Ninjateam develops a modestly represented portfolio of WordPress plugins and productivity applications, including file management tools like FileBird and Filester, chat functionality extensions, and optimization utilities such as FastDup, that collectively serve a niche but active user base. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity, and recur across the product line through weakness classes including cross-site scripting, missing or bypassable authorization checks, and exposure of sensitive information—patterns typical of plugin-based extensions with direct access to user data and administrative interfaces. The exposure reflects the inherent risks of plugin architectures that operate within shared WordPress environments and often require broad permissions to function; defenders deploying these plugins should prioritize authorization and input-handling issues in their patch assessments. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Ninjateam over time
Signals from CVEs in this vendor scope (40 CVEs).
40 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-52703CRITICAL Unauthenticated Path Traversal in FastDup <= 2.7.2 versions. | Jun 15, 2026 | 9.6 | 35 | NO | NO |
CVE-2021-24385CRITICAL The Filebird Plugin 4.7.3 introduced a SQL injection vulnerability as it is making SQL queries without escaping user input data from a HTTP post request. This is a major vulnerabil | Jul 12, 2021 | 9.8 | 31 | NO | NO |
CVE-2023-4827HIGH The File Manager Pro WordPress plugin before 1.8 does not properly check the CSRF nonce in the `fs_connector` AJAX action. This allows attackers to make highly privileged users per | Oct 16, 2023 | 8.8 | 29 | NO | NO |
CVE-2020-24142CRITICAL Server-side request forgery in the Video Downloader for TikTok (aka downloader-tiktok) plugin 1.3 for WordPress lets an attacker send crafted requests from the back-end server of a | Jul 7, 2021 | 9.8 | 29 | NO | NO |
CVE-2024-47331CRITICAL Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ninja Team Multi Step for Contact Form cf7-multi-step allows SQL Injection.Thi | Oct 11, 2024 | 9.8 | 27 | NO | NO |
CVE-2023-6592MEDIUM The FastDup WordPress plugin before 2.2 does not prevent directory listing in sensitive directories containing export files. | Jan 16, 2024 | 5.3 | 27 | NO | YES |
CVE-2020-36718CRITICAL The GDPR CCPA Compliance Support plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.3 via deserialization of untrusted input "njt_gdpr_a | Jun 7, 2023 | 9.8 | 27 | NO | NO |
CVE-2024-8066HIGH The File Manager Pro – Filester plugin for WordPress is vulnerable to arbitrary file uploads due to missing validation in the 'fsConnector' function in all versions up to, and incl | Nov 28, 2024 | 8.8 | 26 | NO | NO |
CVE-2024-7031HIGH The File Manager Pro – Filester plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'njt_fs_saveSettingRestrictions' fu | Aug 3, 2024 | 8.8 | 25 | NO | NO |
CVE-2025-14001MEDIUM The WP Duplicate Page plugin for WordPress is vulnerable to unauthorized modification of data due to missing capability checks on the 'duplicateBulkHandle' and 'duplicateBulkHandle | Jan 13, 2026 | 5.4 | 23 | NO | NO |
Signals from CVEs in this vendor scope (40 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Ninjateam.
Media articles that mention a CVE ID that affects a product developed by Ninjateam — matched by CVE ID, not by vendor name.