Payload 是一款免费且开源的无头内容管理系统(Headless CMS)。Payload 3.0.0 至 3.90.0 之前的版本,以及 4.0.0-canary.0 至 4.0.0-canary.34 之前的 canary 版本,在密码哈希计算中使用了低于推荐标准的 PBKDF2 工作因子(work factor),从而降低了破解 recovered 密码哈希值所需的计算成本。该问题已在版本 3.90.0 和 4.0.0-canary.34 中修复。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| payloadcms | payload | >= 3.0.0, < 3.90.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-105845 | 9.8 CRITICAL | Payload: SQL Injection in SQLite and Postgres |
| CVE-2026-105844 | 9.3 CRITICAL | Payload: Prototype pollution in Payload Import Export plugin |
| CVE-2026-105806 | 8.6 HIGH | Payload: Improper access control for MCP API keys |
| CVE-2026-105805 | 6.9 MEDIUM | Payload: Sort queries could expose protected field information |
No comments yet