Ninjaforma's vulnerability profile centers on its Ninja Forms web form plugin, a component embedded across WordPress installations for handling user input and form submissions. The observed weakness class in this vendor's disclosures reflects the application-layer input-handling risk inherent to web-facing form builders, with cross-site scripting appearing as the durable signal. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Ninjaforma over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-19287MEDIUM XSS in the Ninja Forms plugin before 3.3.18 for WordPress allows Remote Attackers to execute JavaScript via the includes/Admin/Menus/Submissions.php (aka submissions page) begin_da | Nov 15, 2018 | 6.1 | 43 | NO | YES |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Ninjaforma.
Media articles that mention a CVE ID that affects a product developed by Ninjaforma — matched by CVE ID, not by vendor name.