Payload 是一款免费且开源的无头内容管理系统(Headless CMS)。在 3.90.0 之前的版本以及 4.0.0-canary.34 之前的测试版(canary)中,若某个集合(collection)允许上传可下载的 SVG 文件,则攻击者可以存储一个经过恶意构造的 SVG 文件,该文件能够绕过系统的 sanitization(内容清理/过滤)机制。当用户下载并打开此 SVG 文件时,将执行攻击者控制的 JavaScript 代码。此问题已在 3.90.0 版本及 4.0.0-canary.34 测试版
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| payloadcms | payload | < 3.90.0 |
affected |
>= 4.0.0-canary.0, < 4.0.0-canary.34 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| payloadcms | payload | < 3.90.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-105857 | 10.0 CRITICAL | Payload: RCE in Payload Form Builder |
| CVE-2026-105845 | 9.8 CRITICAL | Payload: SQL Injection in SQLite and Postgres |
| CVE-2026-105859 | 9.8 CRITICAL | Payload: Unauthorized update to collection documents |
| CVE-2026-105844 | 9.3 CRITICAL | Payload: Prototype pollution in Payload Import Export plugin |
| CVE-2026-105851 | 9.3 CRITICAL | Payload: Field access control bypass on auth collections |
| CVE-2026-105863 | 9.2 CRITICAL | Payload authentication token field handling issue |
| CVE-2026-105850 | 8.8 HIGH | Payload: Order confirmation validation issue in Payload Ecommerce |
| CVE-2026-105854 | 8.7 HIGH | Payload: ReDoS in Multipart Content-Type Validation |
| CVE-2026-105868 | 8.6 HIGH | Payload: Uploaded XML files could execute same-origin JavaScript |
| CVE-2026-105856 | 8.6 HIGH | Payload: SQL injection in SQLite/Postgres |
| CVE-2026-105806 | 8.6 HIGH | Payload: Improper access control for MCP API keys |
| CVE-2026-105865 | 8.1 HIGH | Payload: Incomplete validation during the upload file lifecycle |
| CVE-2026-105858 | 8.1 HIGH | Payload: Remote Code Execution through first-register |
| CVE-2026-105849 | 7.7 HIGH | Payload: API key disclosure through ordinary document reads |
| CVE-2026-105855 | 7.6 HIGH | Payload: Field-level password update restrictions were not enforced |
| CVE-2026-105861 | 7.2 HIGH | Payload external upload trust validation issue |
| CVE-2026-106100 | 7.1 HIGH | Payload: Field-level write access bypass in Payload on MongoDB |
| CVE-2026-105867 | 7.1 HIGH | Payload: Client uploads could overwrite S3 objects |
| CVE-2026-105860 | 7.1 HIGH | Payload: Tenant authorization bypass in Multi-Tenant Plugin |
| CVE-2026-105847 | 7.1 HIGH | Payload: Polymorphic join queries could disclose hidden fields |
Showing top 20 of 29 CVEs. View all on vendor page → →
No comments yet