Vulnerabilities > Ninjaforms > Ninja Forms > 3.4.22

DATE CVE VULNERABILITY TITLE RISK
2021-01-06 CVE-2020-36174 Cross-Site Request Forgery (CSRF) vulnerability in Ninjaforms Ninja Forms
The Ninja Forms plugin before 3.4.27.1 for WordPress allows CSRF via services integration.
network
low complexity
ninjaforms CWE-352
6.5
2021-01-06 CVE-2020-36173 Improper Encoding or Escaping of Output vulnerability in Ninjaforms Ninja Forms
The Ninja Forms plugin before 3.4.28 for WordPress lacks escaping for submissions-table fields.
network
low complexity
ninjaforms CWE-116
5.3
2020-04-29 CVE-2020-12462 Cross-Site Request Forgery (CSRF) vulnerability in Ninjaforms Ninja Forms
The ninja-forms plugin before 3.4.24.2 for WordPress allows CSRF with resultant XSS.
network
low complexity
ninjaforms CWE-352
6.1
2020-02-14 CVE-2020-8594 Cross-site Scripting vulnerability in Ninjaforms Ninja Forms 3.4.22
The Ninja Forms plugin 3.4.22 for WordPress has Multiple Stored XSS vulnerabilities via ninja_forms[recaptcha_site_key], ninja_forms[recaptcha_secret_key], ninja_forms[recaptcha_lang], or ninja_forms[date_format].
network
low complexity
ninjaforms CWE-79
5.4