Ninja Forms <= 3.11.0 - Unauthenticated PHP Object Injection
Ninja Forms – The Contact Form Builder That Grows With You
Minimum safe version
3.14.2
Update to 3.14.2 or later to address 103 fixable vulnerabilities
Ninja Forms <= 3.14.0 - Unauthenticated Information Disclosure in nf_ajax_submit AJAX Action
Ninja Forms <= 3.14.1 - Authenticated (Contributor+) Sensitive Information Disclosure via Block Editor Token
CVE-2025-14072
CVE-2025-11924
CVE-2025-10499
CVE-2025-10498
Ninja Forms <= 3.10.2.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via CSTI
Ninja Forms – The Contact Form Builder That Grows With You <= 3.10.0 - Authenticated (Admin+) Stored Cross-Site Scripting
Ninja Forms – The Contact Form Builder That Grows With You <= 3.10.0 - Authenticated (Admin+) Stored Cross-Site Scripting
Ninja Forms – The Contact Form Builder That Grows With You <= 3.10.0 - Authenticated (Admin+) Stored Cross-Site Scripting
CVE-2024-13470
CVE-2024-12238
CVE-2024-11052
CVE-2024-50515
CVE-2024-50514
CVE-2024-3866
WordPress Ninja Forms Plugin 3.8.6-3.8.10 is vulnerable to Cross Site Scripting (XSS)
CVE-2024-7354
CVE-2024-43999
CVE-2024-39628
CVE-2024-37934
CVE-2024-25572
CVE-2024-26019
CVE-2024-29220
CVE-2024-2113
CVE-2024-2108
CVE-2024-0685
WordPress Ninja Forms Plugin < 3.6.34 is vulnerable to Cross Site Scripting (XSS)
CVE-2023-4109
Ninja Forms <= 2.9.10 - Cross-Site Scripting (XSS)
Ninja Forms <= 2.9.18 - Cross-Site Scripting (XSS)
Ninja Forms <= 2.9.21 - Authenticated Reflected Cross-Site Scripting (XSS)
Ninja Forms <= 2.9.27 - Malicious File Export
Ninja Forms <= 2.9.51 - Multiple Authenticated Cross-Site Scripting (XSS)
Ninja Forms <= 2.9.55.1 - Authenticated SQL Injection
Ninja Forms <= 3.3.13 - Cross-Site Scripting (XSS) in Import Function
Ninja Forms <= 3.3.21 - XSS and SQLi
Nina Forms < 3.5.5 - Reflected Cross-Site Scripting
Ninja Forms < 3.6.8 - Unauthenticated Email Address Disclosure
Ninja Forms < 3.6.11 - Unauthenticated PHP Object Injection
CVE-2023-38393
CVE-2023-38386
CVE-2023-37979
CVE-2023-35909
CVE-2023-36505
CVE-2023-1835
Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress <= 2.8.6 - Reflected Cross-Site Scripting
Ninja Forms <= 2.9.10 - Reflected Cross-Site Scripting
Ninja Forms Contact Form <= 2.9.18 - Cross-Site Scripting
Ninja Forms Contact Form <= 2.9.21 - Reflected Cross-Site Scripting
Ninja Forms Contact Form <= 2.9.27 - CSV Injection
Ninja Forms Contact Form <= 2.9.28 - Stored Cross-Site Scripting
Ninja Forms Contact Form <= 2.9.51 - Multiple Reflected Cross-Site Scripting
Ninja Forms Contact Form <= 2.9.55.1 - Authenticated SQL Injection
Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress <= 3.0.31 - Arbitrary Wordpress Shortcode Injection
Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress <= 3.3.13 - Cross-Site Scripting
Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress <= 3.6.7 - Email Address Disclosure
Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress <= 3.6.9 - Cross-Site Request Forgery to Field Import and PHP Object Injection
Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress <= 3.6.10 - Code Injection
CVE-2022-2903
WordPress Ninja Forms Plugin <= 2.9.10 - Cross Site Scripting
WordPress Ninja Forms Plugin - Authorization Bypass
CVE-2021-25066
WordPress Ninja Forms Plugin <= 2.9.18 - Cross Site Scripting
CVE-2021-36827
WordPress Ninja Forms Plugin <= 2.9.21 - Cross Site Scripting
WordPress Ninja Forms plugin <= 3.6.10 - Unauthenticated PHP Object Injection vulnerability
WordPress Ninja Forms Plugin <= 2.9.27 - Malicious File Export
CVE-2021-25056
WordPress Ninja Forms Plugin <= 2.9.51 - Multiple Cross Site Scripting
WordPress Ninja Forms Plugin <= 2.9.55.1 - Authenticated SQL Injection
WordPress Ninja Forms plugin <= 3.3.13 - Cross-Site Scripting (XSS) vulnerability
WordPress Ninja Forms plugin <= 3.3.13 - CSV Injection vulnerability
WordPress Ninja Forms plugin <= 3.3.21 - SQL injection (SQLi) vulnerability
WordPress Ninja Forms plugin <= 3.3.21 - Cross-Site Scripting (XSS) vulnerability
WordPress Ninja Forms plugin <= 3.4.27 - Cross-Site Request Forgery (CSRF) leading to Arbitrary Plugin Installation vulnerability
WordPress Ninja Forms Contact Form plugin <= 3.4.33 - Authenticated SendWP Plugin Installation and Client Secret Key Disclosure vulnerability
WordPress Ninja Forms Contact Form plugin <= 3.4.33 - Authenticated OAuth Connection Key Disclosure vulnerability
WordPress Ninja Forms Contact Form plugin <= 3.4.33 - Administrator Open Redirect vulnerability
WordPress Ninja Forms Contact Form plugin <= 3.4.33 - Cross-Site Request Forgery (CSRF) vulnerability
WordPress Ninja Forms plugin <= 3.6.7 - Unauthenticated Email Address Disclosure vulnerability
CVE-2015-2220
CVE-2014-9688
CVE-2016-1209
WordPress Ninja Forms plugin <=3.2.13 - Cross-Site Scripting (XSS) vulnerability
CVE-2018-16308
CVE-2018-19287
WordPress Ninja Forms plugin <= 3.3.19 - Authenticated Open Redirect vulnerability
CVE-2019-15025
CVE-2017-18574
CVE-2018-20980
CVE-2018-20981
CVE-2020-8594
CVE-2020-12462
CVE-2020-36175
CVE-2020-36174
CVE-2020-36173
CVE-2021-24166
CVE-2021-24164
CVE-2021-24163
CVE-2021-24165
CVE-2021-34648
CVE-2021-34647
CVE-2021-24381
CVE-2021-24889