{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-06-23T20:43:34.746","vulnerabilities":[{"cve":{"id":"CVE-2024-26019","sourceIdentifier":"vultures@jpcert.or.jp","published":"2024-04-11T03:15:09.767","lastModified":"2026-06-17T07:16:56.237","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"Ninja Forms prior to 3.8.1 contains a cross-site scripting vulnerability in submit processing. If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user who is accessing to the website using the product."},{"lang":"es","value":"Ninja Forms anterior a 3.8.1 contiene una vulnerabilidad de cross-site scripting en el procesamiento de envíos. Si se explota esta vulnerabilidad, se puede ejecutar un script arbitrario en el navegador web del usuario que accede al sitio web utilizando el producto."}],"affected":[{"source":"vultures@jpcert.or.jp","affectedData":[{"vendor":"Saturday Drive","product":"Ninja Forms","versions":[{"version":"prior to 3.8.1","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","baseScore":5.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.3,"impactScore":2.7}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-07-29T18:33:58.137329Z","id":"CVE-2024-26019","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-79"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:ninjaforms:ninja_forms:*:*:*:*:*:wordpress:*:*","versionEndExcluding":"3.8.1","matchCriteriaId":"504BEA08-652A-4175-9CE6-CAB552E601E4"}]}]}],"references":[{"url":"https://jvn.jp/en/jp/JVN50361500/","source":"vultures@jpcert.or.jp","tags":["Third Party Advisory"]},{"url":"https://ninjaforms.com/","source":"vultures@jpcert.or.jp","tags":["Product"]},{"url":"https://wordpress.org/plugins/ninja-forms/","source":"vultures@jpcert.or.jp","tags":["Product"]},{"url":"https://jvn.jp/en/jp/JVN50361500/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]},{"url":"https://ninjaforms.com/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Product"]},{"url":"https://wordpress.org/plugins/ninja-forms/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Product"]}]}}]}