Ninja Forms File Uploads Flaw: Unauthenticated File Attacks on S3 Uploads (2026)
Ninja Forms’ file upload add-on has its second serious security flaw this year. A newly disclosed vulnerability — CVE-2026-92820, rated CVSS 8.1 (High) — lets attackers with no login read, write, or delete arbitrary files on sites that route form uploads through an external store like Amazon S3. The fix... Read More