SecAlerts
ninja forms logo

ninja forms

Security Risk Profile

40
/100
medium

Security Risk Score

Comprehensive risk assessment based on 29 vulnerabilities, EPSS scores, exploitation status, and remediation availability.

📅 Data spans from March 29, 2024 to present

29
Total CVEs
8
Critical+High
1
Exploited
8
Unpatched

Threat Assessment

Avg CVSS
6.2
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
8
Critical/High
Risk Level
40/100
medium
⚠️ 1 Active Exploits🆕 1Fresh (<7d)📈 8 in Last 30 Days

Severity Distribution

Critical
1
High
7
Medium
20
Low
0

Exploit Likelihood

>50% chance
0
20-50%
0
5-20%
0
<5%
2

Age Distribution

Common Weaknesses (CWE)

1
XSS
11
2
CSRF
4
3
SQL Injection
1
4
Input Validation
1
5
Path Traversal
1

Most Affected Products

1. NinjaForms Ninja Forms Wordpress14
2. Ninja Forms Ninja Forms13
3. Ninja Forms WordPress plugin3
4. Ninja Forms Ninja Forms WordPress plugin2
5. Ninja Forms Ninja Forms – The Contact Form Builder That Grows With You (WordPress plugin)1

Recent Vulnerabilities

See more →
CVE-2026-15256
CVSS 4.8medium

Ninja Forms < 3.14.10 - Unauthenticated Arbitrary Shortcode Execution via Query-String Populated Field Default

8/6/2026🔧 No Patch
CVE-2026-15663
CVSS 4.9medium

Ninja Forms <= 3.14.9 - Authenticated (Administrator+) SQL Injection via Import File 'settings' Key

7/24/2026🔧 No Patch
CVE-2026-65052
CVSS 8.7high

Ninja Forms Calculation and Payment Total Tampering via Fail-Open get_calc_value in ListSelect and ListRadio Fields

7/21/2026🔧 No Patch
CVE-2026-65051
CVSS 6.9medium

Ninja Forms Server-Side Validation Bypass via Client-Controlled Field Metadata Merge in AJAX Submission Handler

7/21/2026🔧 No Patch
CVE-2026-65050
CVSS 7.1high

Ninja Forms Missing Authorization in submissions-table Gutenberg Block Discloses Form Submissions to Unauthenticated Visitors

7/21/2026🔧 No Patch
CVE-2026-65049
CVSS 8.4high

Ninja Forms Cross-Site Network-Wide Data Deletion on WordPress Multisite via nf_delete_all_data AJAX Action

7/21/2026🔧 No Patch
CVE-2026-15161
CVSS 6.4medium

Ninja Forms - Excel Export <= 3.3.6 - Authenticated (Subscriber+) Stored Cross-Site Scripting via 'filter' Parameter

7/17/2026🔧 No Patch
CVE-2026-15159
CVSS 4.3medium

Ninja Forms - Excel Export <= 3.3.6 - Insecure Direct Object Reference to Authenticated (Subscriber+) Sensitive Data Disclosure via 'spreadsheet_export_form_id' Parameter

7/17/2026🔧 No Patch
CVE-2026-13369
CVSS 7.5high

Ninja Forms - File Uploads <= 3.3.29 - Unauthenticated Arbitrary File Read via File Upload Field 'files[].data.file_path' Parameter

7/2/2026🔧 No Patch
CVE-2026-1239
CVSS 7.5high

Ninja Forms <= 3.14.1 - Missing Authorization to Unauthenticated Sensitive Information Disclosure via token/refresh REST Endpoint

7/1/2026🔧 No Patch

Monitor ninja forms in Real-Time

Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.

Powered bySecAlerts

Monitor Your Software Stack in Real-Time

Get instant alerts when vulnerabilities are discovered in your software stack. Stay ahead of security threats with SecAlerts.

© 2026 SecAlerts Pty Ltd. All rights reserved.

ninja forms Security Vulnerabilities & Risk Score | 29 CVEs | SecAlerts - SecAlerts