CVE-2026-19500
SureForms contains an uncontrolled resource consumption vulnerability
- Published
- Aug 18, 2026
- Updated
- Aug 19, 2026
- Assigning CNA
- certcc
- Evidence observed
- Aug 18, 2026
Primary CVSS
nvd · CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HLow · next 30 days
- Percentile
- 40.9%
- Model date
- Sep 21, 2026
EPSS is a statistical estimate, not a certainty or a measure of impact. Combine it with CVSS, KEV status, exposure and your environment.
Summary
The Entries component in Brainstorm Force SureForms version, less than 2.12.3, does not enforce adequate limits on user-controlled form fields or submitted content during processing and rendering, which allows a remote attacker to exhaust server resources, prevent administrators from accessing the Entries interface, and trigger HTTP 500 errors via crafted form submissions.
Sources
1Proof-of-concept for CVE-2026-19500, a DoS vulnerability in the SureForms WordPress plugin that exhausts server resources via oversized key-value form submissions.
Responsible use
Use vulnerability information only on systems you own or are authorized to test. Kitploit links to public research metadata and does not store exploit code or malicious payloads.