SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-19500

HIGH · CVSS 7.5 EPSS 0.49% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-18 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The Entries component in Brainstorm Force SureForms versions prior to 2.1.3 is vulnerable due to insufficient limits on user-controlled form fields, allowing remote attackers to exploit this weakness. This can lead to resource exhaustion on the server, resulting in HTTP 500 errors and preventing administrators from accessing the Entries interface. Organizations using affected versions should prioritize this vulnerability to mitigate potential denial-of-service impacts.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-19500
Severity
HIGH
CVSS
7.5
EPSS
0.49%

Original NVD Description

The Entries component in Brainstorm Force SureForms version, less than 2.12.3, does not enforce adequate limits on user-controlled form fields or submitted content during processing and rendering, which allows a remote attacker to exhaust server resources, prevent administrators from accessing the Entries interface, and trigger HTTP 500 errors via crafted form submissions.