CVE-2026-105857 | PayloadCMS up to 3.89.x/4.0.0-canary.33 plugin-form-builder code injection
A vulnerability was found in PayloadCMS up to 3.89.x/4.0.0-canary.33. It has been declared as critical. This affects an unknown part of the component plugin-form-builder. Such manipulation leads to code injection.
This vulnerability is referenced as CVE-2026-105857. It is possible to launch the attack remotely. No exploit is available.
It is recommended to upgrade the affected component.VulDB Recent EntriesRead More