CVE-2026-65048: Ninja Forms Unauthenticated Stored XSS via Repeatable Fieldset
ID: 13f2d24f-ac5b-546c-ad1e-a8641c71bc6e
STIX ID: report--13f2d24f-ac5b-546c-ad1e-a8641c71bc6e
Feed Name: CosmicBytez Labs
A critical unauthenticated stored XSS vulnerability (CVE-2026-65048, CVSS 9.3) exists in Ninja Forms (versions 3.10.4–3.14.9) due to missing numeric validation in parseSubmissionIndex() and insufficient escaping in admin_form_element(), enabling attackers to store malicious JavaScript that executes in admin browsers when reviewing form submissions; the report provides the attack chain, detection indicators, and remediation guidance (update to >3.14.9, audit submissions, enable WAF, restrict admin access).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
