Extension WordPress
Vulnérabilités Ninja Forms – File Uploads
Cette page rassemble les failles publiées pour Ninja Forms – File Uploads, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Ninja Forms – File Uploads
7 fiches
Ninja Forms – File Uploads <= 3.3.29 – Missing Authorization to Unauthenticated Log Disclosure and Deletion via debug-log/delete-all and debug-log/get-all REST Endpoints
The Ninja Forms – File Uploads plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.3.29. This is due to the plugin not properly verifying that a user is authorized to perform…
*-3.3.29
3.3.30
02/07/2026
Ninja Forms – File Uploads <= 3.3.29 – Unauthenticated Arbitrary File Read via File Upload Field 'files[].data.file_path' Parameter
The Ninja Forms – File Uploads plugin for WordPress is vulnerable to Arbitrary File Read via the attach_files() function in versions up to, and including, 3.3.29. This is due to the get_files_for_attachment() function accepting a raw attacker-controlled 'files'…
*-3.3.29
3.3.30
01/07/2026
Ninja Forms – File Upload <= 3.3.26 – Unauthenticated Arbitrary File Upload
The Ninja Forms – File Uploads plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'NF_FU_AJAX_Controllers_Uploads::handle_upload' function in all versions up to, and including, 3.3.26. This makes it possible for…
*-3.3.26
3.3.27
06/04/2026
Ninja Forms File Uploads <= 3.3.16 – Unauthenticated Stored Cross-Site Scripting via File Upload
The Ninja Forms – File Uploads plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an uploaded file (e.g. RTX file) in all versions up to, and including, 3.3.16 due to insufficient input sanitization and output escaping.…
*-3.3.16
3.3.18
06/09/2024
Ninja Forms – File Uploads Extension <= 3.3.12 – Reflected Cross-Site Scripting
The Ninja Forms – File Uploads Extension WordPress plugin is vulnerable to reflected cross-site scripting due to missing sanitization of the files filename parameter found in the ~/includes/ajax/controllers/uploads.php file which can be used by unauthenticated attackers to add…
*-3.3.12
3.3.13
20/11/2021
Ninja Forms – File Uploads Extension <= 3.3.0 – Arbitrary File Upload
The Ninja Forms – File Uploads Extension WordPress plugin is vulnerable to arbitrary file uploads due to insufficient input file type validation found in the ~/includes/ajax/controllers/uploads.php file which can be bypassed making it possible for unauthenticated attackers to…
*-3.3.0
3.3.1
20/03/2020
Ninja Forms – File Uploads <= 3.0.22 – Unauthenticated Arbitrary File Upload
Path Traversal and Unrestricted File Upload exists in the Ninja Forms plugin before 3.0.23 for WordPress (when the Uploads add-on is activated). This allows an attacker to traverse the file system to access files and execute code via…
[*, 3.0.23)
3.0.23
11/04/2019
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.