System running
Last check: 2026-09-29 01:26:15 | Auto-updates every hour
756 PoCs
CybersecPlayground | The ultimate platform for cybersecurity learning & Bug Bounty Resources

CVE-CVE-2026-94504

Severity
HIGH
CVSS Score
7.2
Description

Ninja Forms 3.15.3 stores an anonymous non-RTE textarea value and renders it without safe HTML encoding in the legacy submission editor. An attacker can break out of the textarea with stored script. When an Administrator opens the attacker-known direct submission URL, the script runs in the WordPress admin origin....

PoCs for CVE-CVE-2026-94504

cve-2026-94504
XSS Python 0
cflowsec 2026-09-24
Master Cybersecurity | Join CybersecPlayground for Cybersecurity Learning & Bug Bounty Resources