Back

CRITICAL

Payload: SQL Injection in SQLite and Postgres

Published Oct 6, 2026

Description

Payload is a free and open source headless content management system. In versions from 3.0.0 before 3.88.0 and canary versions before 4.0.0-canary.27, an untrusted user who can query readable collections through dynamic filters or joins can submit a request that causes SQL injection in the SQLite and Postgres adapters. This issue is fixed in versions 3.88.0 and 4.0.0-canary.27.

Affected products

Remediation

No remediation recorded yet.

Weaknesses (1)

References (5)

Change history (4)
  1. EUVD
    • Updated

      changed from Oct 6, 2026 to Oct 6, 2026

    • Published

      changed from Oct 6, 2026 to Oct 6, 2026

  2. EUVD
    • Updated

      changed from Oct 6, 2026 to Oct 6, 2026

    • Published

      changed from Oct 6, 2026 to Oct 6, 2026

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published Oct 6, 2026
Updated Oct 6, 2026
Reserved Oct 5, 2026
CISA Vulnrichment
Updated Oct 6, 2026
NVD
Status Awaiting Analysis
Modified Oct 6, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner GitHub_M
Published Oct 6, 2026
Updated Oct 6, 2026
Exploited since n/a
EUVD-2026-93471 GHSA-V49J-62M6-PGRR