Payload 是一款免费且开源的无头(headless)内容管理系统。在 3.0.0 至 3.90.0 版本之间(不含 3.90.0),以及在 4.0.0-canary.34 之前的 canary 版本中,如果集合(collection)启用了 useAPIKey 功能,普通读取权限用户即可获取同一集合中其他认证文档的活动 API 密钥,并利用这些密钥冒充目标账户执行操作,直到这些密钥被轮换或禁用为止。该问题已在 3.90.0 和 4.0.0-canary.34 版本中得到修复。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| payloadcms | payload | >= 3.0.0, < 3.90.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-105857 | 10.0 CRITICAL | Payload: RCE in Payload Form Builder |
| CVE-2026-105845 | 9.8 CRITICAL | Payload: SQL Injection in SQLite and Postgres |
| CVE-2026-105859 | 9.8 CRITICAL | Payload: Unauthorized update to collection documents |
| CVE-2026-105844 | 9.3 CRITICAL | Payload: Prototype pollution in Payload Import Export plugin |
| CVE-2026-105851 | 9.3 CRITICAL | Payload: Field access control bypass on auth collections |
| CVE-2026-105850 | 8.8 HIGH | Payload: Order confirmation validation issue in Payload Ecommerce |
| CVE-2026-105854 | 8.7 HIGH | Payload: ReDoS in Multipart Content-Type Validation |
| CVE-2026-105856 | 8.6 HIGH | Payload: SQL injection in SQLite/Postgres |
| CVE-2026-105806 | 8.6 HIGH | Payload: Improper access control for MCP API keys |
| CVE-2026-105858 | 8.1 HIGH | Payload: Remote Code Execution through first-register |
| CVE-2026-105855 | 7.6 HIGH | Payload: Field-level password update restrictions were not enforced |
| CVE-2026-105861 | 7.2 HIGH | Payload external upload trust validation issue |
| CVE-2026-105847 | 7.1 HIGH | Payload: Polymorphic join queries could disclose hidden fields |
| CVE-2026-105860 | 7.1 HIGH | Payload: Tenant authorization bypass in Multi-Tenant Plugin |
| CVE-2026-105853 | 7.1 HIGH | Payload: Token refresh and password reset responses may expose restricted user fields |
| CVE-2026-105852 | 6.9 MEDIUM | Payload relationship-query authorization bypass |
| CVE-2026-105805 | 6.9 MEDIUM | Payload: Sort queries could expose protected field information |
| CVE-2026-105848 | 6.4 MEDIUM | Payload: Insufficient Access Control in Stripe REST Proxy |
| CVE-2026-105846 | 6.1 MEDIUM | Payload: Untrusted redirect URL parameter exploit |
| CVE-2026-105804 | 5.7 MEDIUM | Payload: Password hashes use insufficient PBKDF2 iterations |
No comments yet