SecAlerts
N

Ninja Forms

Security Risk Profile

46
/100
medium

Security Risk Score

Comprehensive risk assessment based on 35 vulnerabilities, EPSS scores, exploitation status, and remediation availability.

📅 Data spans from March 29, 2024 to present

35
Total CVEs
12
Critical+High
1
Exploited
12
Unpatched

Threat Assessment

Avg CVSS
6.4
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
12
Critical/High
Risk Level
46/100
medium
⚠️ 1 Active Exploits🆕 4Fresh (<7d)📈 6 in Last 30 Days

Severity Distribution

Critical
1
High
11
Medium
22
Low
0

Exploit Likelihood

>50% chance
0
20-50%
0
5-20%
0
<5%
4

Age Distribution

Common Weaknesses (CWE)

1
XSS
15
2
CSRF
4
3
SQL Injection
1
4
Input Validation
1
5
Path Traversal
1

Most Affected Products

1. Ninja Forms Ninja Forms17
2. NinjaForms Ninja Forms Wordpress14
3. Ninja Forms WordPress plugin3
4. Ninja Forms Ninja Forms WordPress plugin2
5. Ninja Forms Ninja Forms - Scheduled Exports1

Recent Vulnerabilities

See more →
CVE-2026-95515
CVSS 7.1EPSS 0%high

WordPress Ninja Forms plugin <= 3.15.3 - Cross Site Scripting (XSS) vulnerability

Sep 23, 2026🔧 No Patch
CVE-2026-91827
CVSS 7.5high

Ninja Forms 3.15.3 - Unauthenticated PHP Object Injection via CSV Export

Sep 22, 2026🔧 No Patch
CVE-2026-92438
CVSS 8.8high

Ninja Forms 3.15.3 - Unauthenticated Stored XSS via Paragraph Text Field in Submissions Admin

Sep 22, 2026🔧 No Patch
CVE-2026-94504
CVSS 7.2EPSS 0%high

Ninja Forms – The Contact Form Builder That Grows With You <= 3.15.3 - Stored Cross-Site Scripting

Sep 22, 2026🔧 No Patch
CVE-2026-87870
CVSS 6.4medium

Ninja Forms - Scheduled Exports <= 3.0.3 - Authenticated (Subscriber+) Stored Cross-Site Scripting via REST API Parameters

Sep 10, 2026🔧 No Patch
CVE-2026-11363
CVSS 6.6medium

Ninja Forms <= 3.14.6 - Authenticated (Administrator+) PHP Object Injection via Form Import

Sep 9, 2026🔧 No Patch
CVE-2026-15256
CVSS 4.8medium

Ninja Forms < 3.14.10 - Unauthenticated Arbitrary Shortcode Execution via Query-String Populated Field Default

Aug 6, 2026🔧 No Patch
CVE-2026-15663
CVSS 4.9medium

Ninja Forms <= 3.14.9 - Authenticated (Administrator+) SQL Injection via Import File 'settings' Key

Jul 24, 2026🔧 No Patch
CVE-2026-65052
CVSS 8.7high

Ninja Forms Calculation and Payment Total Tampering via Fail-Open get_calc_value in ListSelect and ListRadio Fields

Jul 21, 2026🔧 No Patch
CVE-2026-65051
CVSS 6.9medium

Ninja Forms Server-Side Validation Bypass via Client-Controlled Field Metadata Merge in AJAX Submission Handler

Jul 21, 2026🔧 No Patch

Monitor Ninja Forms in Real-Time

Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.

Powered bySecAlerts

Monitor Your Software Stack in Real-Time

Get instant alerts when vulnerabilities are discovered in your software stack. Stay ahead of security threats with SecAlerts.

© 2026 SecAlerts Pty Ltd. All rights reserved.

Ninja Forms Security Vulnerabilities & Risk Score | 35 CVEs | SecAlerts - SecAlerts