Payload 是一款免费且开源的无头内容管理系统。在 3.0.0 至 3.88.0(不含)版本以及 4.0.0-canary.27(不含)之前的 canary 版本中,当启用了 插件时,未认证的用户可以提交包含原型污染敏感性的字段路径,从而导致意外的应用行为,并可能引发远程代码执行(RCE)漏洞。该问题已在版本 3.88.0 和 4.0.0-canary.27 中得到修复。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| payloadcms | payload | >= 3.0.0, < 3.88.0 | - |
|
| @payloadcms | plugin-import-export | >= 3.0.0, < 3.88.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-105845 | 9.8 CRITICAL | Payload: SQL Injection in SQLite and Postgres |
| CVE-2026-105851 | 9.3 CRITICAL | Payload: Field access control bypass on auth collections |
| CVE-2026-105850 | 8.8 HIGH | Payload: Order confirmation validation issue in Payload Ecommerce |
| CVE-2026-105806 | 8.6 HIGH | Payload: Improper access control for MCP API keys |
| CVE-2026-105849 | 7.7 HIGH | Payload: API key disclosure through ordinary document reads |
| CVE-2026-105853 | 7.1 HIGH | Payload: Token refresh and password reset responses may expose restricted user fields |
| CVE-2026-105847 | 7.1 HIGH | Payload: Polymorphic join queries could disclose hidden fields |
| CVE-2026-105805 | 6.9 MEDIUM | Payload: Sort queries could expose protected field information |
| CVE-2026-105852 | 6.9 MEDIUM | Payload relationship-query authorization bypass |
| CVE-2026-105848 | 6.4 MEDIUM | Payload: Insufficient Access Control in Stripe REST Proxy |
| CVE-2026-105846 | 6.1 MEDIUM | Payload: Untrusted redirect URL parameter exploit |
| CVE-2026-105804 | 5.7 MEDIUM | Payload: Password hashes use insufficient PBKDF2 iterations |
No comments yet