Payload 是一个免费且开源的无头内容管理系统(Headless CMS)。在 @payloadcms/db-mongodb 版本中,若版本低于 3.87.0,或 Canary 测试版本低于 4.0.0-canary.20,存在一处漏洞:具备文档更新权限的经认证用户,能够修改那些在其字段级写入访问控制权限之外、本不应允许其更改的字段。PostgreSQL 和 SQLite 适配器不受此问题影响。该漏洞已在版本 3.87.0 和 4.0.0-canary.20 中得到修复。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| payloadcms | payload | < 3.87.0 |
affected |
>= 4.0.0-canary.0, < 4.0.0-canary.20 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| payloadcms | payload | < 3.87.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-105857 | 10.0 CRITICAL | Payload: RCE in Payload Form Builder |
| CVE-2026-105845 | 9.8 CRITICAL | Payload: SQL Injection in SQLite and Postgres |
| CVE-2026-105859 | 9.8 CRITICAL | Payload: Unauthorized update to collection documents |
| CVE-2026-105844 | 9.3 CRITICAL | Payload: Prototype pollution in Payload Import Export plugin |
| CVE-2026-105851 | 9.3 CRITICAL | Payload: Field access control bypass on auth collections |
| CVE-2026-105863 | 9.2 CRITICAL | Payload authentication token field handling issue |
| CVE-2026-105850 | 8.8 HIGH | Payload: Order confirmation validation issue in Payload Ecommerce |
| CVE-2026-105862 | 8.7 HIGH | Payload: Bypassed sanitization of user uploaded SVGs |
| CVE-2026-105854 | 8.7 HIGH | Payload: ReDoS in Multipart Content-Type Validation |
| CVE-2026-105856 | 8.6 HIGH | Payload: SQL injection in SQLite/Postgres |
| CVE-2026-105806 | 8.6 HIGH | Payload: Improper access control for MCP API keys |
| CVE-2026-105868 | 8.6 HIGH | Payload: Uploaded XML files could execute same-origin JavaScript |
| CVE-2026-105865 | 8.1 HIGH | Payload: Incomplete validation during the upload file lifecycle |
| CVE-2026-105858 | 8.1 HIGH | Payload: Remote Code Execution through first-register |
| CVE-2026-105849 | 7.7 HIGH | Payload: API key disclosure through ordinary document reads |
| CVE-2026-105855 | 7.6 HIGH | Payload: Field-level password update restrictions were not enforced |
| CVE-2026-105861 | 7.2 HIGH | Payload external upload trust validation issue |
| CVE-2026-105847 | 7.1 HIGH | Payload: Polymorphic join queries could disclose hidden fields |
| CVE-2026-105860 | 7.1 HIGH | Payload: Tenant authorization bypass in Multi-Tenant Plugin |
| CVE-2026-105853 | 7.1 HIGH | Payload: Token refresh and password reset responses may expose restricted user fields |
Showing top 20 of 29 CVEs. View all on vendor page → →
No comments yet