Skip to content

Latest commit

 

History

5 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 
 
 
 
 

Repository files navigation

CVE-2026-19500 Poc and writeup

Description

Sureforms is vulnerable to a DOS vulnerability , when attacker can submit unlimited key-value pair, leads to resource exhaustion and the administrator can not watch entries temporary.

How to reproduce

Submit the Form which is made by Sureforms plugin, and then create large amount of key-value pair, with large size of content in a pair and then submitted. Just need a few times for submit it and admin cannot see the entries.

You can also run this Poc a few times and the vulnerability will be exploited.

How to fix

Update to the latest version (2.12.3 or newer), which have partitially patched the issue

Note

If you feel this write-up here great and interesting, you contribute me in my Github Sponsor.

About

CVE-2026-19500 poc

Resources

Stars

1 star

Watchers

0 watching

Forks

Releases

Sponsor this project

Packages

Contributors

Languages