Ninja Forms

Vendor:

First CVE: Mar 5, 2015 · Active for 11 years

63
Total CVEs
More Total CVEs than 98% of tracked products
5.7
Avg CVEs / Year
Higher CVE frequency than 90% of tracked products
6.5
Avg CVSS
Higher Avg CVSS than 28% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Ninja Forms over time

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 5, 2015
11 years ago
Most Recent CVE
Jul 21, 2026
3 days ago

CVE Severity & Scoring

Ninja Forms63 CVEs
All CVEs352,294 CVEs
MediumHighCritical
Attack Vector
Local1 (1.6%)
Network60 (95.2%)
Unknown2 (3.2%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low61 (96.8%)
High0 (0.0%)
Unknown2 (3.2%)
User Interaction
None25 (39.7%)
Unknown2 (3.2%)
Required36 (57.1%)
Privileges Required
Low12 (19.0%)
High13 (20.6%)
None36 (57.1%)
Unknown2 (3.2%)

Top CVEs

Signals from CVEs in this product scope (63 CVEs).

63 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
The Ninja Forms plugin before 2.9.42.1 for WordPress allows remote attackers to conduct PHP object injection attacks via crafted serialized values in a POST request.
May 14, 20169.880NOYES
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Saturday Drive Ninja Forms Contact Form plugin <= 3.6.25 versions.
Jul 27, 20236.142NOYES
Ninja Forms plugin for WordPress versions 3.10.4 through 3.14.9 contains an unauthenticated stored cross-site scripting vulnerability in the Repeatable Fieldset feature where parse
Jul 21, 20269.340NONO
Ninja Forms plugin version 3.14.8 and prior for WordPress Multisite contains an incorrect authorization vulnerability that allows a subsite Administrator to trigger network-wide de
Jul 21, 20269.335NONO
The Ninja Forms WordPress plugin before 3.11.1 unserializes user input via form field, which could allow Unauthenticated users to perform PHP Object Injection when a suitable gadg
Sep 18, 20259.832NONO
Ninja Forms WordPress plugin version 3.14.8 and prior contains an improper input validation vulnerability that allows unauthenticated attackers to inject arbitrary numeric values i
Jul 21, 20267.530NONO
Missing Authorization vulnerability in Saturday Drive Ninja Forms.This issue affects Ninja Forms: from n/a through 3.6.25.
Jun 19, 20249.830NONO
The Ninja Forms Contact Form WordPress plugin before 3.6.22 does not properly escape user input before outputting it back in an admin page, leading to a Reflected Cross-Site Script
May 15, 20236.130NOYES
In the Ninja Forms Contact Form WordPress plugin before 3.4.34, the wp_ajax_nf_oauth_connect AJAX action was vulnerable to open redirect due to the use of a user supplied redirect
Apr 5, 20216.129NOYES
Missing Authorization vulnerability in Saturday Drive Ninja Forms.This issue affects Ninja Forms: from n/a through 3.6.25.
Jun 19, 20248.828NONO

Exploit Exposure

Signals from CVEs in this product scope (63 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
1.6% of CVEs· 96th percentile
Nuclei
4 CVEs
6.3% of CVEs· 97th percentile
ExploitDB
2 CVEs
3.2% of CVEs· 88th percentile

Social Chatter

Signals from CVEs in this product scope (63 CVEs).

Media Mentions

Signals from CVEs in this product scope (63 CVEs).

Top CNAs Publishing CVEs For Ninja Forms

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
3.4.2215.41.2%00