2019-08-22 15:15:12 2019-08-26 18:36:16

The ninja-forms plugin before 3.0.31 for WordPress has insufficient HTML escaping in the builder.

Vector

NETWORK

Complexity

MEDIUM

Authentication

NONE

Confidentiality

NONE

Integrity

PARTIAL

Availability

NONE
Ninjaforms Ninja forms 2.2.6 ~~~wordpress~~ (not an official CPE) Ninjaforms Ninja forms 2.2.7 ~~~wordpress~~ (not an official CPE) Ninjaforms Ninja forms 2.2.31 ~~~wordpress~~ (not an official CPE) Ninjaforms Ninja forms 2.2.33 ~~~wordpress~~ (not an official CPE) Ninjaforms Ninja forms 2.2.34 ~~~wordpress~~ (not an official CPE) Ninjaforms Ninja forms 2.2.35 ~~~wordpress~~ (not an official CPE) Ninjaforms Ninja forms 2.2.36 ~~~wordpress~~ (not an official CPE) Ninjaforms Ninja forms 2.2.37 ~~~wordpress~~ (not an official CPE) Ninjaforms Ninja forms 2.2.39 ~~~wordpress~~ (not an official CPE) Ninjaforms Ninja forms 2.2.40 ~~~wordpress~~ (not an official CPE) Ninjaforms Ninja forms 2.2.41 ~~~wordpress~~ (not an official CPE) Ninjaforms Ninja forms 2.2.43 ~~~wordpress~~ (not an official CPE) Ninjaforms Ninja forms 2.2.45 ~~~wordpress~~ (not an official CPE) Ninjaforms Ninja forms 2.2.46 ~~~wordpress~~ (not an official CPE) Ninjaforms Ninja forms 2.2.47 ~~~wordpress~~ (not an official CPE) Ninjaforms Ninja forms 2.2.48 ~~~wordpress~~ (not an official CPE) Ninjaforms Ninja forms 2.2.49 ~~~wordpress~~ (not an official CPE) Ninjaforms Ninja forms 2.2.50 ~~~wordpress~~ (not an official CPE) Ninjaforms Ninja forms 2.2.51 ~~~wordpress~~ (not an official CPE) Ninjaforms Ninja forms 2.2.52 ~~~wordpress~~ (not an official CPE) Ninjaforms Ninja forms 2.2.53 ~~~wordpress~~ (not an official CPE) Ninjaforms Ninja forms 2.2.54 ~~~wordpress~~ (not an official CPE) Ninjaforms Ninja forms 2.2.55 ~~~wordpress~~ (not an official CPE) Ninjaforms Ninja forms 2.3 ~~~wordpress~~ (not an official CPE) Ninjaforms Ninja forms 2.3.1 ~~~wordpress~~ (not an official CPE) Ninjaforms Ninja forms 2.3.2 ~~~wordpress~~ (not an official CPE) Ninjaforms Ninja forms 2.3.3 ~~~wordpress~~ (not an official CPE) Ninjaforms Ninja forms 2.3.4 ~~~wordpress~~ (not an official CPE) Ninjaforms Ninja forms 2.3.5 ~~~wordpress~~ (not an official CPE) Ninjaforms Ninja forms 2.3.6 ~~~wordpress~~ (not an official CPE) Ninjaforms Ninja forms 2.3.7 ~~~wordpress~~ (not an official CPE) Ninjaforms Ninja forms 2.3.8 ~~~wordpress~~ (not an official CPE) Ninjaforms Ninja forms 2.4 ~~~wordpress~~ (not an official CPE) Ninjaforms Ninja forms 2.4.1 ~~~wordpress~~ (not an official CPE) Ninjaforms Ninja forms 2.4.2 ~~~wordpress~~ (not an official CPE) Ninjaforms Ninja forms 2.5 ~~~wordpress~~ (not an official CPE) Ninjaforms Ninja forms 2.5.1 ~~~wordpress~~ (not an official CPE) Ninjaforms Ninja forms 2.5.2 ~~~wordpress~~ (not an official CPE) Ninjaforms Ninja forms 2.5.3 ~~~wordpress~~ (not an official CPE) Ninjaforms Ninja forms 2.6 ~~~wordpress~~ (not an official CPE) Ninjaforms Ninja forms 2.6.1 ~~~wordpress~~ (not an official CPE) Ninjaforms Ninja forms 2.6.2 ~~~wordpress~~ (not an official CPE) Ninjaforms Ninja forms 2.6.3 ~~~wordpress~~ (not an official CPE) Ninjaforms Ninja forms 2.6.4 ~~~wordpress~~ (not an official CPE) Ninjaforms Ninja forms 2.6.5 ~~~wordpress~~ (not an official CPE) Ninjaforms Ninja forms 2.7 ~~~wordpress~~ (not an official CPE) Ninjaforms Ninja forms 2.7.1 ~~~wordpress~~ (not an official CPE) Ninjaforms Ninja forms 2.7.2 ~~~wordpress~~ (not an official CPE) Ninjaforms Ninja forms 2.7.3 ~~~wordpress~~ (not an official CPE) Ninjaforms Ninja forms 2.7.4 ~~~wordpress~~ (not an official CPE) Ninjaforms Ninja forms 2.7.5 ~~~wordpress~~ (not an official CPE) Ninjaforms Ninja forms 2.7.6 ~~~wordpress~~ (not an official CPE) Ninjaforms Ninja forms 2.7.7 ~~~wordpress~~ (not an official CPE) Ninjaforms Ninja forms 2.8 ~~~wordpress~~ (not an official CPE) Ninjaforms Ninja forms 2.8.1 ~~~wordpress~~ (not an official CPE) Ninjaforms Ninja forms 2.8.2 ~~~wordpress~~ (not an official CPE) Ninjaforms Ninja forms 2.8.3 ~~~wordpress~~ (not an official CPE) Ninjaforms Ninja forms 2.8.4 ~~~wordpress~~ (not an official CPE) Ninjaforms Ninja forms 2.8.5 ~~~wordpress~~ (not an official CPE) Ninjaforms Ninja forms 2.8.6 ~~~wordpress~~ (not an official CPE) Ninjaforms Ninja forms 2.8.7 ~~~wordpress~~ (not an official CPE) NinjaForms Ninja Forms for WordPress 2.8.8 NinjaForms Ninja Forms for WordPress 2.8.9 Ninjaforms Ninja forms 2.8.10 ~~~wordpress~~ (not an official CPE) Ninjaforms Ninja forms 2.8.11 ~~~wordpress~~ (not an official CPE) Ninjaforms Ninja forms 2.8.12 ~~~wordpress~~ (not an official CPE) Ninjaforms Ninja forms 2.8.13 ~~~wordpress~~ (not an official CPE) Ninjaforms Ninja forms 2.9 ~~~wordpress~~ (not an official CPE) Ninjaforms Ninja forms 2.9.1 ~~~wordpress~~ (not an official CPE) Ninjaforms Ninja forms 2.9.2 ~~~wordpress~~ (not an official CPE) Ninjaforms Ninja forms 2.9.3 ~~~wordpress~~ (not an official CPE) Ninjaforms Ninja forms 2.9.4 ~~~wordpress~~ (not an official CPE) Ninjaforms Ninja forms 2.9.5 ~~~wordpress~~ (not an official CPE) Ninjaforms Ninja forms 2.9.6 ~~~wordpress~~ (not an official CPE) Ninjaforms Ninja forms 2.9.7 ~~~wordpress~~ (not an official CPE) Ninjaforms Ninja forms 2.9.8 ~~~wordpress~~ (not an official CPE) Ninjaforms Ninja forms 2.9.9 ~~~wordpress~~ (not an official CPE) Ninjaforms Ninja forms 2.9.10 ~~~wordpress~~ (not an official CPE) Ninjaforms Ninja forms 2.9.11 ~~~wordpress~~ (not an official CPE) Ninjaforms Ninja forms 2.9.12 ~~~wordpress~~ (not an official