Payload is a free and open source headless content management system. Prior to version 3.79.1, certain request inputs were not properly validated. An attacker could craft requests that influence SQL query execution, potentially exposing or modifying data in collections. This issue has been patched in version 3.79.1.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:NPayloadcms Payload
APPPayloadcms< 3.79.1
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
SQLi
CWE
Related vulnerabilities
CVE-2026-34751CRITICAL9.1PL ✓same product
Payload CMS: ominięcie uwierzytelnienia przez podatny przepływ resetowania hasła
CVE-2026-25544CRITICAL9.8PL ✓same product
SQL Injection w Payload CMS — przejęcie konta bez uwierzytelnienia
CVE-2022-27952CRITICAL9.8PL ✓same product
PayloadCMS: RCE poprzez nieograniczony upload pliku SVG
CVE-2026-34748HIGH8.7same product
Payload is a free and open source headless content management system. Prior to version 3.78.0 in @payloadcms/n...
CVE-2026-34746HIGH7.7same product
Payload is a free and open source headless content management system. Prior to version 3.79.1, an authenticate...