CRITICAL
9.8 CVE-2026-105845 Published 6 Oct 2026
Payload CMS SQL Injection Vulnerability
Worried this affects your website?
Payload, a free and open source headless content management system, is affected by a SQL injection vulnerability.
In versions from 3.0.0 before 3.88.0 and canary versions before 4.0.0-canary.27, an untrusted user who can query readable collections through dynamic filters or joins can submit a request that causes SQL injection in the SQLite and Postgres adapters.
- Affected versions: 3.0.0 through before 3.88.0
- Affected canary versions: before 4.0.0-canary.27
- Fixed versions: 3.88.0 and 4.0.0-canary.27
Reference: CVE-2026-105845 on NVD
← Back to Security News