Ninja Forms – The Contact Form Builder That Grows With You

Explore Ninja Forms – The Contact Form Builder That Grows With You vulnerabilities across all versions. Currently tracking 78 known vulnerabilities, including severity, impact, and patch status.

01234567891021.12.2011Today06.11.20146.1Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress <= 2.8.6 - Reflected Cross-Site Scripting CVSS 6.1 · 06.11.201420.11.20147.2Ninja Forms Contact Form <= 2.8.8 - Stored Cross-Site Scripting CVSS 7.2 · 20.11.201402.12.20146.1Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress <= 2.8.8 - Reflected Cross-Site Scripting CVSS 6.1 · 02.12.201420.04.20156.1Ninja Forms <= 2.9.10 - Reflected Cross-Site Scripting CVSS 6.1 · 20.04.201505.06.20156.1Ninja Forms Contact Form <= 2.9.18 - Cross-Site Scripting CVSS 6.1 · 05.06.201504.08.20155.4Ninja Forms Contact Form <= 2.9.21 - Reflected Cross-Site Scripting CVSS 5.4 · 04.08.201530.09.20158.4Ninja Forms Contact Form <= 2.9.27 - CSV Injection CVSS 8.4 · 30.09.201508.12.20157.2Ninja Forms Contact Form <= 2.9.28 - Stored Cross-Site Scripting CVSS 7.2 · 08.12.201505.05.20169.8Ninja Forms Contact Form 2.9.36 - 2.9.42 - Unauthenticated Arbitrary File Upload CVSS 9.8 · 05.05.201613.05.20168.1Ninja Forms Contact Form 2.9.36 - 2.9.42 - PHP Object Injection CVSS 8.1 · 13.05.201619.07.20166.1Ninja Forms Contact Form <= 2.9.51 - Multiple Reflected Cross-Site Scripting CVSS 6.1 · 19.07.201616.08.20168.8Ninja Forms Contact Form <= 2.9.55.1 - Authenticated SQL Injection CVSS 8.8 · 16.08.201607.03.20176.1Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress <= 3.0.30 - HTML Injection CVSS 6.1 · 07.03.201717.04.20175.3Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress <= 3.0.31 - Arbitrary Wordpress Shortcode Injection CVSS 5.3 · 17.04.201720.02.20186.1Ninja Forms Contact Form <= 3.2.13 - Cross-Site Scripting CVSS 6.1 · 20.02.201826.02.20187.5Ninja Forms Contact Form <= 3.2.14 - Parameter Tampering CVSS 7.5 · 26.02.201806.07.20189.1Ninja Forms <= 3.3.8 - Insufficient Restrictions during Export Personal Data requests CVSS 9.1 · 06.07.201819.08.20188.6Ninja Forms Contact Form <= 3.3.13 - CSV Injection CVSS 8.6 · 19.08.201827.08.20188.3Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress <= 3.3.13 - Cross-Site Scripting CVSS 8.3 · 27.08.201815.11.20186.1Ninja Forms Contact Form <= 3.3.17 - Cross-Site Scripting via begin_date, end_date, or form_id Parameter CVSS 6.1 · 15.11.201801.12.20184.7Ninja Forms Contact Form <= 3.3.19 - Authenticated Open Redirect CVSS 4.7 · 01.12.201807.01.20199.8Ninja Forms Contact Form <= 3.3.21.1 - SQL Injection CVSS 9.8 · 07.01.201903.02.20206.4Ninja Forms Contact Form <= 3.4.22 - Stored Cross-Site Scripting CVSS 6.4 · 03.02.202028.04.20206.1Ninja Forms Contact Form <= 3.4.24.1 - Cross-Site Request Forgery leading to Stored Cross-Site Scripting CVSS 6.1 · 28.04.202020.09.20206.5Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress <= 3.4.27.1 - Stored Cross-Site Scripting CVSS 6.5 · 20.09.202022.09.20208.8Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress <= 3.4.27 - Cross-Site Request Forgery to Plugin Installation CVSS 8.8 · 22.09.20205.3Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress <= 3.4.27 - Validation Bypass via Email Field CVSS 5.3 · 