Loading market data...
← Back to CVE feed

CVE-2026-94504

HIGH CVSS 7.2 View on NVD ↗

Description

Ninja Forms 3.15.3 stores an anonymous non-RTE textarea value and renders it without safe HTML encoding in the legacy submission editor. An attacker can break out of the textarea with stored script. When an Administrator opens the attacker-known direct submission URL, the script runs in the WordPress admin origin.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
Published: Sep 22, 2026 07:16 UTC Modified: Sep 22, 2026 19:04 UTC