CVE-2024-29220Cross-site Scripting in Ninja Forms

Severity
6.1MEDIUMNVD
EPSS
0.3%
top 45.80%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 11

Description

Ninja Forms prior to 3.8.1 contains a cross-site scripting vulnerability in custom fields for labels. If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user who is accessing to the website using the product.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7

Affected Packages2 packages

CVEListV5saturday_drive/ninja_formsprior to 3.8.1

🔴Vulnerability Details

2
GHSA
GHSA-72h6-54fg-6qph: Ninja Forms prior to 32024-04-11
CVEList
CVE-2024-29220: Ninja Forms prior to 32024-04-11
CVE-2024-29220 — Cross-site Scripting in Ninja Forms | cvebase