Extension WordPress
Vulnérabilités Ninja Forms – The Contact Form Builder That Grows With You, page 4
Cette page rassemble les failles publiées pour Ninja Forms – The Contact Form Builder That Grows With You, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Ninja Forms – The Contact Form Builder That Grows With You
77 fiches
Ninja Forms <= 3.3.8 – Insufficient Restrictions during Export Personal Data requests
The ninja-forms plugin before 3.3.9 for WordPress has insufficient restrictions on submission-data retrieval during Export Personal Data requests.
*-3.3.8
3.3.9
06/07/2018
Ninja Forms Contact Form <= 3.2.14 – Parameter Tampering
The ninja-forms plugin before 3.2.15 for WordPress has parameter tampering.
[*, 3.2.15)
3.2.15
26/02/2018
Ninja Forms Contact Form <= 3.2.13 – Cross-Site Scripting
The Ninja Forms plugin before 3.2.14 for WordPress has XSS.
[*, 3.2.14)
3.2.14
20/02/2018
Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress <= 3.0.31 – Arbitrary Wordpress Shortcode Injection
The Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to Arbitrary Wordpress Shortcode Injection in versions up to, and including, 3.0.31. This makes it possible for unauthenticated attackers…
*-3.0.31
3.0.32
17/04/2017
Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress <= 3.0.30 – HTML Injection
The ninja-forms plugin before 3.0.31 for WordPress has insufficient HTML escaping in the builder.
[*, 3.0.31)
3.0.31
07/03/2017
Ninja Forms Contact Form <= 2.9.55.1 – Authenticated SQL Injection
The Ninja Forms Contact Form plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 2.9.55.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL…
[*, 2.9.55.2)
2.9.55.2
16/08/2016
Ninja Forms Contact Form <= 2.9.51 – Multiple Reflected Cross-Site Scripting
The Ninja Forms Contact Form plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via multiple parameters in versions before 2.9.52 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject…
[*, 2.9.52)
2.9.52
19/07/2016
Ninja Forms Contact Form 2.9.36 – 2.9.42 – PHP Object Injection
The Ninja Forms plugin before 2.9.42.1 for WordPress allows remote attackers to conduct PHP object injection attacks via crafted serialized values in a POST request.
2.9.36-2.9.42
2.9.42.1
13/05/2016
Ninja Forms Contact Form 2.9.36 – 2.9.42 – Unauthenticated Arbitrary File Upload
Versions 2.9.36 to 2.9.42 of the Ninja Forms plugin contain an unauthenticated file upload vulnerability, allowing guests to upload arbitrary PHP code that can be executed in the context of the web server.
2.9.36-2.9.42
2.9.42.1
05/05/2016
Ninja Forms Contact Form <= 2.9.28 – Stored Cross-Site Scripting
The Ninja Forms Contact Form plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 2.9.28 due to insufficient input sanitization and output escaping during form submission. This makes it possible for attackers to…
*-2.9.28
2.9.29
08/12/2015
Ninja Forms Contact Form <= 2.9.27 – CSV Injection
The Ninja Forms Contact Form plugin for WordPress is vulnerable to CSV Injection in versions up to, and including, 2.9.27 via the export() function. This allows authenticated attackers to embed untrusted input into exported CSV files, which can…
*-2.9.27
2.9.28
30/09/2015
Ninja Forms Contact Form <= 2.9.21 – Reflected Cross-Site Scripting
The Ninja Forms Contact Form plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 2.9.21 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers to inject…
*-2.9.21
2.9.22
04/08/2015
Ninja Forms Contact Form <= 2.9.18 – Cross-Site Scripting
The Ninja Forms Contact Form plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 2.9.18 due to insufficient input sanitization and output escaping. This makes it possible for unauthorized attackers to inject arbitrary…
*-2.9.18
2.9.19
05/06/2015
Ninja Forms <= 2.9.10 – Reflected Cross-Site Scripting
The Ninja Forms plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 2.9.10 due to insufficient input sanitization and output escaping on add_query_arg and remove_query_arg. This makes it possible for attackers to…
[*, 2.9.11)
2.9.11
20/04/2015
Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress <= 2.8.8 – Reflected Cross-Site Scripting
The Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘ninja_forms_field_1’ parameter in versions up to, and including, 2.8.8 due to insufficient input sanitization…
[*, 2.8.10)
2.8.10
02/12/2014
Ninja Forms Contact Form <= 2.8.8 – Stored Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in the Ninja Forms plugin before 2.8.9 for WordPress allow (1) remote attackers to inject arbitrary web script or HTML via the ninja_forms_field_1 parameter in a ninja_forms_ajax_submit action to wp-admin/admin-ajax.php or (2) remote…
[*, 2.8.9)
2.8.9
20/11/2014
Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress <= 2.8.6 – Reflected Cross-Site Scripting
The Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘update_message’ parameter in versions up to, and including, 2.8.6 due to insufficient input…
*-2.8.6
2.8.7
06/11/2014
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.