Payload 是一个免费且开源的无头内容管理系统。在版本 3.90.0 和 4.0.0-canary.34 之前,如果攻击者对包含 JSON 字段或启用了 的块字段(blocks field)的集合具有读取和创建或更新权限,则可以通过构造的字段路径和操作符注入 SQL 注入攻击。不受影响的集合是不包含这些字段的集合,而 richText 字段也不受影响。 SQLite 相关包已在版本 3.90.0 和 4.0.0-canary.34 中修复该漏洞,Postgres 相关包已在版本 3.73.0 中修复。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| payloadcms | payload | >= 3.0.0, < 3.90.0 | - |
|
| @payloadcms | db-d1-sqlite | >= 3.0.0, < 3.90.0 | - |
|
| @payloadcms | db-postgres | >= 3.0.0 < 3.73.0 | - |
|
| @payloadcms | db-sqlite | >= 3.0.0, < 3.90.0 | - |
|
| @payloadcms | db-vercel-postgres | >= 3.0.0 < 3.73.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-105857 | 10.0 CRITICAL | Payload: RCE in Payload Form Builder |
| CVE-2026-105859 | 9.8 CRITICAL | Payload: Unauthorized update to collection documents |
| CVE-2026-105845 | 9.8 CRITICAL | Payload: SQL Injection in SQLite and Postgres |
| CVE-2026-105844 | 9.3 CRITICAL | Payload: Prototype pollution in Payload Import Export plugin |
| CVE-2026-105851 | 9.3 CRITICAL | Payload: Field access control bypass on auth collections |
| CVE-2026-105850 | 8.8 HIGH | Payload: Order confirmation validation issue in Payload Ecommerce |
| CVE-2026-105854 | 8.7 HIGH | Payload: ReDoS in Multipart Content-Type Validation |
| CVE-2026-105806 | 8.6 HIGH | Payload: Improper access control for MCP API keys |
| CVE-2026-105858 | 8.1 HIGH | Payload: Remote Code Execution through first-register |
| CVE-2026-105849 | 7.7 HIGH | Payload: API key disclosure through ordinary document reads |
| CVE-2026-105855 | 7.6 HIGH | Payload: Field-level password update restrictions were not enforced |
| CVE-2026-105861 | 7.2 HIGH | Payload external upload trust validation issue |
| CVE-2026-105853 | 7.1 HIGH | Payload: Token refresh and password reset responses may expose restricted user fields |
| CVE-2026-105847 | 7.1 HIGH | Payload: Polymorphic join queries could disclose hidden fields |
| CVE-2026-105860 | 7.1 HIGH | Payload: Tenant authorization bypass in Multi-Tenant Plugin |
| CVE-2026-105852 | 6.9 MEDIUM | Payload relationship-query authorization bypass |
| CVE-2026-105805 | 6.9 MEDIUM | Payload: Sort queries could expose protected field information |
| CVE-2026-105848 | 6.4 MEDIUM | Payload: Insufficient Access Control in Stripe REST Proxy |
| CVE-2026-105846 | 6.1 MEDIUM | Payload: Untrusted redirect URL parameter exploit |
| CVE-2026-105804 | 5.7 MEDIUM | Payload: Password hashes use insufficient PBKDF2 iterations |
No comments yet