CRITICAL
10.0 CVE-2026-105857 Published 6 Oct 2026
Payload CMS Form Builder Plugin Remote Code Execution Vulnerability
Worried this affects your website?
Payload is a free and open source headless content management system. A remote code execution vulnerability exists in the @payloadcms/plugin-form-builder plugin.
An attacker can craft a form submission that executes code remotely on the server.
- Affected versions: plugin-form-builder before 3.90.0
- Canary versions before 4.0.0-canary.34
- Fixed in versions 3.90.0 and 4.0.0-canary.34
Reference: CVE-2026-105857 on NVD
← Back to Security News