CVE-2021-36827

WordPress Ninja Forms Contact Form plugin <= 3.6.9 - Authenticated Stored Cross-Site Scripting (XSS) vulnerability

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Saturday Drive's Ninja Forms Contact Form plugin <= 3.6.9 at WordPress via "label".


We have discovered 19,264 live websites that are affected by CVE-2021-36827.

Test my site




Affected Software

Product  Ninja Forms
Category Form Builders
Vulnerable Domains19,264 live websites (13.33% of Ninja Forms install base)
Vulnerable Versions
  • from 0 through 3.6.9
Vulnerable Versions Count211 versions ( 76.45% of all versions)


Common Weakness Enumeration

CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')



Details

  • Published - Jun 16, 2022
  • Updated - Sep 16, 2024

Credits

  • Asif Nawaz Minhas (Patchstack Alliance) (finder)

CVE-2021-36827 usage by Country

United States9,632 websites



Germany1,585 websites
France1,058 websites
GB914 websites
Australia498 websites
Netherlands476 websites
Spain393 websites
Canada326 websites
Italy290 websites
Poland272 websites

CVE-2021-36827 usage by TLD

.com9,964 websites
.org1,167 websites
.co.uk717 websites
.com.au648 websites
.de581 websites
.nl468 websites
.net429 websites
.fr329 websites
.ca319 websites
.it245 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2021-36827

Top websites that are affected by CVE-2021-36827. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
********.com United States**,***
*****************.de Germany**,***
***********.com United States**,***
***********.com United States**,***
********.com France***,***
***********************.com United States***,***
********.com United States***,***
*********.com United States***,***
********.com United States***,***
*******.com United States***,***
See full domain list

FAQ

CVE-2021-36827 is Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Ninja Forms
A total of 19,264 websites have been identified as vulnerable to CVE-2021-36827, discovered through global website indexing conducted by WebTechSurvey.
Ninja Forms is susceptible to CVE-2021-36827 vulnerability.
Ninja Forms versions before, and including, 3.6.9 are vulnerable to CVE-2021-36827.