Cross-Site Scripting
35 records44.9%First: 2014. Latest: 2025.
Plugin security history
The Wordfence Intelligence dataset currently contains 78 vulnerability records associated with Ninja Forms – The Contact Form Builder That Grows With You, published between 2014 and 2026.
Dataset last synchronized: 2026-08-02 09:41:47 UTC
At a glance
| Year | Records | Relative volume |
|---|---|---|
| 2014 | 3 | |
| 2015 | 5 | |
| 2016 | 4 | |
| 2017 | 2 | |
| 2018 | 7 | |
| 2019 | 1 | |
| 2020 | 5 | |
| 2021 | 8 | |
| 2022 | 7 | |
| 2023 | 8 | |
| 2024 | 14 | |
| 2025 | 10 | |
| 2026 | 4 |
| Severity | Records | Share |
|---|---|---|
| Critical | 4 | 5.1% |
| High | 19 | 24.4% |
| Medium | 55 | 70.5% |
First: 2014. Latest: 2025.
First: 2015. Latest: 2025.
First: 2020. Latest: 2025.
First: 2021. Latest: 2026.
First: 2016. Latest: 2026.
First: 2021. Latest: 2026.
First: 2016. Latest: 2016.
First: 2023. Latest: 2023.
Patch status reflects the latest successfully synchronized source dataset and must be checked against the installed version.
3.14.103.14.23.14.13.13.33.12.13.11.13.10.2.23.10.13.8.253.8.233.8.203.8.183.8.163.8.123.8.113.8.73.8.53.8.13.7.23.6.343.6.263.6.253.6.223.6.133.5.8.43.4.34.23.3.21.43.2.283.1.103.0.34.23.6.113.6.103.6.83.6.43.5.8.23.5.83.4.34.13.4.343.4.27.13.4.283.4.24.23.4.233.3.21.23.3.19.13.3.183.3.143.3.93.2.153.2.143.0.32Ranges are deduplicated by source range record and shown with the associated disclosure and known patched versions.
| Affected range | Vulnerability | Published | Patched version | Severity |
|---|---|---|---|---|
*-3.8.0 | Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress <= 3.8.0 - Authenticated (Author+) Stored Cross-Site Scripting | March 28, 2024 | 3.8.1 | Medium |
*-3.8.0 | Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress <= 3.8.0 - Cross-Site Request Forgery to Publicly Accessible Form Submission Export | March 28, 2024 | 3.8.1 | Medium |
*-3.7.1 | Ninja Forms Contact Form <= 3.7.1 - Unauthenticated Second Order SQL Injection | February 1, 2024 | 3.7.2 | Medium |
*-3.6.33 | Ninja Forms Contact Form <= 3.6.33 - Authenticated (Admin+) Stored Cross-Site Scripting | October 16, 2023 | 3.6.34 | Medium |
*-3.6.25 | Ninja Forms <= 3.6.25 - Authenticated (Administrator+) Stored HTML Injection | August 7, 2023 | 3.6.26 | Medium |
*-3.6.25 | Ninja Forms <= 3.6.25 - Missing Authorization to Form Submission Export | July 25, 2023 | 3.6.26 | Medium |
*-3.6.25 | Ninja Forms <= 3.6.25 - Missing Authorization to Contributor+ Form Submission Export | July 25, 2023 | 3.6.26 | Medium |
*-3.6.25 | Ninja Forms <= 3.6.25 - Reflected Cross-Site Scripting via 'data' | July 25, 2023 | 3.6.26 | Medium |
*-3.6.25 | Ninja Forms <= 3.6.25 - Denial of Service via Large Form Submissions | July 7, 2023 | 3.6.26 | Medium |
*-3.6.24 | Ninja Forms <= 3.6.24 - Authenticated (Admin+) Arbitrary File Deletion | June 22, 2023 | 3.6.25 | Medium |
*-3.6.21 | Ninja Forms Contact Form <= 3.6.21 - Reflected Cross-Site Scripting via 'title' | April 24, 2023 | 3.6.22 | Medium |
*-3.6.12 | Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress <= 3.6.12 - Authenticated (Administrator+) PHP Objection Injection | September 5, 2022 | 3.6.13 | High |
