CVE-2026-65051

Ninja Forms Server-Side Validation Bypass via Client-Controlled Field Metadata Merge in AJAX Submission Handler

Ninja Forms WordPress plugin version 3.14.8 contains a client-side enforcement of server-side security vulnerability that allows unauthenticated attackers to bypass all form validation by merging attacker-controlled field metadata over server-loaded form definitions before validation runs. Attackers can craft a malicious AJAX submission overriding field types, removing required flags, and disabling CAPTCHA checks through the nopriv AJAX endpoint to trigger form actions such as email notifications and database storage with unverified, attacker-controlled content.


We have discovered 128,705 live websites that are affected by CVE-2026-65051.

Run a Free Instant Scan




Affected Software

Product  Ninja Forms
Category Form Builders
Vulnerable Domains128,705 live websites (100% of Ninja Forms install base)
Vulnerable Versions
  • from 0 through 3.14.9
Vulnerable Versions Count238 versions ( 100% of all versions)



Details

  • Published - Jul 21, 2026
  • Updated - Jul 23, 2026

Credits

  • Pavel Kohout, Aisle Research (finder)

Website Distribution by Country

Number of websites using CVE-2026-65051
United States57,589 websites



Germany11,974 websites
GB8,890 websites
France6,767 websites
Netherlands5,331 websites
Canada3,881 websites
Australia3,531 websites
Italy2,891 websites
Spain2,567 websites
Switzerland2,181 websites

Website Distribution by TLD

Number of websites using CVE-2026-65051
.com62,783 websites
.org8,821 websites
.de7,763 websites
.co.uk5,994 websites
.nl4,889 websites
.com.au3,236 websites
.fr3,191 websites
.net2,769 websites
.ca2,270 websites
.it1,924 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-65051

Top websites that are affected by CVE-2026-65051. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
****.com United States***
****.org United States*,***
****.ca United States*,***
**********.com United States*,***
***********.com United States*,***
****************.com United States*,***
***************.org GB*,***
****************.com United States*,***
**********.de Germany*,***
************.com United States**,***
See full domain list

FAQ

A total of 128,705 websites have been identified as vulnerable to CVE-2026-65051, based on global website indexing conducted by WebTechSurvey.
The Ninja Forms is affected by the CVE-2026-65051 vulnerability.
Ninja Forms versions up to 3.14.9 are vulnerable to CVE-2026-65051.
CVE-2026-65051 is resolved in version 3.14.9 of Ninja Forms.