Ninja Forms
Vendor:
First CVE: Mar 5, 2015 · Active for 11 years
63
Total CVEs
More Total CVEs than 98% of tracked products
5.7
Avg CVEs / Year
Higher CVE frequency than 90% of tracked products
6.5
Avg CVSS
Higher Avg CVSS than 28% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Ninja Forms over time
Volume of CVEsAvg CVSS Base Score
First CVE
Mar 5, 2015
11 years ago
Most Recent CVE
Jul 21, 2026
3 days ago
CVE Severity & Scoring
Ninja Forms63 CVEs
67%
19%
14%
All CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local1 (1.6%)
Network60 (95.2%)
Unknown2 (3.2%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low61 (96.8%)
High0 (0.0%)
Unknown2 (3.2%)
User Interaction
None25 (39.7%)
Unknown2 (3.2%)
Required36 (57.1%)
Privileges Required
Low12 (19.0%)
High13 (20.6%)
None36 (57.1%)
Unknown2 (3.2%)
Top CVEs
Signals from CVEs in this product scope (63 CVEs).
63 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2016-1209CRITICAL The Ninja Forms plugin before 2.9.42.1 for WordPress allows remote attackers to conduct PHP object injection attacks via crafted serialized values in a POST request. | May 14, 2016 | 9.8 | 80 | NO | YES |
CVE-2023-37979MEDIUM Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Saturday Drive Ninja Forms Contact Form plugin <= 3.6.25 versions. | Jul 27, 2023 | 6.1 | 42 | NO | YES |
CVE-2026-65048CRITICAL Ninja Forms plugin for WordPress versions 3.10.4 through 3.14.9 contains an unauthenticated stored cross-site scripting vulnerability in the Repeatable Fieldset feature where parse | Jul 21, 2026 | 9.3 | 40 | NO | NO |
CVE-2026-65049CRITICAL Ninja Forms plugin version 3.14.8 and prior for WordPress Multisite contains an incorrect authorization vulnerability that allows a subsite Administrator to trigger network-wide de | Jul 21, 2026 | 9.3 | 35 | NO | NO |
CVE-2025-9083CRITICAL The Ninja Forms WordPress plugin before 3.11.1 unserializes user input via form field, which could allow Unauthenticated users to perform PHP Object Injection when a suitable gadg | Sep 18, 2025 | 9.8 | 32 | NO | NO |
CVE-2026-65052HIGH Ninja Forms WordPress plugin version 3.14.8 and prior contains an improper input validation vulnerability that allows unauthenticated attackers to inject arbitrary numeric values i | Jul 21, 2026 | 7.5 | 30 | NO | NO |
CVE-2023-38386CRITICAL Missing Authorization vulnerability in Saturday Drive Ninja Forms.This issue affects Ninja Forms: from n/a through 3.6.25. | Jun 19, 2024 | 9.8 | 30 | NO | NO |
CVE-2023-1835MEDIUM The Ninja Forms Contact Form WordPress plugin before 3.6.22 does not properly escape user input before outputting it back in an admin page, leading to a Reflected Cross-Site Script | May 15, 2023 | 6.1 | 30 | NO | YES |
CVE-2021-24165MEDIUM In the Ninja Forms Contact Form WordPress plugin before 3.4.34, the wp_ajax_nf_oauth_connect AJAX action was vulnerable to open redirect due to the use of a user supplied redirect | Apr 5, 2021 | 6.1 | 29 | NO | YES |
CVE-2023-38393HIGH Missing Authorization vulnerability in Saturday Drive Ninja Forms.This issue affects Ninja Forms: from n/a through 3.6.25. | Jun 19, 2024 | 8.8 | 28 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (63 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
1.6% of CVEs· 96th percentile
Nuclei
4 CVEs
6.3% of CVEs· 97th percentile
ExploitDB
2 CVEs
3.2% of CVEs· 88th percentile
Social Chatter
Signals from CVEs in this product scope (63 CVEs).
Media Mentions
Signals from CVEs in this product scope (63 CVEs).
Top CNAs Publishing CVEs For Ninja Forms
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 3.4.22 | 1 | 5.4 | 1.2% | 0 | 0 |