CVE-2026-105868
Payload is a free and open source headless content management system. In versions before 3.90.0 and canary versions before 4.0.0-canary.34,
CVSS
—
No CVSS
EPSS
—
KEV
—
Exploit Today
—
0-100
Published: Oct 6, 2026 · Last modified: Oct 6, 2026 · CWE-434
Not enough EPSS history yet.
Payload is a free and open source headless content management system. In versions before 3.90.0 and canary versions before 4.0.0-canary.34, local upload configurations that accept XML files can store an XML file and stylesheet that execute JavaScript in the Payload origin when a logged-in user opens the file. This issue is fixed in versions 3.90.0 and 4.0.0-canary.34.
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-1058628.7 HIG—
———Payload is a free and open source headless content management system. In versions before 3.90.0 and canary versions before 4.0.0-canary.34, a collection that allows downloadable SVG uploads can store a malicious SVG that bypasses sanitization and executes attacker-controlled JavaScript when a user downloads and opens the SVG. This issue is fixed in versions 3.90.0 and 4.0.0-canary.34.2hCVE-2026-1040697.2 HIG—
———HortusFox before 6.2 contains a remote code execution vulnerability in ThemeModule::startImport() where an uploaded ZIP archive is extracted directly into the public web root before any validation of file names, extensions, or content is performed. An authenticated administrator can upload a crafted theme archive containing a PHP file and an .htaccess file to re-enable execution, then request it under the themes directory to execute arbitrary OS commands as the web-server user.4hCVE-2026-3977010.0 CRI—
———Unauthenticated Arbitrary File Upload in Doctreat <= 1.7.0 versions.7hCVE-2026-397599.9 CRI—
———Employer / Sales Representative Arbitrary File Upload in Workreap Core <= 3.4.5 versions.7hCVE-2026-397579.9 CRI—
———Subscriber Arbitrary File Upload in Taskbot <= 6.6 versions.7hCVE-2026-397559.9 CRI—
———Subscriber Arbitrary File Upload in WP Duplicate <= 1.1.11 versions.7h