CVE-2018-19287

MEDIUM NUCLEI

Ninja Forms <3.3.18 - XSS

Title source: llm

Description

XSS in the Ninja Forms plugin before 3.3.18 for WordPress allows Remote Attackers to execute JavaScript via the includes/Admin/Menus/Submissions.php (aka submissions page) begin_date, end_date, or form_id parameter.

Exploits (1)

exploitdb WORKING POC
by MTK · textwebappsphp
https://www.exploit-db.com/exploits/45880

Nuclei Templates (1)

WordPress Ninja Forms <3.3.18 - Cross-Site Scripting
MEDIUMVERIFIEDby theamanrawat
Shodan: http.html:/wp-content/plugins/ninja-forms/
FOFA: body=/wp-content/plugins/ninja-forms/

Scores

CVSS v3 6.1
EPSS 0.1222
EPSS Percentile 93.9%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Details

CWE
CWE-79
Status published
Products (1)
ninjaforma/ninja_forms < 3.3.18
Published Nov 15, 2018
Tracked Since Feb 18, 2026