SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-19501

HIGH · CVSS 8.8 EPSS 0.47% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-18 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The CSV export functionality in Brainstorm Force SureForms versions up to 2.1.1 is vulnerable due to inadequate sanitization of user-controlled form field names, allowing remote attackers to embed malicious spreadsheet formulas. When an administrator opens the exported CSV file in a susceptible spreadsheet application, these formulas can execute, potentially compromising the workstation. Organizations using this plugin should prioritize patching to mitigate the risk of remote code execution through CSV exports.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-19501
Severity
HIGH
CVSS
8.8
EPSS
0.47%

Original NVD Description

CSV export functionality in Brainstorm Force SureForms version, <= 2.12.1, fails to neutralize spreadsheet formula characters in user-controlled form field names before generating CSV exports, which allows a remote attacker to execute spreadsheet formulas on an administrator's workstation when the exported CSV file is opened in a vulnerable spreadsheet application.