Ecommerce Payment Processing Vulnerability in Payload CMS
CVE-2026-105850

8.8HIGH

Key Information:

Vendor

Payloadcms

Vendor
CVE Published:
6 October 2026

What is CVE-2026-105850?

In Payload CMS, specifically in the @payloadcms/plugin-ecommerce versions preceding 3.90.0 and canary versions before 4.0.0-canary.34, a flaw exists in the implementation of the Stripe payment adapter. This vulnerability can lead to the potential for a Stripe order confirmation to be processed multiple times under certain conditions, which may result in unexpected charges or duplicate transactions. This issue has been addressed in the latest releases, offering enhanced security and reliability for ecommerce transactions.

Affected Version(s)

payload < 3.90.0 < 3.90.0

payload >= 4.0.0-canary.0, < 4.0.0-canary.34 < 4.0.0-canary.0, 4.0.0-canary.34

plugin-ecommerce < 3.90.0 < 3.90.0

References

CVSS V4

Score:
8.8
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.