CVE-2026-15663

Ninja Forms <= 3.14.9 - Authenticated (Administrator+) SQL Injection via Import File 'settings' Key

The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to generic SQL Injection via Import File 'settings' Key in all versions up to, and including, 3.14.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with administrator-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. The vulnerable keys originate from the 'settings' object in an attacker-controlled import file processed via file_get_contents() or base64-decoded/JSON-decoded blobs, bypassing wp_magic_quotes protections entirely; two distinct sinks are affected — _save_setting() in Model.php and insert_form_meta() in ImportForm.php — as only the value side is escaped while the key side receives no sanitization or parameterization at any point in the call chain.


We have discovered 128,705 live websites that are affected by CVE-2026-15663.

Run a Free Instant Scan




Affected Software

Product  Ninja Forms
Category Form Builders
Vulnerable Domains128,705 live websites (100% of Ninja Forms install base)
Vulnerable Versions
  • from 0 through 3.14.9
Vulnerable Versions Count238 versions ( 100% of all versions)


Common Weakness Enumeration

CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')



Details

  • Published - Jul 24, 2026
  • Updated - Jul 24, 2026

Credits

  • Wordfence PRISM (finder)

Website Distribution by Country

Number of websites using CVE-2026-15663
United States57,589 websites



Germany11,974 websites
GB8,890 websites
France6,767 websites
Netherlands5,331 websites
Canada3,881 websites
Australia3,531 websites
Italy2,891 websites
Spain2,567 websites
Switzerland2,181 websites

Website Distribution by TLD

Number of websites using CVE-2026-15663
.com62,783 websites
.org8,821 websites
.de7,763 websites
.co.uk5,994 websites
.nl4,889 websites
.com.au3,236 websites
.fr3,191 websites
.net2,769 websites
.ca2,270 websites
.it1,924 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-15663

Top websites that are affected by CVE-2026-15663. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
****.com United States***
****.org United States*,***
****.ca United States*,***
**********.com United States*,***
***********.com United States*,***
****************.com United States*,***
***************.org GB*,***
****************.com United States*,***
**********.de Germany*,***
************.com United States**,***
See full domain list

FAQ

CVE-2026-15663 is Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in Ninja Forms
A total of 128,705 websites have been identified as vulnerable to CVE-2026-15663, based on global website indexing conducted by WebTechSurvey.
The Ninja Forms is affected by the CVE-2026-15663 vulnerability.
Ninja Forms versions up to and including 3.14.9 are vulnerable to CVE-2026-15663.