Vulnerabilities > Ninjaforms > Ninja Forms File Uploads > Medium
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2024-09-07 | CVE-2024-1596 | Cross-site Scripting vulnerability in Ninjaforms Ninja Forms File Uploads The Ninja Forms - File Uploads plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an uploaded file (e.g. | 6.1 |
2022-03-23 | CVE-2022-0889 | Cross-site Scripting vulnerability in Ninjaforms Ninja Forms File Uploads The Ninja Forms - File Uploads Extension WordPress plugin is vulnerable to reflected cross-site scripting due to missing sanitization of the files filename parameter found in the ~/includes/ajax/controllers/uploads.php file which can be used by unauthenticated attackers to add malicious web scripts to vulnerable WordPress sites, in versions up to and including 3.3.12. | 6.1 |