CVE-2018-19287

XSS in the Ninja Forms plugin before 3.3.18 for WordPress allows Remote Attackers to execute JavaScript via the includes/Admin/Menus/Submissions.php (aka submissions page) begin_date, end_date, or form_id parameter.


We have discovered 7,763 live websites that are affected by CVE-2018-19287.

Test my site




Affected Software

Product  Ninja Forms
Category Form Builders
Vulnerable Domains7,763 live websites (5.37% of Ninja Forms install base)
Vulnerable Versions
  • from 0 before 3.3.18
Vulnerable Versions Count138 versions ( 50.00% of all versions)



Details

  • Published - Nov 15, 2018
  • Updated - Aug 5, 2024

CVE-2018-19287 usage by Country

United States4,394 websites



Germany479 websites
France325 websites
GB322 websites
Australia182 websites
Netherlands163 websites
Spain152 websites
Italy119 websites
Canada117 websites
Russia116 websites

CVE-2018-19287 usage by TLD

.com4,009 websites
.org707 websites
.co.uk265 websites
.com.au260 websites
.net196 websites
.de175 websites
.nl149 websites
.ca136 websites
.fr100 websites
.ru92 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2018-19287

Top websites that are affected by CVE-2018-19287. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
********.com United States***,***
***********.com United States***,***
*******.com GB***,***
**********.**************.fr France***,***
*********.jp Japan***,***
*************************.org United States***,***
******.com United States***,***
****************.cl United States***,***
************************.org United States***,***
**********.com Nigeria***,***
See full domain list

FAQ

A total of 7,763 websites have been identified as vulnerable to CVE-2018-19287, discovered through global website indexing conducted by WebTechSurvey.
Ninja Forms is susceptible to CVE-2018-19287 vulnerability.
Ninja Forms versions before 3.3.18 are vulnerable to CVE-2018-19287.
Version 3.3.18 of Ninja Forms addresses the CVE-2018-19287 security vulnerability.