CVE-2024-43999 | 1 Ninjaforms | 1 Ninja Forms | 2024-09-25 | N/A | 5.9 MEDIUM |
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Saturday Drive Ninja Forms allows Stored XSS.This issue affects Ninja Forms: from n/a through 3.8.11. |