First published: Thu Apr 11 2024(Updated: )
Ninja Forms prior to 3.8.1 contains a cross-site scripting vulnerability in submit processing. If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user who is accessing to the website using the product.
Credit: vultures@jpcert.or.jp
Affected Software | Affected Version | How to fix |
---|---|---|
Ninja Forms | <3.8.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-26019 is classified as a medium severity vulnerability due to its potential for cross-site scripting attacks.
To fix CVE-2024-26019, it is recommended to update Ninja Forms to version 3.8.1 or later.
CVE-2024-26019 affects users running Ninja Forms versions prior to 3.8.1.
CVE-2024-26019 is a cross-site scripting (XSS) vulnerability that can allow attackers to execute arbitrary scripts.
If exploited, CVE-2024-26019 can lead to malicious scripts running in the web browsers of users accessing the affected website.