Cross-Site Scripting
35 records44.9%First: 2014. Latest: 2025.
Plugin security history
The Wordfence Intelligence dataset currently contains 78 vulnerability records associated with Ninja Forms – The Contact Form Builder That Grows With You, published between 2014 and 2026.
Dataset last synchronized: 2026-08-02 09:41:47 UTC
At a glance
| Year | Records | Relative volume |
|---|---|---|
| 2014 | 3 | |
| 2015 | 5 | |
| 2016 | 4 | |
| 2017 | 2 | |
| 2018 | 7 | |
| 2019 | 1 | |
| 2020 | 5 | |
| 2021 | 8 | |
| 2022 | 7 | |
| 2023 | 8 | |
| 2024 | 14 | |
| 2025 | 10 | |
| 2026 | 4 |
| Severity | Records | Share |
|---|---|---|
| Critical | 4 | 5.1% |
| High | 19 | 24.4% |
| Medium | 55 | 70.5% |
First: 2014. Latest: 2025.
First: 2015. Latest: 2025.
First: 2020. Latest: 2025.
First: 2021. Latest: 2026.
First: 2016. Latest: 2026.
First: 2021. Latest: 2026.
First: 2016. Latest: 2016.
First: 2023. Latest: 2023.
Patch status reflects the latest successfully synchronized source dataset and must be checked against the installed version.
3.14.103.14.23.14.13.13.33.12.13.11.13.10.2.23.10.13.8.253.8.233.8.203.8.183.8.163.8.123.8.113.8.73.8.53.8.13.7.23.6.343.6.263.6.253.6.223.6.133.5.8.43.4.34.23.3.21.43.2.283.1.103.0.34.23.6.113.6.103.6.83.6.43.5.8.23.5.83.4.34.13.4.343.4.27.13.4.283.4.24.23.4.233.3.21.23.3.19.13.3.183.3.143.3.93.2.153.2.143.0.32Ranges are deduplicated by source range record and shown with the associated disclosure and known patched versions.
| Affected range | Vulnerability | Published | Patched version | Severity |
|---|---|---|---|---|
*-3.14.9 | Ninja Forms <= 3.14.9 - Authenticated (Administrator+) SQL Injection via Import File 'settings' Key | July 23, 2026 | 3.14.10 | Medium |
*-3.14.1 | Ninja Forms <= 3.14.1 - Missing Authorization to Unauthenticated Sensitive Information Disclosure via token/refresh REST Endpoint | June 30, 2026 | 3.14.2 | High |
*-3.14.1 | Ninja Forms <= 3.14.1 - Authenticated (Contributor+) Sensitive Information Disclosure via Block Editor Token | March 27, 2026 | 3.14.2 | Medium |
*-3.14.0 | Ninja Forms <= 3.14.0 - Unauthenticated Information Disclosure in nf_ajax_submit AJAX Action | February 9, 2026 | 3.14.1 | High |
*-3.13.2 | Ninja Forms – The Contact Form Builder That Grows With You <= 3.13.2 - Insecure Direct Object Reference to Unauthenticated Sensitive Information Exposure via Unscoped Bearer Token | December 16, 2025 | 3.13.3 | High |
*-3.13.2 | Ninja Forms <= 3.13.2 - Missing Authorization to Unauthenticated Submission Disclosure | December 12, 2025 | 3.13.3 | High |
*-3.12.0 | Ninja Forms – The Contact Form Builder That Grows With You <= 3.12.0 - Cross-Site Request Forgery to Plugin Settings Update | September 26, 2025 | 3.12.1 | Medium |
*-3.12.0 | Ninja Forms – The Contact Form Builder That Grows With You <= 3.12.0 - Cross-Site Request Forgery to Limited File Deletion | September 26, 2025 | 3.12.1 | Medium |
*-3.11.0 | Ninja Forms <= 3.11.0 - Unauthenticated PHP Object Injection | August 28, 2025 | 3.11.1 | High |
*-3.10.2.1 | Ninja Forms <= 3.10.2.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via CSTI | June 26, 2025 | 3.10.2.2 | Medium |
*-3.10.0 | Ninja Forms – The Contact Form Builder That Grows With You <= 3.10.0 - Authenticated (Admin+) Stored Cross-Site Scripting | April 28, 2025 | 3.10.1 | Medium |
