CVE-2026-19500
SureForms
The Entries component in Brainstorm Force SureForms version, less than 2.12.3, does not enforce adequate limits on user-controlled form fields or submitted content during processing and rendering, which allows a remote attacker to exhaust server resources, prevent administrators from accessing the Entries interface, and trigger HTTP 500 errors via crafted form submissions.
- CVSS
- 7.5
- EPSS
- 0.49% 40.1% percentile
- CISA KEV
- Not listed
- Published
- 2026.08.19