logo

CVE-2026-65048: Ninja Forms Unauthenticated Stored XSS via Repeatable Fieldset

ID: 13f2d24f-ac5b-546c-ad1e-a8641c71bc6e

STIX ID: report--13f2d24f-ac5b-546c-ad1e-a8641c71bc6e

Feed Name: CosmicBytez Labs

Threat Score
78/100

Date Published: 2026-07-22

Date Updated: 2026-07-23

...
...

A critical unauthenticated stored XSS vulnerability (CVE-2026-65048, CVSS 9.3) exists in Ninja Forms (versions 3.10.4–3.14.9) due to missing numeric validation in parseSubmissionIndex() and insufficient escaping in admin_form_element(), enabling attackers to store malicious JavaScript that executes in admin browsers when reviewing form submissions; the report provides the attack chain, detection indicators, and remediation guidance (update to >3.14.9, audit submissions, enable WAF, restrict admin access).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.