Extension WordPress
Vulnérabilités Ninja Forms – The Contact Form Builder That Grows With You, page 3
Cette page rassemble les failles publiées pour Ninja Forms – The Contact Form Builder That Grows With You, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Ninja Forms – The Contact Form Builder That Grows With You
77 fiches
Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress <= 3.6.9 – Cross-Site Request Forgery to Field Import and PHP Object Injection
The Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including 3.6.9, due to missing nonce validation on the import_fields_listener()…
*-3.6.9
3.6.10
07/06/2022
Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress <= 3.6.7 – Email Address Disclosure
The Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to Sensitive Data Exposure in versions up to, and including, 3.6.7. This can allow unauthenticated attackers to extract sensitive…
*-3.6.7
3.6.8
22/03/2022
Ninja Forms Contact Form <= 3.6.3 – Authenticated SQL Injection
The Ninja Forms Contact Form WordPress plugin before 3.6.4 does not escape keys of the fields POST parameter, which could allow high privilege users to perform SQL injections attacks
[*, 3.6.4)
3.6.4
26/10/2021
Ninja Forms <= 3.5.8.1 – Cross-Site Scripting
The Ninja Forms Contact Form WordPress plugin before 3.5.8.2 does not sanitise and escape the custom class name of the form field created, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html…
[*, 3.5.8.2)
3.5.8.2
27/09/2021
Ninja Forms <= 3.5.7 – Unprotected REST-API to Email Injection
The Ninja Forms WordPress plugin is vulnerable to arbitrary email sending via the trigger_email_action function found in the ~/includes/Routes/Submissions.php file, in versions up to and including 3.5.7. This allows authenticated attackers to send arbitrary emails from the affected…
*-3.5.7
3.5.8
22/09/2021
Ninja Forms <= 3.5.7 – Unprotected REST-API to Sensitive Information Disclosure
The Ninja Forms WordPress plugin is vulnerable to sensitive information disclosure via the bulk_export_submissions function found in the ~/includes/Routes/Submissions.php file, in versions up to and including 3.5.7. This allows authenticated attackers to export all Ninja Forms submissions data…
*-3.5.7
3.5.8
22/09/2021
Ninja Forms Contact Form <= 3.4.33 – Cross-Site Request Forgery to OAuth Service Disconnection
The wp_ajax_nf_oauth_disconnect from the Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress WordPress plugin before 3.4.34 had no nonce protection making it possible for attackers to craft a request to disconnect a site's…
[*, 3.4.34)
3.4.34
16/02/2021
Ninja Forms <= 3.4.34 – Authenticated OAuth Connection Key Disclosure
In the Ninja Forms Contact Form WordPress plugin before 3.4.34.1, low-level users, such as subscribers, were able to trigger the action, wp_ajax_nf_oauth, and retrieve the connection url needed to establish a connection. They could also retrieve the client_id…
[*, 3.4.34.1)
3.4.34.1
16/02/2021
Ninja Forms Contact Form <= 3.4.33 – Authenticated SendWP Plugin Installation and Client Secret Key Disclosure
The AJAX action, wp_ajax_ninja_forms_sendwp_remote_install_handler, did not have a capability check on it, nor did it have any nonce protection, therefore making it possible for low-level users, such as subscribers, to install and activate the SendWP Ninja Forms Contact…
[*, 3.4.34)
3.4.34
16/02/2021
Ninja Forms Contact Form <= 3.4.33 – Administrator Open Redirect
In the Ninja Forms Contact Form WordPress plugin before 3.4.34, the wp_ajax_nf_oauth_connect AJAX action was vulnerable to open redirect due to the use of a user supplied redirect parameter and no protection in place.
[*, 3.4.34)
3.4.34
16/02/2021
Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress <= 3.4.27 – Cross-Site Request Forgery to Plugin Installation
The Ninja Forms plugin before 3.4.27.1 for WordPress allows CSRF via services integration. This makes it possible for attackers to install arbitrary plugins.
*-3.4.27
3.4.27.1
22/09/2020
Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress <= 3.4.27 – Validation Bypass via Email Field
The Ninja Forms plugin before 3.4.27.1 for WordPress allows attackers to bypass validation via the email field.
*-3.4.27
3.4.27.1
22/09/2020
Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress <= 3.4.27.1 – Stored Cross-Site Scripting
The Ninja Forms plugin before 3.4.28 for WordPress lacks escaping for submissions-table fields.
*-3.4.27.1
3.4.28
20/09/2020
Ninja Forms Contact Form <= 3.4.24.1 – Cross-Site Request Forgery leading to Stored Cross-Site Scripting
The Ninja Forms plugin before 3.4.24.2 for WordPress allows CSRF with resultant XSS.
[*, 3.4.24.2)
3.4.24.2
28/04/2020
Ninja Forms Contact Form <= 3.4.22 – Stored Cross-Site Scripting
The Ninja Forms plugin 3.4.22 for WordPress has Multiple Stored XSS vulnerabilities via ninja_forms[recaptcha_site_key], ninja_forms[recaptcha_secret_key], ninja_forms[recaptcha_lang], or ninja_forms[date_format].
[*, 3.4.23)
3.4.23
03/02/2020
Ninja Forms Contact Form <= 3.3.21.1 – SQL Injection
The ninja-forms plugin before 3.3.21.2 for WordPress has SQL injection in the search filter on the submissions page.
*-3.3.21.1
3.3.21.2
07/01/2019
Ninja Forms Contact Form <= 3.3.19 – Authenticated Open Redirect
An open redirect in the Ninja Forms plugin before 3.3.19.1 for WordPress allows Remote Attackers to redirect a user via the lib/StepProcessing/step-processing.php (aka submissions download page) redirect parameter.
*-3.3.19
3.3.19.1
01/12/2018
Ninja Forms Contact Form <= 3.3.17 – Cross-Site Scripting via begin_date, end_date, or form_id Parameter
XSS in the Ninja Forms plugin before 3.3.18 for WordPress allows Remote Attackers to execute JavaScript via the includes/Admin/Menus/Submissions.php (aka submissions page) begin_date, end_date, or form_id parameter.
[*, 3.3.18)
3.3.18
15/11/2018
Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress <= 3.3.13 – Cross-Site Scripting
The Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to Cross-Site Scripting via the form input function in versions up to, and including, 3.3.13 due to insufficient input…
[*, 3.3.14)
3.3.14
27/08/2018
Ninja Forms Contact Form <= 3.3.13 – CSV Injection
The Ninja Forms plugin before 3.3.14.1 for WordPress allows CSV injection.
*-3.3.13
3.3.14
19/08/2018
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.