22.09.202016.02.20218.8Ninja Forms Contact Form <= 3.4.33 - Authenticated SendWP Plugin Installation and Client Secret Key Disclosure CVSS 8.8 · 16.02.20214.3Ninja Forms <= 3.4.34 - Authenticated OAuth Connection Key Disclosure CVSS 4.3 · 16.02.20216.1Ninja Forms Contact Form <= 3.4.33 - Administrator Open Redirect CVSS 6.1 · 16.02.20215.4Ninja Forms Contact Form <= 3.4.33 - Cross-Site Request Forgery to OAuth Service Disconnection CVSS 5.4 · 16.02.202122.09.20216.5Ninja Forms <= 3.5.7 - Unprotected REST-API to Sensitive Information Disclosure CVSS 6.5 · 22.09.20216.4Ninja Forms <= 3.5.7 - Unprotected REST-API to Email Injection CVSS 6.4 · 22.09.202127.09.20214.8Ninja Forms <= 3.5.8.1 - Cross-Site Scripting CVSS 4.8 · 27.09.202126.10.20217.2Ninja Forms Contact Form <= 3.6.3 - Authenticated SQL Injection CVSS 7.2 · 26.10.202122.03.20225.3Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress <= 3.6.7 - Email Address Disclosure CVSS 5.3 · 22.03.202207.06.20228.8Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress <= 3.6.9 - Cross-Site Request Forgery to Field Import and PHP Object Injection CVSS 8.8 · 07.06.20225.5Ninja Forms Contact Form <= 3.6.9 - Authenticated (Admin+) Cross-Site Scripting via label CVSS 5.5 · 07.06.202210.06.20225.5Ninja Ninja Forms Contact Form <= 3.6.10 - Authenticated (Admin+) Stored Cross-Site Scripting via import CVSS 5.5 · 10.06.202213.06.20224.8Ninja Forms Contact Form <= 3.6.9 - Cross-Site Scripting via field label CVSS 4.8 · 13.06.202215.06.20229.8Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress <= 3.6.10 - Code Injection CVSS 9.8 · 15.06.202205.09.20227.2Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress <= 3.6.12 - Authenticated (Administrator+) PHP Objection Injection CVSS 7.2 · 05.09.202224.04.20236.1Ninja Forms Contact Form <= 3.6.21 - Reflected Cross-Site Scripting via 'title' CVSS 6.1 · 24.04.202322.06.20236.5Ninja Forms <= 3.6.24 - Authenticated (Admin+) Arbitrary File Deletion CVSS 6.5 · 22.06.202307.07.20235.3Ninja Forms <= 3.6.25 - Denial of Service via Large Form Submissions CVSS 5.3 · 07.07.202325.07.20234.3Ninja Forms <= 3.6.25 - Missing Authorization to Form Submission Export CVSS 4.3 · 25.07.20236.1Ninja Forms <= 3.6.25 - Reflected Cross-Site Scripting via 'data' CVSS 6.1 · 25.07.20235.3Ninja Forms <= 3.6.25 - Missing Authorization to Contributor+ Form Submission Export CVSS 5.3 · 25.07.202307.08.20234.4Ninja Forms <= 3.6.25 - Authenticated (Administrator+) Stored HTML Injection CVSS 4.4 · 07.08.202316.10.20234.4Ninja Forms Contact Form <= 3.6.33 - Authenticated (Admin+) Stored Cross-Site Scripting CVSS 4.4 · 16.10.202301.02.20245.9Ninja Forms Contact Form <= 3.7.1 - Unauthenticated Second Order SQL Injection CVSS 5.9 · 01.02.202428.03.20244.3Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress <= 3.8.0 - Cross-Site Request Forgery to Publicly Accessible Form Submission Export CVSS 4.3 · 28.03.20244.6Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress <= 3.8.0 - Authenticated (Author+) Stored Cross-Site Scripting CVSS 4.6 · 28.03.202408.04.20244.4Ninja Forms – The Contact Form Builder That Grows With You <= 3.8.0 - Authenticated (Admin+) Stored Cross-Site Scripting CVSS 4.4 · 08.04.20244.4Ninja Forms – The Contact Form Builder That Grows With You <= 3.8.0 - Authenticated (Admin+) Stored Cross-Site Scripting CVSS 4.4 · 08.04.202404.07.20244.3Ninja Forms <= 3.8.4 - Authenticated (Subscriber+) Arbitrary Shortcode Execution CVSS 4.3 · 04.07.202424.07.20244.3Ninja Forms <= 3.8.6 - Cross-Site Request Forgery CVSS 4.3 · 24.07.202412.08.20246.1Ninja Forms – The Contact Form Builder That Grows With You <= 3.8.10 - Reflected Cross-Site Scripting CVSS 6.1 · 12.08.202428.08.20244.4Ninja Forms <= 3.8.11 - Authenticated (Administrator+) Stored Cross-Site Scripting CVSS 4.4 · 28.08.202424.09.20244.7Ninja Forms Contact Form <= 3.8.15 - Reflected Self-Based Cross-Site Scripting via Referer CVSS 4.7 · 24.09.202428.10.20244.4Ninja Forms – The Contact Form Builder That Grows With You <= 3.8.17 - Authenticated (Admin+) Stored Cross-Site Scripting CVSS 4.4 · 28.10.20244.4Ninja Forms – The Contact Form Builder That Grows With You <= 3.8.17 - Authenticated (Admin+) Stored Cross-Site Scripting CVSS 4.4 · 28.10.202411.12.20247.2Ninja Forms – The Contact Form Builder That Grows With You <= 3.8.19 - Unauthenticated Stored Cross-Site Scripting via Form Calculations CVSS 7.2 · 11.12.202428.12.20246.3Ninja Forms – The Contact Form Builder That Grows With You <= 3.8.22 - Authenticated (Subscriber+) Arbitrary Shortcode Execution CVSS 6.3 · 28.12.202429.01.20256.4Ninja Forms – The Contact Form Builder That Grows With You <= 3.8.24 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode CVSS 6.4 · 29.01.202528.04.20254.4Ninja Forms – The Contact Form Builder That Grows With You <= 3.10.0 - Authenticated (Admin+) Stored Cross-Site Scripting CVSS 4.4 · 28.04.20254.4Ninja Forms – The Contact Form Builder That Grows With You <= 3.10.0 - Authenticated (Admin+) Stored Cross-Site Scripting CVSS 4.4 · 28.04.20254.4Ninja Forms – The Contact Form Builder That Grows With You <= 3.10.0 - Authenticated (Admin+) Stored Cross-Site Scripting CVSS 4.4 · 28.04.202526.06.20256.4Ninja Forms <= 3.10.2.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via CSTI CVSS 6.4 · 26.06.202528.08.20258.1Ninja Forms <= 3.11.0 - Unauthenticated PHP Object Injection CVSS 8.1 · 28.08.202526.09.20254.3Ninja Forms – The Contact Form Builder That Grows With You <= 3.12.0 - Cross-Site Request Forgery to Limited File Deletion CVSS 4.3 · 26.09.20254.3Ninja Forms – The Contact Form Builder That Grows With You <= 3.12.0 - Cross-Site Request Forgery to Plugin Settings Update CVSS 4.3 · 26.09.202512.12.20257.5Ninja Forms <= 3.13.2 - Missing Authorization to Unauthenticated Submission Disclosure CVSS 7.5 · 12.12.202516.12.20257.5Ninja Forms – The Contact Form Builder That Grows With You <= 3.13.2 - Insecure Direct Object Reference to Unauthenticated Sensitive Information Exposure via Unscoped Bearer Token CVSS 7.5 · 16.12.202509.02.20267.5Ninja Forms <= 3.14.0 - Unauthenticated Information Disclosure in nf_ajax_submit AJAX Action CVSS 7.5 · 09.02.202627.03.20266.5Ninja Forms <= 3.14.1 - Authenticated (Contributor+) Sensitive Information Disclosure via Block Editor Token CVSS 6.5 · 27.03.202630.06.20267.5Ninja Forms <= 3.14.1 - Missing Authorization to Unauthenticated Sensitive Information Disclosure via token/refresh REST Endpoint CVSS 7.5 · 30.06.202623.07.20264.9Ninja Forms <= 3.14.9 - Authenticated (Administrator+) SQL Injection via Import File 'settings' Key CVSS 4.9 · 23.07.2026

