Payload 是一个免费且开源的无头(headless)内容管理系统(CMS)。在版本 3.90.0 之前以及 canary 版本中早于 4.0.0-canary.34 的版本里,任何拥有更新或删除本地存储上传文件权限的已认证用户,可能导致文件清理机制意外删除配置上传目录之外的文件,从而引发数据丢失或服务中断。对于仅允许受信任用户管理上传内容的部署环境,受影响程度较低。该问题已在版本 3.90.0 和 4.0.0-canary.34 中得到修复。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| payloadcms | payload | < 3.90.0 |
affected |
>= 4.0.0-canary.0, < 4.0.0-canary.34 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| payloadcms | payload | < 3.90.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-105857 | 10.0 CRITICAL | Payload: RCE in Payload Form Builder |
| CVE-2026-105845 | 9.8 CRITICAL | Payload: SQL Injection in SQLite and Postgres |
| CVE-2026-105859 | 9.8 CRITICAL | Payload: Unauthorized update to collection documents |
| CVE-2026-105844 | 9.3 CRITICAL | Payload: Prototype pollution in Payload Import Export plugin |
| CVE-2026-105851 | 9.3 CRITICAL | Payload: Field access control bypass on auth collections |
| CVE-2026-105863 | 9.2 CRITICAL | Payload authentication token field handling issue |
| CVE-2026-105850 | 8.8 HIGH | Payload: Order confirmation validation issue in Payload Ecommerce |
| CVE-2026-105854 | 8.7 HIGH | Payload: ReDoS in Multipart Content-Type Validation |
| CVE-2026-105862 | 8.7 HIGH | Payload: Bypassed sanitization of user uploaded SVGs |
| CVE-2026-105868 | 8.6 HIGH | Payload: Uploaded XML files could execute same-origin JavaScript |
| CVE-2026-105856 | 8.6 HIGH | Payload: SQL injection in SQLite/Postgres |
| CVE-2026-105806 | 8.6 HIGH | Payload: Improper access control for MCP API keys |
| CVE-2026-105858 | 8.1 HIGH | Payload: Remote Code Execution through first-register |
| CVE-2026-105849 | 7.7 HIGH | Payload: API key disclosure through ordinary document reads |
| CVE-2026-105855 | 7.6 HIGH | Payload: Field-level password update restrictions were not enforced |
| CVE-2026-105861 | 7.2 HIGH | Payload external upload trust validation issue |
| CVE-2026-106100 | 7.1 HIGH | Payload: Field-level write access bypass in Payload on MongoDB |
| CVE-2026-105867 | 7.1 HIGH | Payload: Client uploads could overwrite S3 objects |
| CVE-2026-105860 | 7.1 HIGH | Payload: Tenant authorization bypass in Multi-Tenant Plugin |
| CVE-2026-105847 | 7.1 HIGH | Payload: Polymorphic join queries could disclose hidden fields |
Showing top 20 of 29 CVEs. View all on vendor page → →
No comments yet