Remote Code Execution Vulnerability in Payload CMS Plugin by Payload
CVE-2026-105857
10CRITICAL
What is CVE-2026-105857?
The Payload CMS Plugin for form building is affected by a vulnerability that allows an attacker to craft malicious form submissions. This can lead to remote code execution on the server, posing significant security risks. The issue has been addressed in versions 3.90.0 and 4.0.0-canary.34, which mitigate the threat by implementing security measures that prevent unauthorized code execution.
Affected Version(s)
payload < 3.90.0 < 3.90.0
payload >= 4.0.0-canary.0, < 4.0.0-canary.34 < 4.0.0-canary.0, 4.0.0-canary.34
