CVE-2026-105859
- EPSS 0.35%
- Veröffentlicht 06.10.2026 16:31:52
- Zuletzt bearbeitet 06.10.2026 20:03:40
Payload is a free and open source headless content management system. In versions before 3.90.0 and canary versions before 4.0.0-canary.34, an attacker can submit a request to a specific update endpoint that modifies collection documents without enfo...
CVE-2026-105858
- EPSS 0.48%
- Veröffentlicht 06.10.2026 16:29:52
- Zuletzt bearbeitet 09.10.2026 02:16:56
Payload is a free and open source headless content management system. In versions before 3.90.0 and canary versions before 4.0.0-canary.34, a crafted request to the public first-register operation can execute code remotely when local authentication i...
- EPSS 0.43%
- Veröffentlicht 06.10.2026 16:26:54
- Zuletzt bearbeitet 06.10.2026 20:03:40
Payload is a free and open source headless content management system. In @payloadcms/plugin-form-builder versions before 3.90.0 and canary versions before 4.0.0-canary.34, an attacker can craft a form submission that executes code remotely on the ser...
CVE-2026-105856
- EPSS 0.27%
- Veröffentlicht 06.10.2026 16:23:58
- Zuletzt bearbeitet 06.10.2026 20:03:40
Payload is a free and open source headless content management system. Prior to 3.90.0 and 4.0.0-canary.34, an attacker with read and create or update access to a collection containing a json field or a blocks field with blocksAsJSON enabled can injec...
CVE-2026-105855
- EPSS 0.33%
- Veröffentlicht 06.10.2026 16:18:53
- Zuletzt bearbeitet 06.10.2026 20:03:40
Payload is a free and open source headless content management system. In versions before 3.90.0 and canary versions before 4.0.0-canary.34, the server fails to enforce a field-level access.update restriction on the password field of an authentication...
CVE-2026-105854
- EPSS 0.31%
- Veröffentlicht 06.10.2026 16:17:30
- Zuletzt bearbeitet 06.10.2026 20:03:40
Payload is a free and open source headless content management system. In versions from 3.0.0 before 3.90.0 and canary versions before 4.0.0-canary.34, a malformed multipart request body can cause multipart Content-Type processing to take an extremely...
CVE-2026-105853
- EPSS 0.26%
- Veröffentlicht 06.10.2026 16:16:14
- Zuletzt bearbeitet 09.10.2026 02:16:55
Payload is a free and open source headless content management system. In versions from 3.0.0 before 3.90.0 and canary versions before 4.0.0-canary.34, token refresh responses and password reset responses can independently return hidden or read-restri...
CVE-2026-105852
- EPSS 0.28%
- Veröffentlicht 06.10.2026 16:15:03
- Zuletzt bearbeitet 06.10.2026 20:03:40
Payload is a free and open source headless content management system. In versions before 3.90.0 and canary versions before 4.0.0-canary.34, querying a readable collection with a relationship to another collection can expose information about related ...
CVE-2026-105851
- EPSS 0.31%
- Veröffentlicht 06.10.2026 16:13:11
- Zuletzt bearbeitet 06.10.2026 20:03:40
Payload is a free and open source headless content management system. In versions from 3.0.0 before 3.90.0 and canary versions before 4.0.0-canary.34, the duplicate operation copies values from a source document even when a field is hidden or its acc...
CVE-2026-105850
- EPSS 0.31%
- Veröffentlicht 06.10.2026 16:11:54
- Zuletzt bearbeitet 06.10.2026 20:03:40
Payload is a free and open source headless content management system. In @payloadcms/plugin-ecommerce versions before 3.90.0 and canary versions before 4.0.0-canary.34, use of the Stripe payment adapter can allow a Stripe order confirmation to be pro...