Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-19500— SureForms contains an uncontrolled resource consumption vulnerability

Quick assessment

Affected
SureForms SureForms
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Brainstorm Force SureForms 版本(低于 2.1.3)中的 Entries 组件在处理及渲染过程中,未对用户可控的表单字段或提交内容实施充分限制,这使得远程攻击者可通过构造恶意表单提交,耗尽服务器资源,阻止管理员访问 Entries 界面,并触发 HTTP 500 错误。

AI Predicted 5.3 Difficulty: Easy EPSS 0.49% · P40

Possible ATT&CK Techniques 1 AI

T1496 · Resource Hijacking

Affected Version Matrix 1

VendorProduct Version RangeStatus
SureForms SureForms < 2.12.3 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-19500

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
SureForms contains an uncontrolled resource consumption vulnerability
Source: CVE Program / CVE List V5
Vulnerability Description
The Entries component in Brainstorm Force SureForms version, less than 2.12.3, does not enforce adequate limits on user-controlled form fields or submitted content during processing and rendering, which allows a remote attacker to exhaust server resources, prevent administrators from accessing the Entries interface, and trigger HTTP 500 errors via crafted form submissions.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
SureForms SureForms 0 ~ 2.12.3 -

II. Public POCs for CVE-2026-19500

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-19500

登录查看更多情报信息。

Proof of Concept for CVE-2026-19500 (1)

Vendor Pages for CVE-2026-19500 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-19500

No comments yet


Leave a comment