THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-19501 (HIGH 8.8) — CSV export functionality in Brainstorm Force SureForms version, <= 2.12.1, fails to neutralize spreadsheet formula characters in user-controlled form field names before generating CSV exports, which allows a remote attacker to execute spreadsheet formulas on an administrator's wo

[NVD] CVE-2026-19501 (HIGH 8.8) — CSV export functionality in Brainstorm Force SureForms version, <= 2.12.1, fails to neutralize spreadsheet formula characters in user-controlled form field names before generating CSV exports, which allows a remote attacker to execute spreadsheet formulas on an administrator's wo

mednvdPublished 2026-08-18

CVE-2026-19501 CVSS: 8.8 HIGH Published: 2026-08-18T16:17:02.780

CSV export functionality in Brainstorm Force SureForms version, <= 2.12.1, fails to neutralize spreadsheet formula characters in user-controlled form field names before generating CSV exports, which allows a remote attacker to execute spreadsheet formulas on an administrator's workstation when the exported CSV file is opened in a vu

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-19501