Vulnerabilities (CVE)

Filtered by vendor Ninjaforms Subscribe
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-0888 1 Ninjaforms 1 Ninja Forms File Uploads 2024-01-11 7.5 HIGH 9.8 CRITICAL
The Ninja Forms - File Uploads Extension WordPress plugin is vulnerable to arbitrary file uploads due to insufficient input file type validation found in the ~/includes/ajax/controllers/uploads.php file which can be bypassed making it possible for unauthenticated attackers to upload malicious files that can be used to obtain remote code execution, in versions up to and including 3.3.0
CVE-2018-20981 1 Ninjaforms 1 Ninja Forms 2019-08-26 6.4 MEDIUM 9.1 CRITICAL
The ninja-forms plugin before 3.3.9 for WordPress has insufficient restrictions on submission-data retrieval during Export Personal Data requests.
CVE-2019-15025 1 Ninjaforms 1 Ninjaforms 2019-08-20 7.5 HIGH 9.8 CRITICAL
The ninja-forms plugin before 3.3.21.2 for WordPress has SQL injection in the search filter on the submissions page.
CVE-2016-1209 1 Ninjaforms 1 Ninja Forms 2016-06-23 7.5 HIGH 9.8 CRITICAL
The Ninja Forms plugin before 2.9.42.1 for WordPress allows remote attackers to conduct PHP object injection attacks via crafted serialized values in a POST request.