Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total5
Critical0
High1
Medium4
Reset
Showing 1-5 of 5 records
Threat Entry Updated 2025-07-07

CVE-2025-2940 - Ninja Tables Plugin

The Ninja Tables – Easy Data Table Builder plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 5.0.18 via the args[url] parameter. This makes it possible for unauthenticated attackers to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services.

PLUGIN Ninja Tables

CVE-2025-2940

HIGH CVSS 7.2 2025-06-27
Threat Entry Updated 2025-07-10

CVE-2025-2939 - Ninja Tables Plugin

The Ninja Tables – Easy Data Table Builder plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 5.0.18 via deserialization of untrusted input from the args[callback] parameter . This makes it possible for unauthenticated attackers to inject a PHP Object. The additional presence of a POP chain allows attackers to execute arbitrary functions, though it does not allow user supplied parameters only single functions can be called so the impact is limited.

PLUGIN Ninja Tables

CVE-2025-2939

MEDIUM CVSS 5.6 2025-06-03
Threat Entry Updated 2025-03-28

CVE-2024-12772 - Ninja Tables Plugin

The Ninja Tables WordPress plugin before 5.0.17 does not sanitize and escape a parameter before outputting it back in the page when importing a CSV, leading to a Cross Site Scripting vulnerability.

PLUGIN Ninja Tables

CVE-2024-12772

MEDIUM CVSS 5.4 2025-01-31
Threat Entry Updated 2024-09-12

CVE-2024-7304 - Ninja Tables Plugin

The Ninja Tables – Easiest Data Table Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 5.0.12 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses the SVG file.

PLUGIN Ninja Tables

CVE-2024-7304

MEDIUM CVSS 6.4 2024-08-27
Threat Entry Updated 2024-11-21

CVE-2021-24900 - Ninja Tables Plugin

The Ninja Tables WordPress plugin before 4.1.8 does not sanitise and escape some of its table fields, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

PLUGIN Ninja Tables

CVE-2021-24900

MEDIUM CVSS 4.8 2022-02-01
Scroll to top