CPE) Ninjaforms Ninja forms 2.9.13 ~~~wordpress~~ (not an official CPE) Ninjaforms Ninja forms 2.9.14 ~~~wordpress~~ (not an official CPE) Ninjaforms Ninja forms 2.9.15 ~~~wordpress~~ (not an official CPE) Ninjaforms Ninja forms 2.9.16 ~~~wordpress~~ (not an official CPE) Ninjaforms Ninja forms 2.9.17 ~~~wordpress~~ (not an official CPE) Ninjaforms Ninja forms 2.9.18 ~~~wordpress~~ (not an official CPE) Ninjaforms Ninja forms 2.9.19 ~~~wordpress~~ (not an official CPE) Ninjaforms Ninja forms 2.9.20 ~~~wordpress~~ (not an official CPE) Ninjaforms Ninja forms 2.9.21 ~~~wordpress~~ (not an official CPE) Ninjaforms Ninja forms 2.9.22 ~~~wordpress~~ (not an official CPE) Ninjaforms Ninja forms 2.9.23 ~~~wordpress~~ (not an official CPE) Ninjaforms Ninja forms 2.9.24 ~~~wordpress~~ (not an official CPE) Ninjaforms Ninja forms 2.9.25 ~~~wordpress~~ (not an official CPE) Ninjaforms Ninja forms 2.9.26 ~~~wordpress~~ (not an official CPE) Ninjaforms Ninja forms 2.9.27 ~~~wordpress~~ (not an official CPE) Ninjaforms Ninja forms 2.9.28 ~~~wordpress~~ (not an official CPE) Ninjaforms Ninja forms 2.9.29 ~~~wordpress~~ (not an official CPE) Ninjaforms Ninja forms 2.9.30 ~~~wordpress~~ (not an official CPE) Ninjaforms Ninja forms 2.9.31 ~~~wordpress~~ (not an official CPE) Ninjaforms Ninja forms 2.9.32 ~~~wordpress~~ (not an official CPE) Ninjaforms Ninja forms 2.9.33 ~~~wordpress~~ (not an official CPE) Ninjaforms Ninja forms 2.9.34 ~~~wordpress~~ (not an official CPE) Ninjaforms Ninja forms 2.9.35 ~~~wordpress~~ (not an official CPE) Ninjaforms Ninja forms 2.9.36 ~~~wordpress~~ (not an official CPE) Ninjaforms Ninja forms 2.9.37 ~~~wordpress~~ (not an official CPE) Ninjaforms Ninja forms 2.9.38 ~~~wordpress~~ (not an official CPE) Ninjaforms Ninja forms 2.9.39 ~~~wordpress~~ (not an official CPE) Ninjaforms Ninja forms 2.9.40 ~~~wordpress~~ (not an official CPE) Ninjaforms Ninja forms 2.9.41 ~~~wordpress~~ (not an official CPE) Ninjaforms Ninja forms 2.9.42 ~~~wordpress~~ (not an official CPE) Ninjaforms Ninja forms 2.9.43 ~~~wordpress~~ (not an official CPE) Ninjaforms Ninja forms 2.9.44 ~~~wordpress~~ (not an official CPE) Ninjaforms Ninja forms 2.9.45 ~~~wordpress~~ (not an official CPE) Ninjaforms Ninja forms 2.9.46 ~~~wordpress~~ (not an official CPE) Ninjaforms Ninja forms 2.9.47 ~~~wordpress~~ (not an official CPE) Ninjaforms Ninja forms 2.9.48 ~~~wordpress~~ (not an official CPE) Ninjaforms Ninja forms 2.9.49 ~~~wordpress~~ (not an official CPE) Ninjaforms Ninja forms 2.9.50 ~~~wordpress~~ (not an official CPE) Ninjaforms Ninja forms 2.9.51 ~~~wordpress~~ (not an official CPE) Ninjaforms Ninja forms 2.9.52 ~~~wordpress~~ (not an official CPE) Ninjaforms Ninja forms 2.9.53 ~~~wordpress~~ (not an official