Strategic Overview

Avg CVSSMedium
6.2/ 10
Patch Coverage100%
Open

0

Fixed

78

Get automatic notifications for all Ninja Forms – The Contact Form Builder That Grows With You vulnerabilities before they are exploited.

Vulnerability Records

78 records
2026-07-23 21:25CVE-2026-15663
4.9
Medium
Wordfence PRISMYes
2026-06-30 17:19CVE-2026-1239
7.5
High
suyoung kim(AhnLab)Yes
2026-03-27 18:10CVE-2026-1307
6.5
Medium
Lucas Montes (NiRoX)Yes
2026-02-09 20:41CVE-2026-2268
7.5
High
johskaYes
2025-12-16 18:41CVE-2025-11924
7.5
High
Lucas Montes (NiRoX)Yes
2025-12-12 00:00CVE-2025-14072
7.5
High
Marco LunardiYes
2025-09-26 14:16CVE-2025-10499
4.3
Medium
Nguyen Ngoc Quang Bach (maysbachs)Yes
2025-09-26 14:15CVE-2025-10498
4.3
Medium
Nguyen Ngoc Quang Bach (maysbachs)Yes
2025-08-28 00:00CVE-2025-9083
8.1
High
wesley (wcraft)Yes
2025-06-26 00:00CVE-2025-5398
6.4
Medium
Asaf MozesYes
Showing 1–10 of 78 reports
Ninja Forms &#8211; The Contact Form Builder That Grows With You banner
Latestv3.14.11

Ninja Forms &#8211; The Contact Form Builder That Grows With You

Kevin Stover

Author

Kevin Stover

4.4(1,394)
88/100
Last Updated
2026-07-27 (2d ago)
Active Installs
600,000+
Downloads
61,536,256
Requires WP
6.8+
Requires PHP
7.4+
Tested up to
WP 7.0.2
Created
2011-12-21 (15y ago)

