CVE-2026-65048

Ninja Forms Unauthenticated Stored Cross-Site Scripting via Repeatable Fieldset Submission Index

Ninja Forms plugin for WordPress versions 3.10.4 through 3.14.9 contains an unauthenticated stored cross-site scripting vulnerability in the Repeatable Fieldset feature where parseSubmissionIndex() accepts arbitrary strings as submission indexes without numeric validation, and admin_form_element() interpolates the index directly into HTML without escaping. An unauthenticated attacker can submit a public form with a crafted repeater child key containing malicious script payloads, which execute in an administrator's browser when viewing submissions in the WordPress admin panel, enabling session-cookie theft, creation of administrator accounts, installation of malicious plugins, and arbitrary modification of site content.


We have discovered 91,428 live websites that are affected by CVE-2026-65048.

Run a Free Instant Scan




Affected Software

Product  Ninja Forms
Category Form Builders
Vulnerable Domains91,428 live websites (72% of Ninja Forms install base)
Vulnerable Versions
  • from 3.10.4 through 3.14.9
Vulnerable Versions Count23 versions ( 9.66% of all versions)



Details

  • Published - Jul 21, 2026
  • Updated - Jul 22, 2026

Credits

  • Pavel Kohout, Aisle Research (finder)

Website Distribution by Country

Number of websites using CVE-2026-65048
United States43,360 websites



Germany8,676 websites
GB6,576 websites
France4,664 websites
Netherlands3,994 websites
Canada2,891 websites
Australia2,368 websites
Italy1,712 websites
Switzerland1,685 websites
Spain1,632 websites

Website Distribution by TLD

Number of websites using CVE-2026-65048
.com45,252 websites
.org6,827 websites
.de5,903 websites
.co.uk4,481 websites
.nl3,687 websites
.fr2,320 websites
.com.au2,180 websites
.net1,947 websites
.ca1,707 websites
.ch1,476 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-65048

Top websites that are affected by CVE-2026-65048. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
****.com United States***
****.org United States*,***
****.ca United States*,***
**********.com United States*,***
***********.com United States*,***
****************.com United States*,***
***************.org GB*,***
**********.de Germany*,***
*************.com Italy**,***
****************.com United States**,***
See full domain list

FAQ

A total of 91,428 websites have been identified as vulnerable to CVE-2026-65048, based on global website indexing conducted by WebTechSurvey.
The Ninja Forms is affected by the CVE-2026-65048 vulnerability.
Ninja Forms versions up to 3.14.9 are vulnerable to CVE-2026-65048.
CVE-2026-65048 is resolved in version 3.14.9 of Ninja Forms.