XSS in the Ninja Forms plugin before 3.3.18 for WordPress allows Remote Attackers to execute JavaScript via the includes/Admin/Menus/Submissions.php (aka submissions page) begin_date, end_date, or form_id parameter.
We have discovered 7,763 live websites that are affected by CVE-2018-19287.
Product | |
Category | Form Builders |
Vulnerable Domains | 7,763 live websites (5.37% of Ninja Forms install base) |
Vulnerable Versions |
|
Vulnerable Versions Count | 138 versions ( 50.00% of all versions) |
![]() | 4,394 websites |
![]() | 479 websites |
![]() | 325 websites |
![]() | 322 websites |
![]() | 182 websites |
![]() | 163 websites |
![]() | 152 websites |
![]() | 119 websites |
![]() | 117 websites |
![]() | 116 websites |
.com | 4,009 websites |
.org | 707 websites |
.co.uk | 265 websites |
.com.au | 260 websites |
.net | 196 websites |
.de | 175 websites |
.nl | 149 websites |
.ca | 136 websites |
.fr | 100 websites |
.ru | 92 websites |
Domain | Country | Rank | Contacts |
---|---|---|---|
********.com | ![]() | ***,*** | |
***********.com | ![]() | ***,*** | |
*******.com | ![]() | ***,*** | |
**********.**************.fr | ![]() | ***,*** | |
*********.jp | ![]() | ***,*** | |
*************************.org | ![]() | ***,*** | |
******.com | ![]() | ***,*** | |
****************.cl | ![]() | ***,*** | |
************************.org | ![]() | ***,*** | |
**********.com | ![]() | ***,*** |
FAQ