CVE-2026-34747 Details
Description
Payload is a free and open source headless content management system. Prior to version 3.79.1, certain request inputs were not properly validated. An attacker could craft requests that influence SQL query execution, potentially exposing or modifying data in collections. This issue has been patched in version 3.79.1.
A SQL injection vulnerability has been identified in Payload CMS versions prior to 3.79.1. This issue arises from improper validation of certain request inputs, allowing attackers to craft requests that manipulate SQL query execution. As a result, there is a potential risk of exposing or modifying data within collections.
Users are advised to upgrade to Payload CMS version 3.79.1 or later, where this vulnerability has been patched. Query input validation has been improved in this version. Until an upgrade can be performed, it is recommended to limit access to endpoints that accept dynamic query inputs to trusted users only and to validate or sanitize input from untrusted clients before sending it to query endpoints.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 4, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/payloadcms/payload/releases/tag/v3.79.1 | [email protected] | ProductRelease Notes |
| https://github.com/payloadcms/payload/security/advisories/GHSA-7xxh-373w-35vg | [email protected] | MitigationVendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-89 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| payloadcms payload | < 3.79.1 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 13, 2026 | Initial Analysis | [email protected] |
| Apr 1, 2026 | New CVE Received | [email protected] |