Page 6 of 37 results (0.035 seconds)

CVSS: 6.1EPSS: 0%CPEs: 1EXPL: 0

The ninja-forms plugin before 3.4.24.2 for WordPress allows CSRF with resultant XSS. El plugin ninja-forms versiones anteriores a 3.4.24.2 para WordPress, permite un ataque de tipo CSRF con un XSS resultante. The Ninja Forms plugin before 3.4.24.2 for WordPress allows CSRF with resultant XSS. • https://wordpress.org/plugins/ninja-forms/#developers • CWE-352: Cross-Site Request Forgery (CSRF) •

CVSS: 6.1EPSS: 0%CPEs: 1EXPL: 1

An open redirect in the Ninja Forms plugin before 3.3.19.1 for WordPress allows Remote Attackers to redirect a user via the lib/StepProcessing/step-processing.php (aka submissions download page) redirect parameter. Una redirección abierta en el plugin Ninja Forms en versiones anteriores a la 3.3.19.1 para WordPress permite que los atacantes remotos redirijan a un usuario mediante el parámetro redirect en lib/StepProcessing/step-processing.php (también conocido como submissions download page). • https://plugins.trac.wordpress.org/changeset/1982808/ninja-forms/trunk/lib/StepProcessing/step-processing.php https://wordpress.org/plugins/ninja-forms/#developers https://wpvulndb.com/vulnerabilities/9154 • CWE-601: URL Redirection to Untrusted Site ('Open Redirect') •

CVSS: 6.1EPSS: 22%CPEs: 1EXPL: 1

XSS in the Ninja Forms plugin before 3.3.18 for WordPress allows Remote Attackers to execute JavaScript via the includes/Admin/Menus/Submissions.php (aka submissions page) begin_date, end_date, or form_id parameter. Cross-Site Scripting (XSS) en el plugin Ninja Forms en versiones anteriores a la 3.3.18 para WordPress permite que atacantes remotos ejecuten JavaScript mediante los parámetros begin_date, end_date o form_id en includes/Admin/Menus/Submissions.php (también conocida como página submissions). WordPress Ninja Forms version 3.3.17 suffers from a cross site scripting vulnerability. • https://www.exploit-db.com/exploits/45880 https://plugins.trac.wordpress.org/changeset/1974335/ninja-forms/trunk/includes/Admin/Menus/Submissions.php https://wordpress.org/plugins/ninja-forms/#developers • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 8.6EPSS: 0%CPEs: 1EXPL: 2

The Ninja Forms plugin before 3.3.14.1 for WordPress allows CSV injection. El plugin Ninja Forms en versiones anteriores a la 3.3.14.1 para WordPress permite la inyección CSV. • https://packetstormsecurity.com/files/148993/WordPress-Ninja-Forms-3.3.13-CSV-Injection.html https://wordpress.org/plugins/ninja-forms/#developers https://www.exploit-db.com/exploits/45234 • CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') CWE-1236: Improper Neutralization of Formula Elements in a CSV File •

CVSS: 9.1EPSS: 0%CPEs: 1EXPL: 0

The ninja-forms plugin before 3.3.9 for WordPress has insufficient restrictions on submission-data retrieval during Export Personal Data requests. El plugin ninja-forms versiones anteriores a 3.3.9 para WordPress, presenta restricciones insuficientes sobre la recuperación de datos de envío durante las peticiones de Exportación de Datos Personales. • https://wordpress.org/plugins/ninja-forms/#developers • CWE-20: Improper Input Validation •