Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.8

CVE-2026-105845: Payload CMS allows SQL injection in SQLite and Postgres

CVE-2026-105845 · published 3 days ago
Summary

The free Payload content management system (versions 3.0.0 to 3.87.x and early canary builds before 4.0.0-canary.27) lets a malicious user craft a query that can run unwanted database commands on SQLite or PostgreSQL databases. This could let an attacker view, change, or delete data. Upgrade to version 3.88.0 or later, or the 4.0.0-canary.27 release, to close the problem.

What to do
  • Update elliotpayload payload to version 3.88.0.
  • Update elliotpayload payload to version 4.0.0-canary.27.
  • Update payload to version 3.88.0.
  • Update payload to version 4.0.0-canary.27.
Affected software
Ecosystem VendorProductAffected versions
– payloadcms payload >= 3.0.0, < 3.88.0
npm elliotpayload payload >= 3.0.0, < 3.88.0
>= 4.0.0-canary.0, < 4.0.0-canary.27
Fix: upgrade to 3.88.0
npm – payload >= 3.0.0, < 3.88.0
>= 4.0.0-canary.0, < 4.0.0-canary.27
Fix: upgrade to 3.88.0
Original advisory text
Payload: SQL Injection in SQLite and Postgres
Payload is a free and open source headless content management system. In versions from 3.0.0 before 3.88.0 and canary versions before 4.0.0-canary.27, an untrusted user who can query readable collections through dynamic filters or joins can submit a request that causes SQL injection in the SQLite and Postgres adapters. This issue is fixed in versions 3.88.0 and 4.0.0-canary.27.
Fix within
Internet-facing 3 days
Internal 60 days
  • Not known to be exploited
  • Can be exploited automatically
  • Gives an attacker full control
Severity
9.8 Critical
Exploitation
<1% chance of attack within 30 days
Type
CWE-89SQL Injection
Timeline
Published6 Oct 2026
Updated9 Oct 2026
First seen6 Oct 2026
Track software like this
Free during beta