CPE) Ninjaforms Ninja forms 2.9.54 ~~~wordpress~~ (not an official CPE) Ninjaforms Ninja forms 2.9.55 ~~~wordpress~~ (not an official CPE) Ninjaforms Ninja forms 2.9.55.1 ~~~wordpress~~ (not an official CPE) Ninjaforms Ninja forms 2.9.55.2 ~~~wordpress~~ (not an official CPE) Ninjaforms Ninja forms 2.9.56 ~~~wordpress~~ (not an official CPE) Ninjaforms Ninja forms 2.9.56.1 ~~~wordpress~~ (not an official CPE) Ninjaforms Ninja forms 2.9.56.2 ~~~wordpress~~ (not an official CPE) Ninjaforms Ninja forms 2.9.57 ~~~wordpress~~ (not an official CPE) Ninjaforms Ninja forms 2.9.58 ~~~wordpress~~ (not an official CPE) Ninjaforms Ninja forms 3.0 ~~~wordpress~~ (not an official CPE) Ninjaforms Ninja forms 3.0.1 ~~~wordpress~~ (not an official CPE) Ninjaforms Ninja forms 3.0.2 ~~~wordpress~~ (not an official CPE) Ninjaforms Ninja forms 3.0.3 ~~~wordpress~~ (not an official CPE) Ninjaforms Ninja forms 3.0.4 ~~~wordpress~~ (not an official CPE) Ninjaforms Ninja forms 3.0.5 ~~~wordpress~~ (not an official CPE) Ninjaforms Ninja forms 3.0.6 ~~~wordpress~~ (not an official CPE) Ninjaforms Ninja forms 3.0.7 ~~~wordpress~~ (not an official CPE) Ninjaforms Ninja forms 3.0.8 ~~~wordpress~~ (not an official CPE) Ninjaforms Ninja forms 3.0.9 ~~~wordpress~~ (not an official CPE) Ninjaforms Ninja forms 3.0.10 ~~~wordpress~~ (not an official CPE) Ninjaforms Ninja forms 3.0.11 ~~~wordpress~~ (not an official CPE) Ninjaforms Ninja forms 3.0.12 ~~~wordpress~~ (not an official CPE) Ninjaforms Ninja forms 3.0.12 Beta ~~~wordpress~~ (not an official CPE) Ninjaforms Ninja forms 3.0.13 ~~~wordpress~~ (not an official CPE) Ninjaforms Ninja forms 3.0.14 ~~~wordpress~~ (not an official CPE) Ninjaforms Ninja forms 3.0.15 ~~~wordpress~~ (not an official CPE) Ninjaforms Ninja forms 3.0.16 ~~~wordpress~~ (not an official CPE) Ninjaforms Ninja forms 3.0.17 ~~~wordpress~~ (not an official CPE) Ninjaforms Ninja forms 3.0.18 ~~~wordpress~~ (not an official CPE) Ninjaforms Ninja forms 3.0.19 ~~~wordpress~~ (not an official CPE) Ninjaforms Ninja forms 3.0.20 ~~~wordpress~~ (not an official CPE) Ninjaforms Ninja forms 3.0.21 ~~~wordpress~~ (not an official CPE) Ninjaforms Ninja forms 3.0.22 ~~~wordpress~~ (not an official CPE) Ninjaforms Ninja forms 3.0.23 ~~~wordpress~~ (not an official CPE) Ninjaforms Ninja forms 3.0.24 ~~~wordpress~~ (not an official CPE) Ninjaforms Ninja forms 3.0.25 ~~~wordpress~~ (not an official CPE) Ninjaforms Ninja forms 3.0.26 ~~~wordpress~~ (not an official CPE) Ninjaforms Ninja forms 3.0.27 ~~~wordpress~~ (not an official CPE) Ninjaforms Ninja forms 3.0.28 ~~~wordpress~~ (not an official CPE) Ninjaforms Ninja forms 3.0.29 ~~~wordpress~~ (not an official CPE) Ninjaforms Ninja forms 3.0.30 ~~~wordpress~~ (not an official CPE)

