Payload 是一个免费且开源的无头内容管理系统。在 @payloadcms/storage-s3 插件中,对于 3.90.0 之前的版本以及 4.0.0-canary.34 之前的 canary(测试)版本,当为多个共享同一 S3 存储桶的上传集合启用了客户端上传功能,并且使用 设置为 false 或未设置时,经过身份验证的用户可以覆盖属于其他上传集合的现有 S3 对象。这种行为绕过了目标集合的访问控制机制以及之前的文件验证步骤。该问题已在 3.90.0 版本和 4.0.0-canary.34 版本中得到修复。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| @payloadcms | storage-s3 | < 3.90.0 |
affected |
>= 4.0.0-canary.0, < 4.0.0-canary.34 |
affected | ||
| payloadcms | payload | < 3.90.0 |
affected |
>= 4.0.0-canary.0, < 4.0.0-canary.34 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| payloadcms | payload | < 3.90.0 | - |
|
| @payloadcms | storage-s3 | < 3.90.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-105857 | 10.0 CRITICAL | Payload: RCE in Payload Form Builder |
| CVE-2026-105859 | 9.8 CRITICAL | Payload: Unauthorized update to collection documents |
| CVE-2026-105845 | 9.8 CRITICAL | Payload: SQL Injection in SQLite and Postgres |
| CVE-2026-105844 | 9.3 CRITICAL | Payload: Prototype pollution in Payload Import Export plugin |
| CVE-2026-105851 | 9.3 CRITICAL | Payload: Field access control bypass on auth collections |
| CVE-2026-105863 | 9.2 CRITICAL | Payload authentication token field handling issue |
| CVE-2026-105850 | 8.8 HIGH | Payload: Order confirmation validation issue in Payload Ecommerce |
| CVE-2026-105862 | 8.7 HIGH | Payload: Bypassed sanitization of user uploaded SVGs |
| CVE-2026-105854 | 8.7 HIGH | Payload: ReDoS in Multipart Content-Type Validation |
| CVE-2026-105868 | 8.6 HIGH | Payload: Uploaded XML files could execute same-origin JavaScript |
| CVE-2026-105856 | 8.6 HIGH | Payload: SQL injection in SQLite/Postgres |
| CVE-2026-105806 | 8.6 HIGH | Payload: Improper access control for MCP API keys |
| CVE-2026-105865 | 8.1 HIGH | Payload: Incomplete validation during the upload file lifecycle |
| CVE-2026-105858 | 8.1 HIGH | Payload: Remote Code Execution through first-register |
| CVE-2026-105849 | 7.7 HIGH | Payload: API key disclosure through ordinary document reads |
| CVE-2026-105855 | 7.6 HIGH | Payload: Field-level password update restrictions were not enforced |
| CVE-2026-105861 | 7.2 HIGH | Payload external upload trust validation issue |
| CVE-2026-106100 | 7.1 HIGH | Payload: Field-level write access bypass in Payload on MongoDB |
| CVE-2026-105860 | 7.1 HIGH | Payload: Tenant authorization bypass in Multi-Tenant Plugin |
| CVE-2026-105847 | 7.1 HIGH | Payload: Polymorphic join queries could disclose hidden fields |
Showing top 20 of 29 CVEs. View all on vendor page → →
No comments yet