Payload 是一个免费且开源的无头(headless)内容管理系统。在 @payloadcms/plugin-multi-tenant 插件中,版本号低于 3.90.0 以及 4.0.0-canary.34 之前的 canary 版本存在安全漏洞。该漏洞允许一个被限制只能访问单个租户的已认证用户,在至少存在一个启用租户功能的集合(collection)的情况下,创建属于其他租户的记录。不过,无法绕过对目标租户中已有文档的读取和直接编辑操作。该问题已在版本 3.90.0 和 4.0.0-canary.34 中修复
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| @payloadcms | plugin-multi-tenant | < 3.90.0 |
affected |
>= 4.0.0-canary.0, < 4.0.0-canary.34 |
affected | ||
| payloadcms | payload | < 3.90.0 |
affected |
>= 4.0.0-canary.0, < 4.0.0-canary.34 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| payloadcms | payload | < 3.90.0 | - |
|
| @payloadcms | plugin-multi-tenant | < 3.90.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-105857 | 10.0 CRITICAL | Payload: RCE in Payload Form Builder |
| CVE-2026-105845 | 9.8 CRITICAL | Payload: SQL Injection in SQLite and Postgres |
| CVE-2026-105859 | 9.8 CRITICAL | Payload: Unauthorized update to collection documents |
| CVE-2026-105844 | 9.3 CRITICAL | Payload: Prototype pollution in Payload Import Export plugin |
| CVE-2026-105851 | 9.3 CRITICAL | Payload: Field access control bypass on auth collections |
| CVE-2026-105863 | 9.2 CRITICAL | Payload authentication token field handling issue |
| CVE-2026-105850 | 8.8 HIGH | Payload: Order confirmation validation issue in Payload Ecommerce |
| CVE-2026-105862 | 8.7 HIGH | Payload: Bypassed sanitization of user uploaded SVGs |
| CVE-2026-105854 | 8.7 HIGH | Payload: ReDoS in Multipart Content-Type Validation |
| CVE-2026-105806 | 8.6 HIGH | Payload: Improper access control for MCP API keys |
| CVE-2026-105868 | 8.6 HIGH | Payload: Uploaded XML files could execute same-origin JavaScript |
| CVE-2026-105856 | 8.6 HIGH | Payload: SQL injection in SQLite/Postgres |
| CVE-2026-105865 | 8.1 HIGH | Payload: Incomplete validation during the upload file lifecycle |
| CVE-2026-105858 | 8.1 HIGH | Payload: Remote Code Execution through first-register |
| CVE-2026-105849 | 7.7 HIGH | Payload: API key disclosure through ordinary document reads |
| CVE-2026-105855 | 7.6 HIGH | Payload: Field-level password update restrictions were not enforced |
| CVE-2026-105861 | 7.2 HIGH | Payload external upload trust validation issue |
| CVE-2026-105867 | 7.1 HIGH | Payload: Client uploads could overwrite S3 objects |
| CVE-2026-106100 | 7.1 HIGH | Payload: Field-level write access bypass in Payload on MongoDB |
| CVE-2026-105860 | 7.1 HIGH | Payload: Tenant authorization bypass in Multi-Tenant Plugin |
Showing top 20 of 29 CVEs. View all on vendor page → →
No comments yet