Skip to content
Founder-led WordPress incident response and care Request an assessment
3zerodigital Request a Website Assessment

Plugin security history

Ninja Forms – The Contact Form Builder That Grows With You Vulnerability History & Security Timeline

The Wordfence Intelligence dataset currently contains 78 vulnerability records associated with Ninja Forms – The Contact Form Builder That Grows With You, published between 2014 and 2026.

Dataset last synchronized: 2026-08-02 09:41:47 UTC

At a glance

Security Snapshot

78Total records
4Critical
19High
55Medium
0Low
0Informational
78Patched records
0Currently marked unpatched
2014-11-06First disclosure
2026-07-23Latest disclosure
66 of 78CVE coverage

Year-by-Year Timeline

YearRecordsRelative volume
201433 records
201555 records
201644 records
201722 records
201877 records
201911 records
202055 records
202188 records
202277 records
202388 records
20241414 records
20251010 records
202644 records

Severity Breakdown

SeverityRecordsShare
Critical45.1%
High1924.4%
Medium5570.5%

Vulnerability-Type Breakdown

Cross-Site Scripting

35 records44.9%

First: 2014. Latest: 2025.

Other

15 records19.2%

First: 2015. Latest: 2025.

CSRF

8 records10.3%

First: 2020. Latest: 2025.

Missing Authorization

8 records10.3%

First: 2021. Latest: 2026.

SQL Injection

5 records6.4%

First: 2016. Latest: 2026.

Information Disclosure

5 records6.4%

First: 2021. Latest: 2026.

Arbitrary File Upload

1 record1.3%

First: 2016. Latest: 2016.

Path Traversal

1 record1.3%

First: 2023. Latest: 2023.

Patch Status

Patched
78
Currently marked unpatched
0
Unknown status
0

Patch status reflects the latest successfully synchronized source dataset and must be checked against the installed version.

Latest Known Patched Versions

  • 3.14.10
  • 3.14.2
  • 3.14.1
  • 3.13.3
  • 3.12.1
  • 3.11.1
  • 3.10.2.2
  • 3.10.1
  • 3.8.25
  • 3.8.23
  • 3.8.20
  • 3.8.18
  • 3.8.16
  • 3.8.12
  • 3.8.11
  • 3.8.7
  • 3.8.5
  • 3.8.1
  • 3.7.2
  • 3.6.34
  • 3.6.26
  • 3.6.25
  • 3.6.22
  • 3.6.13
  • 3.5.8.4
  • 3.4.34.2
  • 3.3.21.4
  • 3.2.28
  • 3.1.10
  • 3.0.34.2
  • 3.6.11
  • 3.6.10
  • 3.6.8
  • 3.6.4
  • 3.5.8.2
  • 3.5.8
  • 3.4.34.1
  • 3.4.34
  • 3.4.27.1
  • 3.4.28
  • 3.4.24.2
  • 3.4.23
  • 3.3.21.2
  • 3.3.19.1
  • 3.3.18
  • 3.3.14
  • 3.3.9
  • 3.2.15
  • 3.2.14
  • 3.0.32

Affected-Version History

Ranges are deduplicated by source range record and shown with the associated disclosure and known patched versions.

Affected rangeVulnerabilityPublishedPatched versionSeverity
2.9.36-2.9.42Ninja Forms Contact Form 2.9.36 - 2.9.42 - Unauthenticated Arbitrary File UploadMay 5, 20162.9.42.1Critical
*-2.9.28Ninja Forms Contact Form <= 2.9.28 - Stored Cross-Site ScriptingDecember 8, 20152.9.29High
*-2.9.27Ninja Forms Contact Form <= 2.9.27 - CSV InjectionSeptember 30, 20152.9.28High
*-2.9.21Ninja Forms Contact Form <= 2.9.21 - Reflected Cross-Site ScriptingAugust 4, 20152.9.22Medium
*-2.9.18Ninja Forms Contact Form <= 2.9.18 - Cross-Site ScriptingJune 5, 20152.9.19Medium
[*, 2.9.11)Ninja Forms <= 2.9.10 - Reflected Cross-Site ScriptingApril 20, 20152.9.11Medium
[*, 2.8.10)Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress <= 2.8.8 - Reflected Cross-Site ScriptingDecember 2, 20142.8.10Medium
[*, 2.8.9)Ninja Forms Contact Form <= 2.8.8 - Stored Cross-Site ScriptingNovember 20, 20142.8.9High
*-2.8.6Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress <= 2.8.6 - Reflected Cross-Site ScriptingNovember 6, 20142.8.7Medium

Selected source records

Latest Records

MediumCVE-2026-15663

Ninja Forms <= 3.14.9 - Authenticated (Administrator+) SQL Injection via Import File 'settings' Key

