Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Ninjaforms

First CVE: Mar 5, 2015Active for: 11 yearsTotal CVEs: 69
38.2
VTI Score
Medium

Ninjaforms develops a WordPress plugin ecosystem centered on form-building and data-collection tools, with a notably concentrated product portfolio that belies substantial landscape prominence due to the plugin's widespread adoption across WordPress sites. Vulnerabilities affecting the vendor skew strongly toward critical severity and concentrate in the core Ninja Forms plugin and its file-upload extensions, recurrently manifesting as cross-site scripting, cross-site request forgery, input validation gaps, and SQL injection flaws that reflect the challenges of sanitizing user-supplied form data and managing administrative access in a plugin environment. The exposure pattern is characteristic of form-processing middleware: attackers can inject malicious scripts, bypass CSRF protections, or execute arbitrary SQL through insufficiently validated input, and improper authorization controls compound the risk by allowing unauthenticated or low-privilege actors to reach sensitive functions. A moderate tendency toward public exploit availability reinforces the need for rapid patching. Defenders should prioritize Ninjaforms updates in their WordPress infrastructure and audit form configurations for exposure to untrusted input; live severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
69
Total CVEs
More Total CVEs than 99% of tracked vendors
1.3
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 75% of tracked vendors
6.5
Avg CVSS Score
Higher Avg CVSS Score than 41% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Ninjaforms over time

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 5, 2015
11 years ago
Most Recent CVE
Jul 21, 2026
3 days ago

Products(5 total)

Top CVEs

Signals from CVEs in this vendor scope (69 CVEs).

69 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2016-1209CRITICAL
The Ninja Forms plugin before 2.9.42.1 for WordPress allows remote attackers to conduct PHP object injection attacks via crafted serialized values in a POST request.
May 14, 20169.880NOYES
CVE-2022-0888CRITICAL
The Ninja Forms - File Uploads Extension WordPress plugin is vulnerable to arbitrary file uploads due to insufficient input file type validation found in the ~/includes/ajax/contro
Mar 23, 20229.853NONO
CVE-2023-37979MEDIUM
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Saturday Drive Ninja Forms Contact Form plugin <= 3.6.25 versions.
Jul 27, 20236.142NOYES
CVE-2026-65048CRITICAL
Ninja Forms plugin for WordPress versions 3.10.4 through 3.14.9 contains an unauthenticated stored cross-site scripting vulnerability in the Repeatable Fieldset feature where parse
Jul 21, 20269.340NONO
CVE-2026-65049CRITICAL
Ninja Forms plugin version 3.14.8 and prior for WordPress Multisite contains an incorrect authorization vulnerability that allows a subsite Administrator to trigger network-wide de
Jul 21, 20269.335NONO
CVE-2025-9083CRITICAL
The Ninja Forms WordPress plugin before 3.11.1 unserializes user input via form field, which could allow Unauthenticated users to perform PHP Object Injection when a suitable gadg
Sep 18, 20259.832NONO
CVE-2019-10869HIGH
Path Traversal and Unrestricted File Upload exists in the Ninja Forms plugin before 3.0.23 for WordPress (when the Uploads add-on is activated). This allows an attacker to traverse
May 7, 20198.132NONO
CVE-2026-65052HIGH
Ninja Forms WordPress plugin version 3.14.8 and prior contains an improper input validation vulnerability that allows unauthenticated attackers to inject arbitrary numeric values i
Jul 21, 20267.530NONO
CVE-2023-38386CRITICAL
Missing Authorization vulnerability in Saturday Drive Ninja Forms.This issue affects Ninja Forms: from n/a through 3.6.25.
Jun 19, 20249.830NONO
CVE-2023-1835MEDIUM
The Ninja Forms Contact Form WordPress plugin before 3.6.22 does not properly escape user input before outputting it back in an admin page, leading to a Reflected Cross-Site Script
May 15, 20236.130NOYES
View all 69 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products69 CVEs
67%
19%
14%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local1 (1.4%)
Network66 (95.7%)
Unknown2 (2.9%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low66 (95.7%)
High1 (1.4%)
Unknown2 (2.9%)
User Interaction
None27 (39.1%)
Unknown2 (2.9%)
Required40 (58.0%)
Privileges Required
Low12 (17.4%)
High15 (21.7%)
None40 (58.0%)
Unknown2 (2.9%)

Exploit Exposure

Signals from CVEs in this vendor scope (69 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
1.4% of CVEs· 97th percentile
Nuclei
4 CVEs
5.8% of CVEs· 96th percentile
ExploitDB
2 CVEs
2.9% of CVEs· 75th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Ninjaforms.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Ninjaforms — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Ninjaforms's Products

View all 6 CNAs →

Top CWEs