Payload is a free and open source headless content management system. Prior to version 3.79.1, certain request inputs were not properly validated. An attacker could craft requests that influence SQL query execution, potentially exposing or modifying data in collections. This issue has been patched in version 3.79.1.
oryginał ENCVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:NPayloadcms Payload
APPPayloadcms< 3.79.1
🔵
ZWERYFIKUJ U PRODUCENTA
Brak jednoznacznych danych o patchu. Sprawdź referencje od producenta.
Tagi
SQLi
CWE
Powiązane podatności
CVE-2026-34751CRITICAL9.1PL ✓ten sam produkt
Payload CMS: ominięcie uwierzytelnienia przez podatny przepływ resetowania hasła
CVE-2026-25544CRITICAL9.8PL ✓ten sam produkt
SQL Injection w Payload CMS — przejęcie konta bez uwierzytelnienia
CVE-2022-27952CRITICAL9.8PL ✓ten sam produkt
PayloadCMS: RCE poprzez nieograniczony upload pliku SVG
CVE-2026-34748HIGH8.7ten sam produkt
Payload is a free and open source headless content management system. Prior to version 3.78.0 in @payloadcms/n...
CVE-2026-34746HIGH7.7ten sam produkt
Payload is a free and open source headless content management system. Prior to version 3.79.1, an authenticate...