CVE-2026-19500
The Entries component in Brainstorm Force SureForms version, less than 2.12.3, does not enforce adequate limits on user-controlled form fields or submitted content during processing and rendering, which allows a remote attacker to exhaust server resources, prevent administrators from accessing the Entries interface, and trigger HTTP 500 errors via crafted form submissions.
- Affected products
- Sureforms
- CVSS 3.1
- 7.5 HIGH
- EPSS
- 0.5% (40th percentile)
- Weakness
- CWE-400
- NVD status
- Received
- Published
- 2026-08-18
CVE-2026-19500 at NVD
1 known exploit for CVE-2026-19500
Proof-of-concept code and exploit modules indexed by Sploitus