Page 6 of 34 results (0.008 seconds)

CVSS: 6.1EPSS: 0%CPEs: 1EXPL: 1

An open redirect in the Ninja Forms plugin before 3.3.19.1 for WordPress allows Remote Attackers to redirect a user via the lib/StepProcessing/step-processing.php (aka submissions download page) redirect parameter. Una redirección abierta en el plugin Ninja Forms en versiones anteriores a la 3.3.19.1 para WordPress permite que los atacantes remotos redirijan a un usuario mediante el parámetro redirect en lib/StepProcessing/step-processing.php (también conocido como submissions download page). • https://plugins.trac.wordpress.org/changeset/1982808/ninja-forms/trunk/lib/StepProcessing/step-processing.php https://wordpress.org/plugins/ninja-forms/#developers https://wpvulndb.com/vulnerabilities/9154 • CWE-601: URL Redirection to Untrusted Site ('Open Redirect') •

CVSS: 8.6EPSS: 0%CPEs: 1EXPL: 2

The Ninja Forms plugin before 3.3.14.1 for WordPress allows CSV injection. El plugin Ninja Forms en versiones anteriores a la 3.3.14.1 para WordPress permite la inyección CSV. • https://packetstormsecurity.com/files/148993/WordPress-Ninja-Forms-3.3.13-CSV-Injection.html https://wordpress.org/plugins/ninja-forms/#developers https://www.exploit-db.com/exploits/45234 • CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') CWE-1236: Improper Neutralization of Formula Elements in a CSV File •

CVSS: 9.1EPSS: 0%CPEs: 1EXPL: 0

The ninja-forms plugin before 3.3.9 for WordPress has insufficient restrictions on submission-data retrieval during Export Personal Data requests. El plugin ninja-forms versiones anteriores a 3.3.9 para WordPress, presenta restricciones insuficientes sobre la recuperación de datos de envío durante las peticiones de Exportación de Datos Personales. • https://wordpress.org/plugins/ninja-forms/#developers • CWE-20: Improper Input Validation •

CVSS: 7.5EPSS: 0%CPEs: 1EXPL: 0

The ninja-forms plugin before 3.2.15 for WordPress has parameter tampering. El plugin ninja-forms versiones anteriores a 3.2.15 para WordPress, presenta una manipulación de parámetros. • https://wordpress.org/plugins/ninja-forms/#developers • CWE-20: Improper Input Validation •

CVSS: 6.1EPSS: 0%CPEs: 1EXPL: 0

The Ninja Forms plugin before 3.2.14 for WordPress has XSS. El plugin Ninja Forms en versiones anteriores a la 3.2.14 para WordPress tiene Cross-Site Scripting (XSS). • https://wordpress.org/plugins/ninja-forms/#developers • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •