Sigma Watch is free and independent. If it saves you time, keep it running. ☕ Buy me a coffee
SigmaWatch
CVE coverage

CVE-2026-94504

CVSS 7.2 no coverage
View on NVD →
Ninja Forms 3.15.3 stores an anonymous non-RTE textarea value and renders it without safe HTML encoding in the legacy submission editor. An attacker can break out of the textarea with stored script. When an Administrator opens the attacker-known direct submission URL, the script runs in the WordPress admin origin.

Detection rules

No detection found — yet
None of Sigma, Elastic, Splunk ESCU, YARA, Microsoft Sentinel, Snort, or Suricata currently has a rule referencing CVE-2026-94504.