CVE-2026-105861High· 7.2▾ TwilightPayload is a free and open source headless content management system. In versions after 3.0.0 and before 3.90.0, authenticated external URL-based upload retrieval can forward authentication data to a redirected destination that was not v…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 39.6 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Payload is a free and open source headless content management system. In versions after 3.0.0 and before 3.90.0, authenticated external URL-based upload retrieval can forward authentication data to a redirected destination that was not verified as trusted, potentially exposing a valid session to an unintended recipient. This issue is fixed in version 3.90.0.
payload > 3.0.0, < 3.90.0payload > 4.0.0-canary.0, < 4.0.0-canary-34Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-105847High· 7.1Payload: Polymorphic join queries could disclose hidden fields
CVE-2026-105853High· 7.1Payload: Token refresh and password reset responses may expose restricted user fields
CVE-2026-105857Critical· 10.0Payload: RCE in Payload Form Builder
CVE-2026-105856High· 8.6Payload: SQL injection in SQLite/Postgres
CVE-2026-105859Critical· 9.8Payload: Unauthorized update to collection documents
CVE-2026-105858High· 8.1Payload: Remote Code Execution through first-register