CVE-2026-19501
CVE-2026-19501
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
CSV export functionality in Brainstorm Force SureForms version, <= 2.1.1, fails to neutralize spreadsheet formula characters in user-controlled form field names before generating CSV exports, which allows a remote attacker to execute spreadsheet formulas on an administrator's workstation when the exported CSV file is opened in a vulnerable spreadsheet application.
| Vendor | sureforms |
| Product | sureforms |
| Published | Aug 18, 2026 |
Stay Ahead of the Next One
Get instant alerts for sureforms sureforms
Be the first to know when new unknown vulnerabilities affecting sureforms sureforms are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
SureForms / SureForms
0 โค 2.1.1