Direct naar de inhoud
⚡ Kritieke cyberalerts voor jouw sector & systemen — direct in je inbox. Aanmelden →
cybernieuws.nl Cybersecurity en informatiebeveiling nieuws alerts live · net nu 129 bronnen 1 kritiek 10 vandaag
CVE's Videos Dagbriefing

← Terug naar CVE-database

CVE-2026-105857

CRITICAL · 10.0 CVSS Gepubliceerd: CWE-94

Beschrijving

Payload is a free and open source headless content management system. In @payloadcms/plugin-form-builder versions before 3.90.0 and canary versions before 4.0.0-canary.34, an attacker can craft a form submission that executes code remotely on the server. This issue is fixed in versions 3.90.0 and 4.0.0-canary.34.

References