CVE Database /
CVE-2020-36173
CVE · Medium
CVE-2020-36173 — Ninja Forms – The Contact Form Builder That Grows With You [ninja-forms] < 3.4.28
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2020-36173
|
Ninja Forms – The Contact Form Builder That Grows With You [ninja-forms] < 3.4.28 |
Improper Encoding or Escaping of Output |
Medium
5.3
|
< 3.4.28
|
3.4.28 |
2020-09-20 |
—
|
CVE-2020-36173
The plugin failed to properly sanitize user-submitted HTML content stored in the submissions table, potentially allowing malicious scripts to be injected and executed on user's browsers, leading to cross-site scripting vulnerabilities.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings