Cross-Site Scripting
35 records44.9%First: 2014. Latest: 2025.
Plugin security history
The Wordfence Intelligence dataset currently contains 78 vulnerability records associated with Ninja Forms – The Contact Form Builder That Grows With You, published between 2014 and 2026.
Dataset last synchronized: 2026-08-02 09:41:47 UTC
At a glance
| Year | Records | Relative volume |
|---|---|---|
| 2014 | 3 | |
| 2015 | 5 | |
| 2016 | 4 | |
| 2017 | 2 | |
| 2018 | 7 | |
| 2019 | 1 | |
| 2020 | 5 | |
| 2021 | 8 | |
| 2022 | 7 | |
| 2023 | 8 | |
| 2024 | 14 | |
| 2025 | 10 | |
| 2026 | 4 |
| Severity | Records | Share |
|---|---|---|
| Critical | 4 | 5.1% |
| High | 19 | 24.4% |
| Medium | 55 | 70.5% |
First: 2014. Latest: 2025.
First: 2015. Latest: 2025.
First: 2020. Latest: 2025.
First: 2021. Latest: 2026.
First: 2016. Latest: 2026.
First: 2021. Latest: 2026.
First: 2016. Latest: 2016.
First: 2023. Latest: 2023.
Patch status reflects the latest successfully synchronized source dataset and must be checked against the installed version.
3.14.103.14.23.14.13.13.33.12.13.11.13.10.2.23.10.13.8.253.8.233.8.203.8.183.8.163.8.123.8.113.8.73.8.53.8.13.7.23.6.343.6.263.6.253.6.223.6.133.5.8.43.4.34.23.3.21.43.2.283.1.103.0.34.23.6.113.6.103.6.83.6.43.5.8.23.5.83.4.34.13.4.343.4.27.13.4.283.4.24.23.4.233.3.21.23.3.19.13.3.183.3.143.3.93.2.153.2.143.0.32Ranges are deduplicated by source range record and shown with the associated disclosure and known patched versions.
| Affected range | Vulnerability | Published | Patched version | Severity |
|---|---|---|---|---|
2.9.36-2.9.42 | Ninja Forms Contact Form 2.9.36 - 2.9.42 - Unauthenticated Arbitrary File Upload | May 5, 2016 | 2.9.42.1 | Critical |
*-2.9.28 | Ninja Forms Contact Form <= 2.9.28 - Stored Cross-Site Scripting | December 8, 2015 | 2.9.29 | High |
*-2.9.27 | Ninja Forms Contact Form <= 2.9.27 - CSV Injection | September 30, 2015 | 2.9.28 | High |
*-2.9.21 | Ninja Forms Contact Form <= 2.9.21 - Reflected Cross-Site Scripting | August 4, 2015 | 2.9.22 | Medium |
*-2.9.18 | Ninja Forms Contact Form <= 2.9.18 - Cross-Site Scripting | June 5, 2015 | 2.9.19 | Medium |
[*, 2.9.11) | Ninja Forms <= 2.9.10 - Reflected Cross-Site Scripting | April 20, 2015 | 2.9.11 | Medium |
[*, 2.8.10) | Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress <= 2.8.8 - Reflected Cross-Site Scripting | December 2, 2014 | 2.8.10 | Medium |
[*, 2.8.9) | Ninja Forms Contact Form <= 2.8.8 - Stored Cross-Site Scripting | November 20, 2014 | 2.8.9 | High |
*-2.8.6 | Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress <= 2.8.6 - Reflected Cross-Site Scripting | November 6, 2014 | 2.8.7 | Medium |
Selected source records
Published: July 23, 2026
Published: June 30, 2026
Published: March 27, 2026
Published: February 9, 2026
Published: December 16, 2025
Published: December 12, 2025
Published: September 26, 2025
Published: September 26, 2025
Published: May 5, 2016
Published: January 7, 2019
Published: June 15, 2022
Published: July 6, 2018
Published: February 16, 2021
Published: June 7, 2022
Published: August 16, 2016
Published: September 22, 2020
Running an affected version does not prove that a website was compromised. Suspicious redirects, unknown administrators, injected content, unexpected files or recurring malware may require a manual investigation.
Vulnerability data: Wordfence Intelligence. Analysis and practical guidance: 3Zero Digital.
This page aggregates active Production Feed records. Counts are not software-quality rankings, and an affected version does not prove exploitation or infection. Read the full methodology.