Vulnerabilities > Ninjaforms > Ninja Forms > Critical

DATE CVE VULNERABILITY TITLE RISK
2024-07-09 CVE-2024-37934 Code Injection vulnerability in Ninjaforms Ninja Forms
Improper Control of Generation of Code ('Code Injection') vulnerability in Saturday Drive Ninja Forms allows Code Injection.This issue affects Ninja Forms: from n/a through 3.8.4.
network
low complexity
ninjaforms CWE-94
critical
9.8
2024-02-02 CVE-2024-0685 SQL Injection vulnerability in Ninjaforms Ninja Forms
The Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to Second Order SQL Injection via the email address value submitted through forms in all versions up to, and including, 3.7.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.
network
low complexity
ninjaforms CWE-89
critical
9.8