3.6-3.6.10 | Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress <= 3.6.10 - Code Injection | June 15, 2022 | 3.0.34.2, 3.1.10, 3.2.28, 3.3.21.4, 3.4.34.2, 3.5.8.4, 3.6.11 | Critical |
3.5-3.5.8.3 | Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress <= 3.6.10 - Code Injection | June 15, 2022 | 3.0.34.2, 3.1.10, 3.2.28, 3.3.21.4, 3.4.34.2, 3.5.8.4, 3.6.11 | Critical |
3.4-3.4.34.1 | Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress <= 3.6.10 - Code Injection | June 15, 2022 | 3.0.34.2, 3.1.10, 3.2.28, 3.3.21.4, 3.4.34.2, 3.5.8.4, 3.6.11 | Critical |
3.3-3.3.21.3 | Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress <= 3.6.10 - Code Injection | June 15, 2022 | 3.0.34.2, 3.1.10, 3.2.28, 3.3.21.4, 3.4.34.2, 3.5.8.4, 3.6.11 | Critical |
3.2-3.2.27 | Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress <= 3.6.10 - Code Injection | June 15, 2022 | 3.0.34.2, 3.1.10, 3.2.28, 3.3.21.4, 3.4.34.2, 3.5.8.4, 3.6.11 | Critical |
3.1-3.1.9 | Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress <= 3.6.10 - Code Injection | June 15, 2022 | 3.0.34.2, 3.1.10, 3.2.28, 3.3.21.4, 3.4.34.2, 3.5.8.4, 3.6.11 | Critical |
*-3.0.34.1 | Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress <= 3.6.10 - Code Injection | June 15, 2022 | 3.0.34.2, 3.1.10, 3.2.28, 3.3.21.4, 3.4.34.2, 3.5.8.4, 3.6.11 | Critical |
*-3.6.9 | Ninja Forms Contact Form <= 3.6.9 - Cross-Site Scripting via field label | June 13, 2022 | 3.6.10 | Medium |
*-3.6.10 | Ninja Ninja Forms Contact Form <= 3.6.10 - Authenticated (Admin+) Stored Cross-Site Scripting via import | June 10, 2022 | 3.6.11 | Medium |
*-3.6.9 | Ninja Forms Contact Form <= 3.6.9 - Authenticated (Admin+) Cross-Site Scripting via label | June 7, 2022 | 3.6.10 | Medium |
*-3.6.9 | Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress <= 3.6.9 - Cross-Site Request Forgery to Field Import and PHP Object Injection | June 7, 2022 | 3.6.10 | High |
*-3.6.7 | Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress <= 3.6.7 - Email Address Disclosure | March 22, 2022 | 3.6.8 | Medium |
[*, 3.6.4) | Ninja Forms Contact Form <= 3.6.3 - Authenticated SQL Injection | October 26, 2021 | 3.6.4 | High |
Selected source records
Published: July 23, 2026
Published: June 30, 2026
Published: March 27, 2026
Published: February 9, 2026
Published: December 16, 2025
Published: December 12, 2025
Published: September 26, 2025
Published: September 26, 2025
Published: May 5, 2016
Published: January 7, 2019
Published: June 15, 2022
Published: July 6, 2018
Published: February 16, 2021
Published: June 7, 2022
Published: August 16, 2016
Published: September 22, 2020
Running an affected version does not prove that a website was compromised. Suspicious redirects, unknown administrators, injected content, unexpected files or recurring malware may require a manual investigation.
Vulnerability data: Wordfence Intelligence. Analysis and practical guidance: 3Zero Digital.
This page aggregates active Production Feed records. Counts are not software-quality rankings, and an affected version does not prove exploitation or infection. Read the full methodology.