Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
8.8
CVE-2026-92438
- EPSS 0.35%
- Veröffentlicht 22.09.2026 06:58:00
- Zuletzt bearbeitet 22.09.2026 19:41:38
The Ninja Forms WordPress plugin 3.15.3 does not escape submitted form field values before outputting them on the submission edit screen in the admin area, which could allow unauthenticated users to submit values through a public form that then execu...
5.9
CVE-2026-80438
- EPSS 0.14%
- Veröffentlicht 04.09.2026 06:00:04
- Zuletzt bearbeitet 08.09.2026 19:15:18
The Ninja Forms WordPress plugin before 3.15.2 does not restrict its REST abilities to administrators, accepting a Ninja Forms WordPress plugin before 3.15.2-specific capability as equivalent to full site administration, which allows any user grant...
9.8
CVE-2019-15025
- EPSS 1.78%
- Veröffentlicht 14.08.2019 15:15:12
- Zuletzt bearbeitet 21.11.2024 04:27:53
The ninja-forms plugin before 3.3.21.2 for WordPress has SQL injection in the search filter on the submissions page.
1