Pricing
Case studies
Login
Start trial
Ninja Forms
Kevin Stover
Developer
3.14.2
Latest version
600,000
Installations
No date
Last updated
WordPress Plugin
No VDP
See changelog
Claim ownership
Report vulnerability
Vulnerabilities
Security Contributors
Vulnerability history
0 present
62 patched
18 Mitigation rules
Authenticated (Contributor+) Sensitive Information Disclosure via Block Editor Token vulnerability
<= 3.14.1
4 days ago
Unauthenticated Information Disclosure in nf_ajax_submit AJAX Action vulnerability
<= 3.14.0
10/02/2026
Admin+ Stored XSS vulnerability
< 3.10.1
31/12/2025
Admin+ Stored XSS vulnerability
< 3.10.1
31/12/2025
Insecure Direct Object Reference to Unauthenticated Sensitive Information Exposure via Unscoped Bearer Token vulnerability
<= 3.13.2
17/12/2025
Cross-Site Request Forgery to Limited File Deletion vulnerability
<= 3.12.0
26/09/2025
Cross-Site Request Forgery to Plugin Settings Update vulnerability
<= 3.12.0
26/09/2025
Unauthenticated PHP Object Injection vulnerability
< 3.11.1
09/09/2025
Authenticated (Contributor+) Stored Cross-Site Scripting via CSTI vulnerability
<= 3.10.2.1
26/06/2025
Admin+ Stored XSS vulnerability
< 3.10.1
19/05/2025
Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode vulnerability
<= 3.8.24
30/01/2025
Authenticated (Subscriber+) Arbitrary Shortcode Execution vulnerability
<= 3.8.22
30/12/2024
Unauthenticated Stored Cross-Site Scripting via Form Calculations vulnerability
<= 3.8.19
12/12/2024
Cross Site Scripting (XSS) vulnerability
<= 3.8.16
28/10/2024
Cross Site Scripting (XSS) vulnerability
<= 3.8.16
28/10/2024
Reflected Self-Based Cross-Site Scripting via Referer vulnerability
<= 3.8.15
25/09/2024
Wordpress Ninja Forms plugin 3.8.6 - 3.8.10 - Reflected XSS
3.8.6-3.8.10
03/09/2024
Cross Site Scripting (XSS) vulnerability
<= 3.8.11
28/08/2024
Cross Site Request Forgery (CSRF) vulnerability
<= 3.8.6
24/07/2024
Subscriber+ Arbitrary Shortcode Execution vulnerability
<= 3.8.4
04/07/2024
Cross-Site Request Forgery to Publicly Accessible Form Submission Export vulnerability
<= 3.8.0
29/03/2024
Authenticated (Author+) Stored Cross-Site Scripting vulnerability
<= 3.8.0
29/03/2024
Unauthenticated Second Order SQL Injection vulnerability
<= 3.7.1
01/02/2024
Admin+ Stored XSS vulnerability
< 3.6.34
07/11/2023
Reflected Cross Site Scripting (XSS) vulnerability
<= 3.6.25
25/07/2023
Subscriber+ Broken Access Control vulnerability
<= 3.6.25
25/07/2023
Contributor+ Broken Access Control vulnerability
<= 3.6.25
25/07/2023
Denial of Service Attack vulnerability
<= 3.6.25
07/07/2023
Arbitrary File Deletion vulnerability
<= 3.6.24
22/06/2023
Reflected XSS vulnerability
< 3.6.22
02/05/2023
Authenticated PHP Objection Injection vulnerability
<= 3.6.12
05/09/2022
Unauthenticated PHP Object Injection vulnerability
<= 3.6.10
15/06/2022
Authenticated Stored Cross-Site Scripting (XSS) vulnerability
<= 3.6.9
13/06/2022
Authenticated Stored Cross-Site Scripting (XSS) vulnerability
<= 3.6.9
10/06/2022
Authenticated Stored Cross-Site Scripting (XSS) vulnerability
<= 3.6.9
07/06/2022
Unauthenticated Email Address Disclosure vulnerability
<= 3.6.7
22/03/2022
SQL Injection (SQLi) vulnerability
<= 3.6.3
26/10/2021
Stored Cross-Site Scripting (XSS) vulnerability
<= 3.5.8.1
27/09/2021
Unprotected REST-API to Sensitive Information Disclosure vulnerability
<= 3.5.7
22/09/2021
Unprotected REST-API to Email Injection vulnerability
<= 3.5.7
22/09/2021
Cross-Site Request Forgery (CSRF) vulnerability
<= 3.4.33
16/02/2021
Administrator Open Redirect vulnerability
<= 3.4.33
16/02/2021
Authenticated OAuth Connection Key Disclosure vulnerability
<= 3.4.33
16/02/2021
Authenticated SendWP Plugin Installation and Client Secret Key Disclosure vulnerability
<= 3.4.33
16/02/2021
Cross-Site Request Forgery (CSRF) leading to Arbitrary Plugin Installation vulnerability
<= 3.4.27
22/09/2020
Cross-Site Scripting (XSS) vulnerability
<= 3.3.21
25/06/2019
SQL injection (SQLi) vulnerability
<= 3.3.21
25/06/2019
Authenticated Open Redirect vulnerability
<= 3.3.19
04/12/2018
Unauthenticated Cross-Site Scripting (XSS) vulnerability
<= 3.3.17
15/11/2018
CSV Injection vulnerability
<= 3.3.13
28/08/2018
Cross-Site Scripting (XSS) vulnerability
<= 3.3.13
28/08/2018
Cross-Site Scripting (XSS) vulnerability
<= 3.2.13
22/02/2018
Authenticated SQL Injection
<= 2.9.55.1
16/08/2016
Multiple Cross Site Scripting
<= 2.9.51
19/07/2016
PHP Object Injection
<= 2.9.42.0
26/12/2015
Malicious File Export
<= 2.9.27
30/09/2015
Cross Site Scripting
<= 2.9.21
04/08/2015
Cross Site Scripting
<= 2.9.18
05/06/2015
Cross Site Scripting
<= 2.9.10
20/04/2015
Multiple XSS
<= 2.8.8
05/03/2015
Unspecified Vulnerability
<= 2.8.9
05/03/2015
Authorization Bypass
<= 2.7.7
08/09/2014