Ecommerce Payment Processing Vulnerability in Payload CMS
CVE-2026-105850
8.8HIGH
What is CVE-2026-105850?
In Payload CMS, specifically in the @payloadcms/plugin-ecommerce versions preceding 3.90.0 and canary versions before 4.0.0-canary.34, a flaw exists in the implementation of the Stripe payment adapter. This vulnerability can lead to the potential for a Stripe order confirmation to be processed multiple times under certain conditions, which may result in unexpected charges or duplicate transactions. This issue has been addressed in the latest releases, offering enhanced security and reliability for ecommerce transactions.
Affected Version(s)
payload < 3.90.0 < 3.90.0
payload >= 4.0.0-canary.0, < 4.0.0-canary.34 < 4.0.0-canary.0, 4.0.0-canary.34
plugin-ecommerce < 3.90.0 < 3.90.0