Published: July 23, 2026

Affected versions
*-3.14.9
Patched versions
3.14.10
Original Wordfence record
HighCVE-2026-1239

Ninja Forms <= 3.14.1 - Missing Authorization to Unauthenticated Sensitive Information Disclosure via token/refresh REST Endpoint

Published: June 30, 2026

Affected versions
*-3.14.1
Patched versions
3.14.2
Original Wordfence record
MediumCVE-2026-1307

Ninja Forms <= 3.14.1 - Authenticated (Contributor+) Sensitive Information Disclosure via Block Editor Token

Published: March 27, 2026

Affected versions
*-3.14.1
Patched versions
3.14.2
Original Wordfence record
HighCVE-2026-2268

Ninja Forms <= 3.14.0 - Unauthenticated Information Disclosure in nf_ajax_submit AJAX Action

Published: February 9, 2026

Affected versions
*-3.14.0
Patched versions
3.14.1
Original Wordfence record
HighCVE-2025-11924

Ninja Forms – The Contact Form Builder That Grows With You <= 3.13.2 - Insecure Direct Object Reference to Unauthenticated Sensitive Information Exposure via Unscoped Bearer Token

Published: December 16, 2025

Affected versions
*-3.13.2
Patched versions
3.13.3
Original Wordfence record
HighCVE-2025-14072

Ninja Forms <= 3.13.2 - Missing Authorization to Unauthenticated Submission Disclosure

Published: December 12, 2025

Affected versions
*-3.13.2
Patched versions
3.13.3
Original Wordfence record
MediumCVE-2025-10499

Ninja Forms – The Contact Form Builder That Grows With You <= 3.12.0 - Cross-Site Request Forgery to Plugin Settings Update

Published: September 26, 2025

Affected versions
*-3.12.0
Patched versions
3.12.1
Original Wordfence record
MediumCVE-2025-10498

Ninja Forms – The Contact Form Builder That Grows With You <= 3.12.0 - Cross-Site Request Forgery to Limited File Deletion

Published: September 26, 2025

Affected versions
*-3.12.0
Patched versions
3.12.1
Original Wordfence record

Highest-Severity Records

CriticalCVE-2016-1209

Ninja Forms Contact Form 2.9.36 - 2.9.42 - Unauthenticated Arbitrary File Upload

Published: May 5, 2016

Affected versions
2.9.36-2.9.42
Patched versions
2.9.42.1
Original Wordfence record
CriticalCVE-2019-15025

Ninja Forms Contact Form <= 3.3.21.1 - SQL Injection

Published: January 7, 2019

Affected versions
*-3.3.21.1
Patched versions
3.3.21.2
Original Wordfence record
Critical

Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress <= 3.6.10 - Code Injection

Published: June 15, 2022

Affected versions
*-3.0.34.1; 3.1-3.1.9; 3.2-3.2.27; 3.3-3.3.21.3; 3.4-3.4.34.1; 3.5-3.5.8.3; 3.6-3.6.10
Patched versions
3.0.34.2, 3.1.10, 3.2.28, 3.3.21.4, 3.4.34.2, 3.5.8.4, 3.6.11
Original Wordfence record
CriticalCVE-2018-20981

Ninja Forms <= 3.3.8 - Insufficient Restrictions during Export Personal Data requests

Published: July 6, 2018

Affected versions
*-3.3.8
Patched versions
3.3.9
Original Wordfence record
HighCVE-2021-24163

Ninja Forms Contact Form <= 3.4.33 - Authenticated SendWP Plugin Installation and Client Secret Key Disclosure

Published: February 16, 2021

Affected versions
[*, 3.4.34)
Patched versions
3.4.34
Original Wordfence record
High

Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress <= 3.6.9 - Cross-Site Request Forgery to Field Import and PHP Object Injection

Published: June 7, 2022

Affected versions
*-3.6.9
Patched versions
3.6.10
Original Wordfence record
High

Ninja Forms Contact Form <= 2.9.55.1 - Authenticated SQL Injection

Published: August 16, 2016

Affected versions
[*, 2.9.55.2)
Patched versions
2.9.55.2
Original Wordfence record
HighCVE-2020-36174

Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress <= 3.4.27 - Cross-Site Request Forgery to Plugin Installation

Published: September 22, 2020

Affected versions
*-3.4.27
Patched versions
3.4.27.1
Original Wordfence record

View all associated vulnerabilities

Need help reviewing an exposed WordPress website?

Running an affected version does not prove that a website was compromised. Suspicious redirects, unknown administrators, injected content, unexpected files or recurring malware may require a manual investigation.

Vulnerability data: Wordfence Intelligence. Analysis and practical guidance: 3Zero Digital.

Data Source, Attribution and Methodology

This page aggregates active Production Feed records. Counts are not software-quality rankings, and an affected version does not prove exploitation or infection. Read the full methodology.

Return to the Security History Directory