8.8
CVE-2026-105850
- EPSS 0.31%
- Veröffentlicht 06.10.2026 16:11:54
- Zuletzt bearbeitet 06.10.2026 20:03:40
- Erkennungen
Payload: Order confirmation validation issue in Payload Ecommerce
Payload is a free and open source headless content management system. In @payloadcms/plugin-ecommerce versions before 3.90.0 and canary versions before 4.0.0-canary.34, use of the Stripe payment adapter can allow a Stripe order confirmation to be processed more than once under certain conditions. This issue is fixed in versions 3.90.0 and 4.0.0-canary.34.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
Herstellerpayloadcms
≫
Produkt
payload
Version
< 3.90.0
Status
affected
Version
>= 4.0.0-canary.0, < 4.0.0-canary.34
Status
affected
Hersteller@payloadcms
≫
Produkt
plugin-ecommerce
Version
< 3.90.0
Status
affected
Version
>= 4.0.0-canary.0, < 4.0.0-canary.34
Status
affected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.31% | 0.217 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| security-advisories@github.com | 8.8 | 0 | 0 |
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
|
CWE-837 Improper Enforcement of a Single, Unique Action
The product requires that an actor should only be able to perform an action once, or to have only one unique action, but the product does not enforce or improperly enforces this restriction.
https://github.com/payloadcms/payload/releases/tag/v3.90.0
https://github.com/payloadcms/payload/security/advisories/GHSA-8r29-2mp2-pmrw
https://github.com/payloadcms/payload/commit/6c0c4dc9b4ce1ac87b03fbb5dd7356b8559cbc4e