Forms that grow with your business As one of WordPress’ oldest form builders, we’re proud to serve users from around the world, from all walks of life, and from different stages of online growth. From the small businesses and local nonprofits that make up the core Ninja Forms user base to universities, hospitals, and even Fortune 500 companies, we’ll scale with you from startup to wherever you’re aiming for. We’re committed to offering as many free, open source tools as we can get away with to back you up in the extremely price-conscious early days. As you grow, pick and choose only the premium features you need as you need them. We’ll grow with you from there for as far as you want to take us. We’re also committed to respecting your privacy and time. No unsolicited emails or aggressive marketing. No paywalling basic features or scraping private data. We offer a fully staffed team of support experts and a comprehensive library of plugin documentation for all users, free and paid, to help keep you collecting the submissions that move your business forward. We look forward to seeing where you’ll take us! All the basics without the paywalls When you’re starting out, even little expenses add up quickly. That’s why Ninja Forms core will always be free and open source. It’s why we try to offer as much in core as we can to cover your basic needs at no cost. Here’s a peek at some of what core has to offer. Form Building Features – 24+ FREE drag-and-drop form fields – Customize fields with default values, specialty text, and much more – Favorite and reuse any customized field – Calculations: assign values to fields and calculate totals – Merge tag system for pre-populating fields and passing field data between forms – Configurable per-field submission storage for easy GDPR compliance – Email notifications on submission (as many as you like, free!) – Customizable success messages (supports links and downloads!) – Redirect to new page after submission – Customize callbacks to WP action hooks on submit – Spam Protection: full integration with Google reCAPTCHA & Akismet – Configurable form display settings – Form restriction settings – Unique field validation – Unlimited forms & submissions – Form Templates – Form Import / Export – Shareable forms (share the form via link without it being attached to a page) – No aggressive marketing, pushy review asks, constant popups, or unsolicited emails – Responsive and mobile friendly – SEO friendly Submission Management Features – Unlimited FREE submissions – Configurable submissions display – Search and filter by field – Search and filter by submitted value – Search and filter by submission date – Edit submitted values – Refire any email notification from any submission – Export to CSV – Bulk submissions export – Automated WordPress GDPR integration for export & delete data requests – Mark fields as PII and selectively not store specific data – All submissions stored locally on YOUR server only unless you specify otherwise – We never see or collect your field or submission data Dozens of buildable form types – Contact form – Email form – Calculation form – Lead form – Quiz form – Mortgage or Payment Calculator forms – Quote and Cost Calculator forms – Health and Fitness Calculator forms – Polling form – Survey form – Lead Magnet Download form – Event Registration form – Sales form – Appointment form – Booking form – Entry form – Order form – Lesson Plan form – Job Application form – RSVP form – Request form – Feedback form – Support form – GDPR Export or Delete Data Request forms …and many more! You get more than just a plugin – Fully documented – Regular updates – FREE technical support – Privacy and security minded – Accessibility focused – Translated into 24+ languages by the WordPress Polyglots team – Long term partners of WPML for even more translations! – Ecosystem aware: we know it’s not just you and Ninja Forms. We do our best to communicate and play nice with others. Pick and choose just what you need as you need it As you start to grow, so does what you need out of your forms. But there’s no need to dive into the deep end right away and spend more than is practical. All premium features are contained in add-ons to the core form builder and can be purchased independently. When you find yourself wanting just one or two things, you can grab just what you need without paying for extras. When you’re ready for more, our membership plans bundle popular features together in budget friendly packages. Select from 40+ add-ons across multiple categories: Advanced Form Features – Advanced Datepicker – Conditional Logic – File Uploads – Layout & Styles – Multi Step Forms – Save Progress – User Analytics – User Management Submissions Extended – Excel Export – Front End Posting – PDF Form Submissions – Scheduled Submissions Export Accept Payments – Authorize.net – Elavon – PayPal official partner – Recurly – Stripe Email Marketing – Active Campaign – AWeber – Campaign Monitor – CleverReach – Constant Contact – ConvertKit – EmailOctopus – Emma – Mailchimp – MailPoet CRMs – Capsule – CiviCRM – HubSpot *official partners – Insightly – OnePageCRM – PipelineDeals – Salesforce – Zoho CRM Notifications & Workflow – ClickSend SMS – Help Scout – Slack – Trello – Twilio SMS Automation – Webhooks – Zapier official partners The sky’s the limit on what you can build with add-on features, but here are some of the most popular forms we see in the wild: Payment forms Donation forms Signup forms User Registration form Newsletter forms CRM forms User Registration form Login forms Upload forms Google Sheets forms Post Creation forms Notes We’ve been standing by our product and our users for over a decade, working to make your experience the best it can be. We’re one of the only form builders around that offers support for all users, whether you’ve made a purchase or not. If you have any questions or suggestions, we’re always happy to hear from you. We have a dedicated support team with team members that span four continents standing by to help with technical questions every Monday to Friday. General feedback is always welcome too. It’s a big part of how we figure out what to do next, so chime in any time! You’ll always have a direct line to us right here! Additional Branding and Trademark Information Ninja Forms&reg; is a registered trademark of Saturday Drive INC. We are a WordPress forms or WP forms builder, not to be confused with the independent WPForms brand for WordPress. All official Ninja Forms add-ons and memberships can be found on our official website, ninjaforms.com.

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C