CSV Export Vulnerability in Brainstorm Force SureForms Product
CVE-2026-19501

Currently unrated

Key Information:

Vendor

Sureforms

Status
Vendor
CVE Published:
18 August 2026

What is CVE-2026-19501?

The SureForms product by Brainstorm Force contains a vulnerability in its CSV export functionality, present in versions 2.1.1 and earlier. The flaw arises from the failure to sanitize user-controlled form field names, which can include spreadsheet formula characters. This oversight allows a remote attacker to create a malicious CSV file that, when opened in a vulnerable spreadsheet application, executes arbitrary formulas on the administrator's workstation, potentially leading to unauthorized actions or data exfiltration.

Affected Version(s)

SureForms 0 <= 2.1.1

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.