Vulnerabilities > Ninjaforms > Ninja Forms File Uploads > Medium

DATE CVE VULNERABILITY TITLE RISK
2024-09-07 CVE-2024-1596 Cross-site Scripting vulnerability in Ninjaforms Ninja Forms File Uploads
The Ninja Forms - File Uploads plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an uploaded file (e.g.
network
low complexity
ninjaforms CWE-79
6.1
2022-03-23 CVE-2022-0889 Cross-site Scripting vulnerability in Ninjaforms Ninja Forms File Uploads
The Ninja Forms - File Uploads Extension WordPress plugin is vulnerable to reflected cross-site scripting due to missing sanitization of the files filename parameter found in the ~/includes/ajax/controllers/uploads.php file which can be used by unauthenticated attackers to add malicious web scripts to vulnerable WordPress sites, in versions up to and including 3.3.12.
network
low complexity
ninjaforms CWE-79
6.1