Vulnerabilities > Ninjaforms > Critical

DATE CVE VULNERABILITY TITLE RISK
2024-07-09 CVE-2024-37934 Unspecified vulnerability in Ninjaforms Ninja Forms
Improper Control of Generation of Code ('Code Injection') vulnerability in Saturday Drive Ninja Forms allows Code Injection.This issue affects Ninja Forms: from n/a through 3.8.4.
network
low complexity
ninjaforms
critical
9.8
2024-02-02 CVE-2024-0685 SQL Injection vulnerability in Ninjaforms Ninja Forms
The Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to Second Order SQL Injection via the email address value submitted through forms in all versions up to, and including, 3.7.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.
network
low complexity
ninjaforms CWE-89
critical
9.8
2022-03-23 CVE-2022-0888 Unrestricted Upload of File with Dangerous Type vulnerability in Ninjaforms Ninja Forms File Uploads
The Ninja Forms - File Uploads Extension WordPress plugin is vulnerable to arbitrary file uploads due to insufficient input file type validation found in the ~/includes/ajax/controllers/uploads.php file which can be bypassed making it possible for unauthenticated attackers to upload malicious files that can be used to obtain remote code execution, in versions up to and including 3.3.0
network
low complexity
ninjaforms CWE-434
critical
9.8
2019-08-22 CVE-2018-20981 Improper Input Validation vulnerability in Ninjaforms Ninja Forms
The ninja-forms plugin before 3.3.9 for WordPress has insufficient restrictions on submission-data retrieval during Export Personal Data requests.
network
low complexity
ninjaforms CWE-20
critical
9.1
2019-08-14 CVE-2019-15025 SQL Injection vulnerability in Ninjaforms
The ninja-forms plugin before 3.3.21.2 for WordPress has SQL injection in the search filter on the submissions page.
network
low complexity
ninjaforms CWE-89
critical
9.8
2016-05-14 CVE-2016-1209 Improper Input Validation vulnerability in Ninjaforms Ninja Forms
The Ninja Forms plugin before 2.9.42.1 for WordPress allows remote attackers to conduct PHP object injection attacks via crafted serialized values in a POST request.
network
low complexity
ninjaforms CWE-20
critical
9.8