Payload
Payloadcms · 41 CVEs
Payload: Field-level write access bypass in Payload on MongoDB
Oct 6, 2026
Payload: Uploaded XML files could execute same-origin JavaScript
Oct 6, 2026
Payload: Client uploads could overwrite S3 objects
Oct 6, 2026
Payload: Unauthenticated account-lockout denial of service
Oct 6, 2026
Payload: Incomplete validation during the upload file lifecycle
Oct 6, 2026
Payload: Cross-tenant create in @payloadcms/plugin-multi-tenant
Oct 6, 2026
Payload authentication token field handling issue
Oct 6, 2026
Payload: Bypassed sanitization of user uploaded SVGs
Oct 6, 2026
Payload external upload trust validation issue
Oct 6, 2026
Payload: Tenant authorization bypass in Multi-Tenant Plugin
Oct 6, 2026
Payload: Unauthorized update to collection documents
Oct 6, 2026
Payload: Remote Code Execution through first-register
Oct 6, 2026
Payload: RCE in Payload Form Builder
Oct 6, 2026
Payload: SQL injection in SQLite/Postgres
Oct 6, 2026
Payload: Field-level password update restrictions were not enforced
Oct 6, 2026
Payload: ReDoS in Multipart Content-Type Validation
Oct 6, 2026
Payload: Token refresh and password reset responses may expose restricted user fields
Oct 6, 2026
Payload relationship-query authorization bypass
Oct 6, 2026
Payload: Field access control bypass on auth collections
Oct 6, 2026
Payload: Order confirmation validation issue in Payload Ecommerce
Oct 6, 2026
Payload: API key disclosure through ordinary document reads
Oct 6, 2026
Payload: Insufficient Access Control in Stripe REST Proxy
Oct 6, 2026
Payload: Polymorphic join queries could disclose hidden fields
Oct 6, 2026
Payload: Untrusted redirect URL parameter exploit
Oct 6, 2026
Payload: SQL Injection in SQLite and Postgres
Oct 6, 2026
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2026-106100 | Payload: Field-level write access bypass in Payload on MongoDB | HIGH | n/a | Oct 6, 2026 |
| CVE-2026-105868 | Payload: Uploaded XML files could execute same-origin JavaScript | HIGH | n/a | Oct 6, 2026 |
| CVE-2026-105867 | Payload: Client uploads could overwrite S3 objects | HIGH | n/a | Oct 6, 2026 |
| CVE-2026-105866 | Payload: Unauthenticated account-lockout denial of service | MEDIUM | n/a | Oct 6, 2026 |
| CVE-2026-105865 | Payload: Incomplete validation during the upload file lifecycle | HIGH | n/a | Oct 6, 2026 |
| CVE-2026-105864 | Payload: Cross-tenant create in @payloadcms/plugin-multi-tenant | MEDIUM | n/a | Oct 6, 2026 |
| CVE-2026-105863 | Payload authentication token field handling issue | CRITICAL | n/a | Oct 6, 2026 |
| CVE-2026-105862 | Payload: Bypassed sanitization of user uploaded SVGs | HIGH | n/a | Oct 6, 2026 |
| CVE-2026-105861 | Payload external upload trust validation issue | HIGH | n/a | Oct 6, 2026 |
| CVE-2026-105860 | Payload: Tenant authorization bypass in Multi-Tenant Plugin | HIGH | n/a | Oct 6, 2026 |
| CVE-2026-105859 | Payload: Unauthorized update to collection documents | CRITICAL | n/a | Oct 6, 2026 |
| CVE-2026-105858 | Payload: Remote Code Execution through first-register | HIGH | n/a | Oct 6, 2026 |
| CVE-2026-105857 | Payload: RCE in Payload Form Builder | CRITICAL | n/a | Oct 6, 2026 |
| CVE-2026-105856 | Payload: SQL injection in SQLite/Postgres | HIGH | n/a | Oct 6, 2026 |
| CVE-2026-105855 | Payload: Field-level password update restrictions were not enforced | HIGH | n/a | Oct 6, 2026 |
| CVE-2026-105854 | Payload: ReDoS in Multipart Content-Type Validation | HIGH | n/a | Oct 6, 2026 |
| CVE-2026-105853 | Payload: Token refresh and password reset responses may expose restricted user fields | HIGH | n/a | Oct 6, 2026 |
| CVE-2026-105852 | Payload relationship-query authorization bypass | MEDIUM | n/a | Oct 6, 2026 |
| CVE-2026-105851 | Payload: Field access control bypass on auth collections | CRITICAL | n/a | Oct 6, 2026 |
| CVE-2026-105850 | Payload: Order confirmation validation issue in Payload Ecommerce | HIGH | n/a | Oct 6, 2026 |
| CVE-2026-105849 | Payload: API key disclosure through ordinary document reads | HIGH | n/a | Oct 6, 2026 |
| CVE-2026-105848 | Payload: Insufficient Access Control in Stripe REST Proxy | MEDIUM | n/a | Oct 6, 2026 |
| CVE-2026-105847 | Payload: Polymorphic join queries could disclose hidden fields | HIGH | n/a | Oct 6, 2026 |
| CVE-2026-105846 | Payload: Untrusted redirect URL parameter exploit | MEDIUM | n/a | Oct 6, 2026 |
| CVE-2026-105845 | Payload: SQL Injection in SQLite and Postgres | CRITICAL | n/a | Oct 6, 2026 |
Showing 1 to 25 of 41 CVEs