PatchSiren

SureForms CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH SureForms CVE published 2026-08-18

CVE-2026-19501

The CVE-2026-19501 record details a critical vulnerability in Brainstorm Force SureForms version <= 2.12.1. The vulnerability is related to the CSV export functionality, which fails to neutralize spreadsheet formula characters in user-controlled form field names. This allows a remote attacker to execute spreadsheet formulas on an administrator's workstation when the exported CSV file is opened in a vulner [truncated]

Review SureForms CVE published 2026-07-14

CVE-2026-11567

The SureForms WordPress plugin before 2.11.1 has a vulnerability allowing unauthenticated users to underpay for configured products or subscriptions due to improper validation of dynamically-sourced payment amounts. This vulnerability affects forms using dynamically-sourced payment amounts, while forms with fixed configured prices are not affected. The vulnerability has a medium defensive priority, and us [truncated]