Cross-Site Scripting
35 records44.9%First: 2014. Latest: 2025.
Plugin security history
The Wordfence Intelligence dataset currently contains 78 vulnerability records associated with Ninja Forms – The Contact Form Builder That Grows With You, published between 2014 and 2026.
Dataset last synchronized: 2026-08-03 00:31:25 UTC
At a glance
| Year | Records | Relative volume |
|---|---|---|
| 2014 | 3 | |
| 2015 | 5 | |
| 2016 | 4 | |
| 2017 | 2 | |
| 2018 | 7 | |
| 2019 | 1 | |
| 2020 | 5 | |
| 2021 | 8 | |
| 2022 | 7 | |
| 2023 | 8 | |
| 2024 | 14 | |
| 2025 | 10 | |
| 2026 | 4 |
| Severity | Records | Share |
|---|---|---|
| Critical | 4 | 5.1% |
| High | 19 | 24.4% |
| Medium | 55 | 70.5% |
First: 2014. Latest: 2025.
First: 2015. Latest: 2025.
First: 2020. Latest: 2025.
First: 2021. Latest: 2026.
First: 2016. Latest: 2026.
First: 2021. Latest: 2026.
First: 2016. Latest: 2016.
First: 2023. Latest: 2023.
Patch status reflects the latest successfully synchronized source dataset and must be checked against the installed version.
3.14.103.14.23.14.13.13.33.12.13.11.13.10.2.23.10.13.8.253.8.233.8.203.8.183.8.163.8.123.8.113.8.73.8.53.8.13.7.23.6.343.6.263.6.253.6.223.6.133.5.8.43.4.34.23.3.21.43.2.283.1.103.0.34.23.6.113.6.103.6.83.6.43.5.8.23.5.83.4.34.13.4.343.4.27.13.4.283.4.24.23.4.233.3.21.23.3.19.13.3.183.3.143.3.93.2.153.2.143.0.32Ranges are deduplicated by source range record and shown with the associated disclosure and known patched versions.
| Affected range | Vulnerability | Published | Patched version | Severity |
|---|---|---|---|---|
[*, 3.5.8.2) | Ninja Forms <= 3.5.8.1 - Cross-Site Scripting | September 27, 2021 | 3.5.8.2 | Medium |
*-3.5.7 | Ninja Forms <= 3.5.7 - Unprotected REST-API to Email Injection | September 22, 2021 | 3.5.8 | Medium |
*-3.5.7 | Ninja Forms <= 3.5.7 - Unprotected REST-API to Sensitive Information Disclosure | September 22, 2021 | 3.5.8 | Medium |
[*, 3.4.34) | Ninja Forms Contact Form <= 3.4.33 - Cross-Site Request Forgery to OAuth Service Disconnection | February 16, 2021 | 3.4.34 | Medium |
[*, 3.4.34.1) | Ninja Forms <= 3.4.34 - Authenticated OAuth Connection Key Disclosure | February 16, 2021 | 3.4.34.1 | Medium |
[*, 3.4.34) | Ninja Forms Contact Form <= 3.4.33 - Authenticated SendWP Plugin Installation and Client Secret Key Disclosure | February 16, 2021 | 3.4.34 | High |
[*, 3.4.34) | Ninja Forms Contact Form <= 3.4.33 - Administrator Open Redirect | February 16, 2021 | 3.4.34 | Medium |
*-3.4.27 | Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress <= 3.4.27 - Cross-Site Request Forgery to Plugin Installation | September 22, 2020 | 3.4.27.1 | High |
*-3.4.27 | Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress <= 3.4.27 - Validation Bypass via Email Field | September 22, 2020 | 3.4.27.1 | Medium |
*-3.4.27.1 | Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress <= 3.4.27.1 - Stored Cross-Site Scripting | September 20, 2020 | 3.4.28 | Medium |
[*, 3.4.24.2) | Ninja Forms Contact Form <= 3.4.24.1 - Cross-Site Request Forgery leading to Stored Cross-Site Scripting | April 28, 2020 | 3.4.24.2 | Medium |
[*, 3.4.23) | Ninja Forms Contact Form <= 3.4.22 - Stored Cross-Site Scripting | February 3, 2020 | 3.4.23 | Medium |
*-3.3.21.1 | Ninja Forms Contact Form <= 3.3.21.1 - SQL Injection | January 7, 2019 | 3.3.21.2 | Critical |
*-3.3.19 | Ninja Forms Contact Form <= 3.3.19 - Authenticated Open Redirect | December 1, 2018 | 3.3.19.1 | Medium |
[*, 3.3.18) | Ninja Forms Contact Form <= 3.3.17 - Cross-Site Scripting via begin_date, end_date, or form_id Parameter | November 15, 2018 | 3.3.18 | Medium |
[*, 3.3.14) | Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress <= 3.3.13 - Cross-Site Scripting | August 27, 2018 | 3.3.14 | High |
*-3.3.13 | Ninja Forms Contact Form <= 3.3.13 - CSV Injection | August 19, 2018 | 3.3.14 | High |
*-3.3.8 | Ninja Forms <= 3.3.8 - Insufficient Restrictions during Export Personal Data requests | July 6, 2018 | 3.3.9 | Critical |
[*, 3.2.15) | Ninja Forms Contact Form <= 3.2.14 - Parameter Tampering | February 26, 2018 | 3.2.15 | High |
[*, 3.2.14) | Ninja Forms Contact Form <= 3.2.13 - Cross-Site Scripting | February 20, 2018 | 3.2.14 | Medium |
*-3.0.31 | Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress <= 3.0.31 - Arbitrary Wordpress Shortcode Injection | April 17, 2017 | 3.0.32 | Medium |
[*, 3.0.31) | Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress <= 3.0.30 - HTML Injection | March 7, 2017 | 3.0.31 | Medium |
[*, 2.9.55.2) | Ninja Forms Contact Form <= 2.9.55.1 - Authenticated SQL Injection | August 16, 2016 | 2.9.55.2 | High |
[*, 2.9.52) | Ninja Forms Contact Form <= 2.9.51 - Multiple Reflected Cross-Site Scripting | July 19, 2016 | 2.9.52 | Medium |
2.9.36-2.9.42 | Ninja Forms Contact Form 2.9.36 - 2.9.42 - PHP Object Injection | May 13, 2016 | 2.9.42.1 | High |
Selected source records
Published: July 23, 2026
Published: June 30, 2026
Published: March 27, 2026
Published: February 9, 2026
Published: December 16, 2025
Published: December 12, 2025
Published: September 26, 2025
Published: September 26, 2025
Published: May 5, 2016
Published: January 7, 2019
Published: June 15, 2022
Published: July 6, 2018
Published: February 16, 2021
Published: June 7, 2022
Published: August 16, 2016
Published: September 22, 2020
Running an affected version does not prove that a website was compromised. Suspicious redirects, unknown administrators, injected content, unexpected files or recurring malware may require a manual investigation.
Vulnerability data: Wordfence Intelligence. Analysis and practical guidance: 3Zero Digital.
This page aggregates active Production Feed records. Counts are not software-quality rankings, and an affected version does not prove exploitation or infection. Read the full methodology.