Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
8.8

CVE-2026-105850: Payload CMS ecommerce can double‑charge Stripe orders

CVE-2026-105850 · published 3 days ago
Summary

The Payload headless CMS and its ecommerce plugin allow a Stripe order confirmation to be processed more than once in older versions. This could result in customers being charged twice for the same purchase. Upgrade to version 3.90.0 or later (or the 4.0.0‑canary.34 release) to stop the duplicate processing.

What to do
  • Update payloadcms plugin-ecommerce to version 3.90.0.
  • Update payloadcms plugin-ecommerce to version 4.0.0-canary.34.
  • Update payloadcms @payloadcms/plugin-ecommerce to version 3.90.0.
  • Update payloadcms @payloadcms/plugin-ecommerce to version 4.0.0-canary.34.
Affected software
Ecosystem VendorProductAffected versions
– payloadcms payload < 3.90.0
– @payloadcms plugin-ecommerce < 3.90.0
npm payloadcms plugin-ecommerce < 3.90.0
>= 4.0.0-canary.0, < 4.0.0-canary.34
Fix: upgrade to 3.90.0
npm payloadcms @payloadcms/plugin-ecommerce < 3.90.0
>= 4.0.0-canary.0, < 4.0.0-canary.34
Fix: upgrade to 3.90.0
Original advisory text
Payload Ecommerce has an order confirmation validation issue
Payload is a free and open source headless content management system. In @payloadcms/plugin-ecommerce versions before 3.90.0 and canary versions before 4.0.0-canary.34, use of the Stripe payment adapter can allow a Stripe order confirmation to be processed more than once under certain conditions. This issue is fixed in versions 3.90.0 and 4.0.0-canary.34.
Fix within
Internet-facing 14 days
Internal 60 days
  • Not known to be exploited
  • Can be exploited automatically
  • Gives an attacker partial control
Severity
8.8 High
Exploitation
<1% chance of attack within 30 days
Type
CWE-837Improper Enforcement of a Single, Unique Action
Timeline
Published6 Oct 2026
Updated9 Oct 2026
First seen6 Oct 2026
Track software like this
Free during beta