Ninja Forms - File Uploads

Ninja Forms - File Uploads has 9 disclosed vulnerabilities in the WordSec catalog, reported between 2019 and 2026; 7 are fixed and 2 remain unpatched as of September 2026. Their average CVSS score is 7.4, and the most serious one scores 9.8 out of 10. Severity breakdown: 2 critical and 5 high. 2026 was the busiest year with 5 disclosures.

The most common weakness is Cross-Site Scripting, behind 3 of the records (33%). Other recurring categories include Unrestricted Upload Of File With Dangerous Type, Cross-Site Request Forgery (CSRF).

7 of the records (78%) have a vendor fix, while 2 remain unpatched. The oldest unresolved one dates back to 2026.

9 independent researchers contributed these findings, one record each.

Strategic Overview

Avg CVSSHigh
7.4/ 10
Patch Coverage78%
Open

2

Fixed

7

Get automatic notifications for all Ninja Forms - File Uploads vulnerabilities before they are exploited.

Most severe open issueCVSS 7.2CVE-2026-81773

Ninja Forms - File Uploads <= 3.3.26 - Unauthenticated Stored Cross-Site Scripting

Read the full analysis

Vulnerability Records

9 records
2026-09-02 00:00CVE-2026-81773
7.2
High
Marc-André BeaulieuNo
2026-07-02 16:04CVE-2026-12557
5.3
Medium
Ad4m5Yes
2026-07-01 20:41CVE-2026-13369
7.5
High
darooYes
2026-04-08 00:00CVE-2026-57784
4.3
Medium
Marc-André Beaulieu (h3dg3h0g)No
2026-04-06 15:57CVE-2026-0740
9.8
Critical
Sélim Lanouar (whattheslime)Yes
2024-09-06 00:00CVE-2024-1596
7.2
High
wesley (wcraft)Yes
2021-11-20 00:00CVE-2022-0889
7.2
High
Nuno Correia (Blaze Security)Yes
2020-03-20 00:00CVE-2022-0888
9.8
Critical
Muhammad Zeeshan (Xib3rR4dAr)Yes
2019-04-11 00:00CVE-2019-10869
8.1
High
Jasper WeijtsYes
Showing 1–9 of 9 reports

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C