CVE-2026-105857 | PayloadCMS up to 3.89.x/4.0.0-canary.33 plugin-form-builder code injection

SecurityVulns

A vulnerability was found in PayloadCMS up to 3.89.x/4.0.0-canary.33. It has been declared as critical. This affects an unknown part of the component plugin-form-builder. Such manipulation leads to code injection.

This vulnerability is referenced as CVE-2026-105857. It is possible to launch the attack remotely. No exploit is available.

It is recommended to upgrade the affected component.VulDB Recent EntriesRead More