Payload 是一款免费且开源的无头内容管理系统(Headless CMS)。在版本低于 3.90.0 以及低于 4.0.0-canary.34 的 canary 版本中,存在安全漏洞:如果集合(collection)或连接字段(join field)上启用了“可排序”(orderable)功能,攻击者可以向特定的更新端点提交请求,从而修改集合文档,而系统在此过程中未强制执行集合级别或字段级别的访问控制。该问题已在版本 3.90.0 和 4.0.0-canary.34 中得到修复。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| payloadcms | payload | < 3.90.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-105857 | 10.0 CRITICAL | Payload: RCE in Payload Form Builder |
| CVE-2026-105845 | 9.8 CRITICAL | Payload: SQL Injection in SQLite and Postgres |
| CVE-2026-105844 | 9.3 CRITICAL | Payload: Prototype pollution in Payload Import Export plugin |
| CVE-2026-105851 | 9.3 CRITICAL | Payload: Field access control bypass on auth collections |
| CVE-2026-105850 | 8.8 HIGH | Payload: Order confirmation validation issue in Payload Ecommerce |
| CVE-2026-105854 | 8.7 HIGH | Payload: ReDoS in Multipart Content-Type Validation |
| CVE-2026-105856 | 8.6 HIGH | Payload: SQL injection in SQLite/Postgres |
| CVE-2026-105806 | 8.6 HIGH | Payload: Improper access control for MCP API keys |
| CVE-2026-105858 | 8.1 HIGH | Payload: Remote Code Execution through first-register |
| CVE-2026-105849 | 7.7 HIGH | Payload: API key disclosure through ordinary document reads |
| CVE-2026-105855 | 7.6 HIGH | Payload: Field-level password update restrictions were not enforced |
| CVE-2026-105861 | 7.2 HIGH | Payload external upload trust validation issue |
| CVE-2026-105853 | 7.1 HIGH | Payload: Token refresh and password reset responses may expose restricted user fields |
| CVE-2026-105847 | 7.1 HIGH | Payload: Polymorphic join queries could disclose hidden fields |
| CVE-2026-105860 | 7.1 HIGH | Payload: Tenant authorization bypass in Multi-Tenant Plugin |
| CVE-2026-105852 | 6.9 MEDIUM | Payload relationship-query authorization bypass |
| CVE-2026-105805 | 6.9 MEDIUM | Payload: Sort queries could expose protected field information |
| CVE-2026-105848 | 6.4 MEDIUM | Payload: Insufficient Access Control in Stripe REST Proxy |
| CVE-2026-105846 | 6.1 MEDIUM | Payload: Untrusted redirect URL parameter exploit |
| CVE-2026-105804 | 5.7 MEDIUM | Payload: Password hashes use insufficient PBKDF2 iterations |
No comments yet