*-3.10.0 | Ninja Forms – The Contact Form Builder That Grows With You <= 3.10.0 - Authenticated (Admin+) Stored Cross-Site Scripting | April 28, 2025 | 3.10.1 | Medium |
*-3.10.0 | Ninja Forms – The Contact Form Builder That Grows With You <= 3.10.0 - Authenticated (Admin+) Stored Cross-Site Scripting | April 28, 2025 | 3.10.1 | Medium |
*-3.8.24 | Ninja Forms – The Contact Form Builder That Grows With You <= 3.8.24 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode | January 29, 2025 | 3.8.25 | Medium |
*-3.8.22 | Ninja Forms – The Contact Form Builder That Grows With You <= 3.8.22 - Authenticated (Subscriber+) Arbitrary Shortcode Execution | December 28, 2024 | 3.8.23 | Medium |
*-3.8.19 | Ninja Forms – The Contact Form Builder That Grows With You <= 3.8.19 - Unauthenticated Stored Cross-Site Scripting via Form Calculations | December 11, 2024 | 3.8.20 | High |
*-3.8.17 | Ninja Forms – The Contact Form Builder That Grows With You <= 3.8.17 - Authenticated (Admin+) Stored Cross-Site Scripting | October 28, 2024 | 3.8.18 | Medium |
*-3.8.17 | Ninja Forms – The Contact Form Builder That Grows With You <= 3.8.17 - Authenticated (Admin+) Stored Cross-Site Scripting | October 28, 2024 | 3.8.18 | Medium |
*-3.8.15 | Ninja Forms Contact Form <= 3.8.15 - Reflected Self-Based Cross-Site Scripting via Referer | September 24, 2024 | 3.8.16 | Medium |
*-3.8.11 | Ninja Forms <= 3.8.11 - Authenticated (Administrator+) Stored Cross-Site Scripting | August 28, 2024 | 3.8.12 | Medium |
3.8.6-3.8.10 | Ninja Forms – The Contact Form Builder That Grows With You <= 3.8.10 - Reflected Cross-Site Scripting | August 12, 2024 | 3.8.11 | Medium |
*-3.8.6 | Ninja Forms <= 3.8.6 - Cross-Site Request Forgery | July 24, 2024 | 3.8.7 | Medium |
*-3.8.4 | Ninja Forms <= 3.8.4 - Authenticated (Subscriber+) Arbitrary Shortcode Execution | July 4, 2024 | 3.8.5 | Medium |
*-3.8.0 | Ninja Forms – The Contact Form Builder That Grows With You <= 3.8.0 - Authenticated (Admin+) Stored Cross-Site Scripting | April 8, 2024 | 3.8.1 | Medium |
*-3.8.0 | Ninja Forms – The Contact Form Builder That Grows With You <= 3.8.0 - Authenticated (Admin+) Stored Cross-Site Scripting | April 8, 2024 | 3.8.1 | Medium |
Selected source records
Published: July 23, 2026
Published: June 30, 2026
Published: March 27, 2026
Published: February 9, 2026
Published: December 16, 2025
Published: December 12, 2025
Published: September 26, 2025
Published: September 26, 2025
Published: May 5, 2016
Published: January 7, 2019
Published: June 15, 2022
Published: July 6, 2018
Published: February 16, 2021
Published: June 7, 2022
Published: August 16, 2016
Published: September 22, 2020
Running an affected version does not prove that a website was compromised. Suspicious redirects, unknown administrators, injected content, unexpected files or recurring malware may require a manual investigation.
Vulnerability data: Wordfence Intelligence. Analysis and practical guidance: 3Zero Digital.
This page aggregates active Production Feed records. Counts are not software-quality rankings, and an affected version does not prove exploitation or infection. Read the full methodology.