CVE-2026-94504

CVE-2026-94504 published: Ninja Forms 3.15.3 stores an anonymous non-RTE textarea value and renders it without safe HTML encoding in the legacy submission editor. An attacker can break out of the textarea with stored script. When an Administrator opens the attacker-known direct subm...

View full NVD advisory → ← Back to CVE watch