SQL Injection Vulnerability in Payload CMS Affecting Multiple Versions
CVE-2026-105856
8.6HIGH
What is CVE-2026-105856?
Prior to versions 3.90.0 and 4.0.0-canary.34, Payload CMS is susceptible to SQL injection due to improper validation of crafted field paths and operators by authenticated attackers with read and create/update permissions. This vulnerability is specifically present in collections containing either a JSON field or a blocks field with the blocksAsJSON feature enabled. Collections lacking these features and richText fields are not affected. Update to the patched versions to safeguard against these attacks.
Affected Version(s)
db-d1-sqlite >= 3.0.0, < 3.90.0 < 3.0.0, 3.90.0
db-d1-sqlite >= 4.0.0-canary.0, < 4.0.0-canary.34 < 4.0.0-canary.0, 4.0.0-canary.34
db-postgres >= 3.0.0 < 3.73.0
