Known Vulnerabilities for Ninja Forms by Saturday Drive
Listed below are 10 of the newest known vulnerabilities associated with "Ninja Forms" by "Saturday Drive".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-95515 json | Unauthenticated Cross Site Scripting (XSS) in Ninja Forms <= 3.15.3 versions. | Not Provided | 2026-09-23 | 2026-09-23 |
| CVE-2026-94504 json | Ninja Forms 3.15.3 stores an anonymous non-RTE textarea value and renders it without safe HTML encoding in the legacy submiss... | Not Provided | 2026-09-22 | 2026-09-22 |
| CVE-2026-92438 json | The Ninja Forms WordPress plugin 3.15.3 does not escape submitted form field values before outputting them on the submission ... | Not Provided | 2026-09-22 | 2026-09-22 |
| CVE-2026-91827 json | The Ninja Forms WordPress plugin 3.15.3 does not prevent user-submitted form field values from being deserialised when an adm... | Not Provided | 2026-09-22 | 2026-09-22 |
| CVE-2026-87870 json | The Ninja Forms - Scheduled Exports plugin for WordPress is vulnerable to Stored Cross-Site Scripting via REST API Parameters... | Not Provided | 2026-09-10 | 2026-09-11 |
| CVE-2026-81773 json | Unauthenticated Cross Site Scripting (XSS) in Ninja Forms File Uploads Extension <= 3.3.26 versions. | Not Provided | 2026-09-03 | 2026-09-05 |
| CVE-2026-81772 json | Unauthenticated PHP Object Injection in Ninja Forms - Layout & Styles <= 3.0.31 versions. | Not Provided | 2026-09-02 | 2026-09-03 |
| CVE-2026-80438 json | The Ninja Forms WordPress plugin before 3.15.2 does not restrict its REST abilities to administrators, accepting a Ninja For... | Not Provided | 2026-09-04 | 2026-09-04 |
| CVE-2026-80437 json | The Ninja Forms WordPress plugin from 3.14.10 before 3.15.2 does not prevent shortcodes in request-derived values from being ... | Not Provided | 2026-09-06 | 2026-09-06 |
| CVE-2026-65052 json | Ninja Forms WordPress plugin version 3.14.8 and prior contains an improper input validation vulnerability that allows unauthe... | Not Provided | 2026-07-21 | 2026-07-22 |