
株式会社mgn@mgn_jpn
🚨 Ninja Forms に脆弱性(深刻度 高) 60万サイト以上が利用 / CVSS 7.2 修正版 3.15.4 が公開済み https://shindan.m-g-n.me/alerts/cve-2026-94504/
000001.9K
270 followersView on X
Signal is active with 1 mentions in latest observed window
Recommended action window: Monitor and triage in normal cycle
NVD description
Ninja Forms 3.15.3 stores an anonymous non-RTE textarea value and renders it without safe HTML encoding in the legacy submission editor. An attacker can break out of the textarea with stored script. When an Administrator opens the attacker-known direct submission URL, the script runs in the WordPress admin origin.
Priority
LOW
Exploitation
NONE
PoC
NONE
Patch
NONE
Momentum
NONE

🚨 Ninja Forms に脆弱性(深刻度 高) 60万サイト以上が利用 / CVSS 7.2 修正版 3.15.4 が公開済み https://shindan.m-g-n.me/alerts/cve-2026-94504/