CRITICAL 10.0 CVE-2026-105857 Published 6 Oct 2026

Payload CMS Form Builder Plugin Remote Code Execution Vulnerability

Worried this affects your website?

Payload is a free and open source headless content management system. A remote code execution vulnerability exists in the @payloadcms/plugin-form-builder plugin.

An attacker can craft a form submission that executes code remotely on the server.

  • Affected versions: plugin-form-builder before 3.90.0
  • Canary versions before 4.0.0-canary.34
  • Fixed in versions 3.90.0 and 4.0.0-canary.34

Reference: CVE-2026-105857 on NVD

← Back to Security News