Ninja Forms – The Contact Form Builder That Grows With You

Information

Software Type Plugin
Software Slug ninja-forms (view on wordpress.org)
Software Status Active
Software Author kstover
Software Website ninjaforms.com
Software Downloads 61,469,186
Software Active Installs 600,000
Software Record Last Updated July 22, 2026

Showing 1-20 of 77 Vulnerabilities

Title Status CVE ID CVSS Researchers Date
Ninja Forms <= 3.14.1 - Missing Authorization to Unauthenticated Sensitive Information Disclosure via token/refresh REST Endpoint Patched CVE-2026-1239 7.5 suyoung kim(AhnLab) June 30, 2026
Ninja Forms <= 3.14.1 - Authenticated (Contributor+) Sensitive Information Disclosure via Block Editor Token Patched CVE-2026-1307 6.5 Lucas Montes (NiRoX) March 27, 2026
Ninja Forms <= 3.14.0 - Unauthenticated Information Disclosure in nf_ajax_submit AJAX Action Patched CVE-2026-2268 7.5 johska February 9, 2026
Ninja Forms – The Contact Form Builder That Grows With You <= 3.13.2 - Insecure Direct Object Reference to Unauthenticated Sensitive Information Exposure via Unscoped Bearer Token Patched CVE-2025-11924 7.5 Lucas Montes (NiRoX), Marcin Dudek (dudekmar) December 16, 2025
Ninja Forms <= 3.13.2 - Missing Authorization to Unauthenticated Submission Disclosure Patched CVE-2025-14072 7.5 Marco Lunardi December 12, 2025
Ninja Forms – The Contact Form Builder That Grows With You <= 3.12.0 - Cross-Site Request Forgery to Plugin Settings Update Patched CVE-2025-10499 4.3 Nguyen Ngoc Quang Bach (maysbachs) September 26, 2025
Ninja Forms – The Contact Form Builder That Grows With You <= 3.12.0 - Cross-Site Request Forgery to Limited File Deletion Patched CVE-2025-10498 4.3 Nguyen Ngoc Quang Bach (maysbachs) September 26, 2025
Ninja Forms <= 3.11.0 - Unauthenticated PHP Object Injection Patched CVE-2025-9083 8.1 wesley (wcraft) August 28, 2025
Ninja Forms <= 3.10.2.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via CSTI Patched CVE-2025-5398 6.4 Asaf Mozes June 26, 2025
Ninja Forms – The Contact Form Builder That Grows With You <= 3.10.0 - Authenticated (Admin+) Stored Cross-Site Scripting Patched CVE-2025-2561 4.4 Bob Matyas April 28, 2025
Ninja Forms – The Contact Form Builder That Grows With You <= 3.10.0 - Authenticated (Admin+) Stored Cross-Site Scripting Patched CVE-2025-2524 4.4 Dmitrii Ignatyev April 28, 2025
Ninja Forms – The Contact Form Builder That Grows With You <= 3.10.0 - Authenticated (Admin+) Stored Cross-Site Scripting Patched CVE-2025-2560 4.4 Dmitrii Ignatyev April 28, 2025
Ninja Forms – The Contact Form Builder That Grows With You <= 3.8.24 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Patched CVE-2024-13470 6.4 Peter Thaleikis January 29, 2025
Ninja Forms – The Contact Form Builder That Grows With You <= 3.8.22 - Authenticated (Subscriber+) Arbitrary Shortcode Execution Patched CVE-2024-12238 6.3 mikemyers December 28, 2024
Ninja Forms – The Contact Form Builder That Grows With You <= 3.8.19 - Unauthenticated Stored Cross-Site Scripting via Form Calculations Patched CVE-2024-11052 7.2 mikemyers December 11, 2024
Ninja Forms – The Contact Form Builder That Grows With You <= 3.8.17 - Authenticated (Admin+) Stored Cross-Site Scripting Patched CVE-2024-50515 4.4 Hwang Se-yeon October 28, 2024
Ninja Forms – The Contact Form Builder That Grows With You <= 3.8.17 - Authenticated (Admin+) Stored Cross-Site Scripting Patched CVE-2024-50514 4.4 Hwang Se-yeon October 28, 2024
Ninja Forms Contact Form <= 3.8.15 - Reflected Self-Based Cross-Site Scripting via Referer Patched CVE-2024-3866 4.7 wesley (wcraft) September 24, 2024
Ninja Forms <= 3.8.11 - Authenticated (Administrator+) Stored Cross-Site Scripting Patched CVE-2024-43999 4.4 Joel Indra August 28, 2024
Ninja Forms – The Contact Form Builder That Grows With You <= 3.8.10 - Reflected Cross-Site Scripting Patched CVE-2024-7354 6.1 Erwan LR August 12, 2024

Did you know Wordfence Intelligence provides free personal and commercial API access to our comprehensive WordPress vulnerability database, along with a free webhook integration to stay on top of the latest vulnerabilities added and updated in the database? Get started today!

Learn more

Want to get notified of the latest vulnerabilities that may affect your WordPress site?
Install Wordfence on your site today to get notified immediately if your site is affected by a vulnerability that has been added to our database.

Get Wordfence

The Wordfence Intelligence WordPress vulnerability database is completely free to access and query via API. Please review the documentation on how to access and consume the vulnerability data via API.

Documentation