CRITICAL 9.8 CVE-2026-105845 Published 6 Oct 2026

Payload CMS SQL Injection Vulnerability

Worried this affects your website?

Payload, a free and open source headless content management system, is affected by a SQL injection vulnerability.

In versions from 3.0.0 before 3.88.0 and canary versions before 4.0.0-canary.27, an untrusted user who can query readable collections through dynamic filters or joins can submit a request that causes SQL injection in the SQLite and Postgres adapters.

  • Affected versions: 3.0.0 through before 3.88.0
  • Affected canary versions: before 4.0.0-canary.27
  • Fixed versions: 3.88.0 and 4.0.0-canary.27

Reference: CVE-2026-105845 on NVD

← Back to Security News