CVE-2026-19500: Sureforms

High severity, CVSS 7.5. EPSS: 0.6% chance of exploitation in the next 30 days.

The Entries component in Brainstorm Force SureForms version, less than 2.12.3, does not enforce adequate limits on user-controlled form fields or submitted content during processing and rendering, which allows a remote attacker to exhaust server resources, prevent administrators from accessing the Entries interface, and trigger HTTP 500 errors via crafted form submissions.

Affected products

  • Sureforms Sureforms: before 2.12.3 (fixed in 2.12.3)

Published 2026-08-18. Last modified 2026-09-03.