Improper Input Validation (ID 20)

Related CAPEC 58 Buffer Overflow via Environment Variables (CAPEC-ID 10) Server Side Include (SSI) Injection (CAPEC-ID 101) Cross Zone Scripting (CAPEC-ID 104) Cross Site Scripting through Log Files (CAPEC-ID 106) Command Line Execution through SQL Injection (CAPEC-ID 108) Object Relational Mapping Injection (CAPEC-ID 109) SQL Injection through SOAP Parameter Tampering (CAPEC-ID 110) Subverting Environment Variable Values (CAPEC-ID 13) Format String Injection (CAPEC-ID 135) LDAP Injection (CAPEC-ID 136) Relative Path Traversal (CAPEC-ID 139) Client-side Injection-induced Buffer Overflow (CAPEC-ID 14) Variable Manipulation (CAPEC-ID 171) Embedding Scripts in Non-Script Elements (CAPEC-ID 18) Flash Injection (CAPEC-ID 182) Cross-Site Scripting Using Alternate Syntax (CAPEC-ID 199) Exploiting Trust in Client (aka Make the Client Invisible) (CAPEC-ID 22) XML Nested Payloads (CAPEC-ID 230) XML Oversized Payloads (CAPEC-ID 231) Filter Failure through Buffer Overflow (CAPEC-ID 24) Cross-Site Scripting via Encoded URI Schemes (CAPEC-ID 244) XML Injection (CAPEC-ID 250) Environment Variable Manipulation (CAPEC-ID 264) Global variable manipulation (CAPEC-ID 265) Leverage Alternate Encoding (CAPEC-ID 267) Fuzzing (CAPEC-ID 28) Using Leading 'Ghost' Character Sequences to Bypass Input Filters (CAPEC-ID 3) Accessing/Intercepting/Modifying HTTP Cookies (CAPEC-ID 31) Embedding Scripts in HTTP Query Strings (CAPEC-ID 32) MIME Conversion (CAPEC-ID 42) Exploiting Multiple Input Interpretation Layers (CAPEC-ID 43) Buffer Overflow via Symbolic Links (CAPEC-ID 45) Overflow Variables and Tags (CAPEC-ID 46) Buffer Overflow via Parameter Expansion (CAPEC-ID 47) Signature Spoof (CAPEC-ID 473) XML Client-Side Attack (CAPEC-ID 484) Embedding NULL Bytes (CAPEC-ID 52) Postfix, Null Terminate, and Backslash (CAPEC-ID 53) Simple Script Injection (CAPEC-ID 63) Using Slashes and URL Encoding Combined to Bypass Validation Logic (CAPEC-ID 64) SQL Injection (CAPEC-ID 66) String Format Overflow in syslog() (CAPEC-ID 67) Blind SQL Injection (CAPEC-ID 7) Using Unicode Encoding to Bypass Validation Logic (CAPEC-ID 71) URL Encoding (CAPEC-ID 72) User-Controlled Filename (CAPEC-ID 73) Using Escaped Slashes in Alternate Encoding (CAPEC-ID 78) Using Slashes in Alternate Encoding (CAPEC-ID 79) Buffer Overflow in an API Call (CAPEC-ID 8) Using UTF-8 Encoding to Bypass Validation Logic (CAPEC-ID 80) Web Logs Tampering (CAPEC-ID 81) XPath Injection (CAPEC-ID 83) AJAX Fingerprinting (CAPEC-ID 85) Embedding Script (XSS) in HTTP Headers (CAPEC-ID 86) OS Command Injection (CAPEC-ID 88) Buffer Overflow in Local Command-Line Utilities (CAPEC-ID 9) XSS in IMG Tags (CAPEC-ID 91) XML Parser Attack (CAPEC-ID 99)