VYPR

Sureforms

by Brainstormforce

CVEs (9)

  • CVE-2026-19501HigAug 18, 2026
    risk 0.57cvss 8.8epss 0.00

    CSV export functionality in Brainstorm Force SureForms version, <= 2.12.1, fails to neutralize spreadsheet formula characters in user-controlled form field names before generating CSV exports, which allows a remote attacker to execute spreadsheet formulas on an administrator's…

  • CVE-2025-6691HigJul 9, 2025
    risk 0.53cvss 8.1epss 0.01

    The SureForms – Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the delete_entry_files() function in all versions up to, and including, 1.7.3. This makes it possible for…

  • CVE-2026-19500HigAug 18, 2026
    risk 0.49cvss 7.5epss 0.00

    The Entries component in Brainstorm Force SureForms version, less than 2.12.3, does not enforce adequate limits on user-controlled form fields or submitted content during processing and rendering, which allows a remote attacker to exhaust server resources, prevent administrators…

  • CVE-2025-6742HigJul 9, 2025
    risk 0.49cvss 7.5epss 0.01

    The SureForms – Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.7.3 via the use of file_exists() in the delete_entry_files() function without restriction on the path provided. This…

  • CVE-2025-5921MedAug 1, 2025
    risk 0.38cvss 5.8epss 0.00

    The SureForms WordPress plugin before 1.7.2 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against both authenticated and unauthenticated users.

  • CVE-2024-12713MedJan 8, 2025
    risk 0.34cvss 5.3epss 0.00

    The SureForms – Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.2.2 via the handle_export_form() function due to a missing capability check. This makes it possible for unauthenticated…

  • CVE-2025-3471MedApr 30, 2025
    risk 0.32cvss 4.9epss 0.00

    The SureForms WordPress plugin before 1.4.4 does not have proper authorisation check when updating its settings via the REST API, which could allow Contributor and above roles to perform such action

  • CVE-2025-3514LowMay 2, 2025
    risk 0.23cvss 3.5epss 0.00

    The SureForms WordPress plugin before 1.4.4 does not sanitise and escape some of its Form settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in…

  • CVE-2025-3513LowMay 2, 2025
    risk 0.23cvss 3.5epss 0.00

    The SureForms WordPress plugin before 1.4.4 does not sanitise and escape some of its Form settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in…