CVE-2024-26019Cross-site Scripting in Ninja Forms

Severity
5.4MEDIUMNVD
EPSS
0.4%
top 41.74%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 11

Description

Ninja Forms prior to 3.8.1 contains a cross-site scripting vulnerability in submit processing. If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user who is accessing to the website using the product.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:NExploitability: 2.3 | Impact: 2.7

Affected Packages2 packages

CVEListV5saturday_drive/ninja_formsprior to 3.8.1

🔴Vulnerability Details

2
CVEList
CVE-2024-26019: Ninja Forms prior to 32024-04-11
GHSA
GHSA-p5g2-89mm-prg6: Ninja Forms prior to 32024-04-11
CVE-2024-26019 — Cross-site Scripting in Ninja Forms | cvebase