Ninja Forms 漏洞列表
共找到 10 个与 Ninja Forms 相关的漏洞
📅 加载漏洞趋势中...
-
CVE-2018-19287: WordPress Ninja Forms <3.3.18 - Cross-Site Scripting POC
WordPress Ninja Forms plugin before 3.3.18 contains a cross-site scripting vulnerability. An attacker can inject arbitrary script in includes/Admin/Menus/Submissions.php via the begin_date, end_date, or form_id parameters. This can allow an attacker to steal cookie-based authentication credentials and launch other attacks. -
CVE-2021-24165: WordPress Ninja Forms <3.4.34 - Open Redirect POC
WordPress Ninja Forms plugin before 3.4.34 contains an open redirect vulnerability via the wp_ajax_nf_oauth_connect AJAX action, due to the use of a user-supplied redirect parameter and no protection in place. An attacker can redirect a user to a malicious site and possibly obtain sensitive information, modify data, and/or execute unauthorized operations. -
CVE-2023-1835: Ninja Forms < 3.6.22 - Cross-Site Scripting POC
Ninja Forms before 3.6.22 is susceptible to cross-site scripting via the page parameter due to insufficient input sanitization and output escaping. An attacker can inject arbitrary script in the browser of an unsuspecting user in the context of the affected site. This can allow the attacker to steal cookie-based authentication credentials and launch other attacks. -
CVE-2023-37979: Ninja Forms < 3.6.26 - Cross-Site Scripting POC
The plugin does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin -
CVE-2018-19287: WordPress Ninja Forms <3.3.18 - Cross-Site Scripting POC
WordPress Ninja Forms plugin before 3.3.18 contains a cross-site scripting vulnerability. An attacker can inject arbitrary script in includes/Admin/Menus/Submissions.php via the begin_date, end_date, or form_id parameters. This can allow an attacker to steal cookie-based authentication credentials and launch other attacks. -
CVE-2021-24165: WordPress Ninja Forms <3.4.34 - Open Redirect POC
WordPress Ninja Forms plugin before 3.4.34 contains an open redirect vulnerability via the wp_ajax_nf_oauth_connect AJAX action, due to the use of a user-supplied redirect parameter and no protection in place. An attacker can redirect a user to a malicious site and possibly obtain sensitive information, modify data, and/or execute unauthorized operations. -
CVE-2023-1835: Ninja Forms < 3.6.22 - Cross-Site Scripting POC
Ninja Forms before 3.6.22 is susceptible to cross-site scripting via the page parameter due to insufficient input sanitization and output escaping. An attacker can inject arbitrary script in the browser of an unsuspecting user in the context of the affected site. This can allow the attacker to steal cookie-based authentication credentials and launch other attacks. -
CVE-2023-37979: Ninja Forms < 3.6.26 - Cross-Site Scripting POC
The plugin does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin -
ninja-forms-xss: Ninja Forms < 3.5.5 - Cross-Site Scripting POC
The Ninja Forms WordPress plugin before 3.5.5 does not escape an URL before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin -
WordPress plugin Ninja Forms 代码注入漏洞 无POC
WordPress和WordPress plugin都是WordPress基金会的产品。WordPress是一套使用PHP语言开发的博客平台。该平台支持在PHP和MySQL的服务器上架设个人博客网站。WordPress plugin是一个应用插件。 WordPress plugin Ninja Forms 3.8.22及之前版本存在代码注入漏洞,该漏洞源于软件在运行do_shortcode之前未正确验证值,允许具有Subscriber级别及以上访问权限的认证攻击者执行任意shortcode。